Only what the service needs
Cookie notice
Thunder Debates uses four first-party cookies and no advertising or third-party analytics cookies.
Last updated 17 July 2026Cookies in use
The production defaults are listed below. A deployment can change the names of the session, trusted-device and anonymous-integrity cookies without changing their purposes.
- td_session: a browser-session cookie used for form security, notices, sign-in and administrator access. Server-side session and sign-in records expire according to the applicable security lifetime.
- __Host-td_remember: set only when you actively choose Remember me on this browser for 30 days. It holds a versioned random selector and validator so a verified account can resume routine sign-in on that browser. The service stores only keyed versions of those values, not the readable cookie credential. Owners and moderators receive it only after completing any required authenticator or recovery-code check. A remembered sign-in does not count as recent reauthentication, so sensitive Owner actions still require a fresh password and authenticator code.
- td_age: set only after you confirm the 18+ notice. It remembers that confirmation for up to 180 days. It does not verify your age.
- td_anon: set when the service needs an anonymous participant identity. It holds a signed random token for up to 180 days so aliases remain stable and duplicate participation can be resisted. The raw token is not stored in the database.
Security attributes
On the production HTTPS service, all four cookies are Secure, HttpOnly and SameSite=Lax, and are limited to this site. HttpOnly prevents site scripts from reading them. The __Host-td_remember cookie also uses Path=/ and has no Domain attribute, as required by its __Host- prefix. FurCaptcha does not add a cookie or browser-storage identifier to Thunder Debates. A successful solve is remembered server-side in the existing td_session for no more than 15 minutes. The service does not use local storage, tracking pixels, embedded social tools or third-party advertising cookies.
Why there is no consent banner
The cookies are used only to provide a service you request and to supply essential security, session, age-policy and participation-integrity functions. The trusted-device cookie is written only when you actively request the 30-day remembered-sign-in feature, and is used only to provide and protect that feature. The operator relies on the strictly necessary exception in the Privacy and Electronic Communications Regulations. That exception applies only while each cookie remains essential from the user’s perspective and is not reused for analytics, advertising or another purpose.
Your controls
You can block or clear cookies using your browser. Blocking the session cookie prevents secure forms and sign-in. Clearing __Host-td_remember stops that browser from resuming sign-in, although the matching server record remains unusable without the cookie and expires within 30 days. Signing out revokes the current browser’s trusted-device record. A password reset, account restriction, relevant role or status change, or authenticator change revokes every trusted-device record for the account. Clearing td_age shows the 18+ notice again. Clearing td_anon can change your anonymous alias, but it does not guarantee that related server records are erased and must not be used to evade vote or abuse controls.
If the service changes
Any non-essential storage or access technology will remain off until the operator provides clear information and obtains valid consent or documents another applicable statutory exception. This notice must be updated before such a feature is enabled.