Effective date: 22 July 2026 Version: 1.0 Provider: GuildWard, 1046 Budapest, Klauzál utca 9.
Current position
GuildWard sets only the three first-party cookies listed below. They are strictly necessary for Discord OAuth security and the private member-verification route. The application does not use analytics, marketing, advertising or preference cookies. A repository and application review found no use of localStorage or sessionStorage by GuildWard. Because only strictly necessary cookies are used, GuildWard does not display a nonessential-cookie consent banner.
Cookie inventory
| Name | Provider | Purpose | Category | Duration | Attributes |
|---|---|---|---|---|---|
guildward_session | GuildWard | Keeps an administrator signed in after Discord OAuth. The browser value maps to a hashed server-side session; the raw token is not stored in plain form in the database. | Strictly necessary | Default 24 hours from creation (SESSION_TTL_HOURS; configurable between 1 and 720 hours). Ends earlier on logout or revocation. | HttpOnly; SameSite=Lax; Path=/; Secure in production |
guildward_oauth_state | GuildWard | Binds the Discord OAuth callback to the browser that started login and reduces request-forgery and replay risk. | Strictly necessary | Default 5 minutes (OAUTH_STATE_TTL_SECONDS; configurable between 60 and 900 seconds). Deleted after the callback completes or when it expires. | HttpOnly; SameSite=Lax; Path=/api/v1/auth/discord/callback; Secure in production |
guildward_verification | GuildWard | Scopes a member browser to one exchanged verification continuation without retaining the raw continuation token server-side. | Strictly necessary | Default 10 minutes (VERIFICATION_SESSION_TTL_MINUTES; configurable between 2 and 60 minutes), and never longer than the remaining verification-session expiry. | HttpOnly; SameSite=Lax; Path=/; Secure in production |
Cloudflare Turnstile
The member-verification page loads Cloudflare Turnstile from https://challenges.cloudflare.com/turnstile/v0/api.js and sends a challenge token to GuildWard for server-side validation. According to Cloudflare’s public Turnstile documentation, Turnstile does not rely on cookies or client-side storage to operate. GuildWard does not set Turnstile cookies and does not use the Turnstile token for advertising. Cloudflare may still process browser, device and network signals needed to deliver the challenge under Cloudflare’s own terms and privacy notices. If a deployment later places GuildWard behind additional Cloudflare network products that set their own cookies (for example bot-management cookies such as __cf_bm), those cookies are controlled by Cloudflare and will be disclosed when that network configuration is active.
Future technologies
If GuildWard introduces analytics, marketing or another nonessential technology, that technology will remain disabled until any legally required consent mechanism and an updated Cookie Policy are in place.
Controls and contact
Browser settings can block or delete cookies. Blocking the cookies above will prevent administrator login or member verification. Questions about this Cookie Policy may be sent in writing to GuildWard, 1046 Budapest, Klauzál utca 9., marked “Cookies”.