Cookie policy
Effective from 7 August 2026. Version 1.0.
A cookie is a small file a website asks your browser to keep and send back on your next request. It is how a site remembers that you are signed in. This page lists every cookie LifeCraft sets. There is nothing else.
What we do not do
- No advertising cookies. We do not show advertising anywhere in the product.
- No analytics or marketing tags, and no third-party trackers or pixels.
- No cross-site tracking, and no sharing of any identifier with an ad network.
- No cookies used to build a profile of you or of anyone in your household.
- Nothing on the child-facing mission view sets a cookie of its own, and nothing on that screen measures, profiles or tracks the child. It runs inside the guardian’s existing signed-in session, so no additional cookie is created for the child.
Because we only use cookies that are strictly necessary to deliver a service you asked for, we do not show a consent banner. Consent banners exist for the tracking we do not do. We still tell you exactly what is set, below.
Every cookie we set
| Name | Purpose | Duration |
|---|---|---|
| authjs.session-token | Keeps you signed in so the server knows which account a request belongs to. Set only after you sign in. Marked HttpOnly, Secure and SameSite, so scripts cannot read it and other sites cannot send it | 30 days, refreshed while you keep using the app, cleared when you sign out |
| authjs.csrf-token | Proves that a form or action came from our own pages, which stops another site from making changes to your account in the background | Until you close the browser |
| authjs.callback-url | Remembers the page you were heading to so that signing in returns you to it rather than to the dashboard | Until you close the browser |
| lc-theme | Remembers whether you chose the light or dark theme. Stored in your browser’s local storage rather than as a cookie, and never sent to our servers | Until you clear your browser storage |
On a secure connection the session and CSRF entries carry the browser security prefixes __Secure- and __Host-, so their full names appear as __Secure-authjs.session-token and __Host-authjs.csrf-token. They are the same cookies described above.
Third parties
We do not embed third-party scripts that set cookies. Two exceptions exist and neither happens on our pages without you acting first. When you pay, you are handed to Razorpay or Stripe, who set their own cookies on their own pages to complete the payment and prevent fraud. Their cookie policies apply there. Cloudflare, which sits in front of the site to filter attacks, may set a security cookie to tell a real visitor from an automated attack. None of these are used for advertising.
Controlling cookies
Every browser lets you view, block and delete cookies in its settings. You are welcome to. Be aware that the session and CSRF cookies are what make signing in possible, so blocking them means you will not be able to use the account area at all. Blocking local storage means the app will not remember your theme choice between visits.
Questions and changes
If we ever add a cookie, this page is updated before it ships, and the change is described in the same terms as everything above. For anything about this page, or about what we hold more generally, see the privacy policy or email privacy@lifecraft.in.