Cookie policy
Every cookie this site sets. There are no analytics cookies, no advertising cookies and no tracking across other sites.
Last updated September 2026
| Cookie | Set | What it is for | Lasts |
|---|---|---|---|
__Secure-authjs.session-token | When you sign in | Keeps you signed in. | Until you sign out, or 30 days without a visit |
__Host-authjs.csrf-token | When a sign-in page loads | Stops another site from signing you in or out. | The browser session |
__Secure-authjs.callback-url | When you start signing in | Remembers the page to send you back to. | The browser session |
__Secure-authjs.state, __Secure-authjs.pkce.code_verifier | Only during Discord sign-in | Protects the hand-off to Discord and back. | About 15 minutes |
rbx_state, rbx_verifier | Only while connecting a Roblox account through Roblox | Protects the hand-off to Roblox and back. | About 10 minutes |
ref | Only when you arrive through an affiliate link | Credits the person who referred you if you buy. | 30 days |
risor-theme | Only if you switch between light and dark | Remembers the theme you chose. | One year |
All of them are needed for the thing they are set for, and none is set before you do that thing. Paying by card happens on Stripe's own page, which sets its own cookies under Stripe's own policy.
Privacy covers what happens to your data.