Cookie Policy
Last updated: May 2026
This Cookie Policy explains which cookies Plutton uses, why we use them, and how you can manage your preferences in accordance with the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA/CPRA).
1. What Are Cookies?
Cookies are small text files stored on your device when you visit a website. They allow the site to recognize your browser, maintain your session, and remember your preferences. Cookies cannot execute code or access other files on your device.
2. Cookies We Use
Plutton uses the following cookies. Essential cookies are always active and required for the service to work. Analytical cookies are only placed with your explicit consent.
- next-auth.session-token (or __Secure-next-auth.session-token on HTTPS) — Purpose: Maintains your authenticated login session. Provider: Plutton (NextAuth.js). Duration: 30 days. Category: Essential.
- next-auth.csrf-token — Purpose: Prevents cross-site request forgery attacks. Provider: Plutton (NextAuth.js). Duration: Session. Category: Essential.
- __cf_bm — Purpose: Cloudflare bot management and Turnstile CAPTCHA verification. Provider: Cloudflare. Duration: 30 minutes. Category: Essential (security).
- _ga — Purpose: Distinguishes unique visitors for Google Analytics. Provider: Google LLC. Duration: 2 years. Category: Analytics (requires your consent).
- _gid — Purpose: Distinguishes visitors between sessions for Google Analytics. Provider: Google LLC. Duration: 24 hours. Category: Analytics (requires your consent).
3. Legal Basis for Cookies
Essential cookies are placed on the basis of legitimate interest and the performance of our contract with you (GDPR Art. 6(1)(b) and 6(1)(f)) — they are strictly necessary for the platform to function. Analytical cookies (Google Analytics) are placed only with your explicit consent (GDPR Art. 6(1)(a)). You may withdraw consent at any time via the cookie banner or by clearing your browser's local storage. We do not use cookies for advertising or behavioral profiling.
4. Your Rights (EU/EEA — GDPR)
If you are in the EU or EEA, you have the right to withdraw your consent for analytical cookies at any time without affecting any prior processing. You may also lodge a complaint with your national data protection authority. To opt out of Google Analytics across all sites, install the Google Analytics Opt-out Browser Add-on at tools.google.com/dlpage/gaoptout.
5. California Residents (CCPA/CPRA)
Plutton does not sell, rent, or share your personal information for cross-context behavioral advertising. The cookies we use do not constitute a sale of personal information under CCPA/CPRA. California residents may contact us at [email protected] to exercise their rights, including the right to know what personal information we collect and the right to request its deletion.
6. Managing Your Cookie Preferences
You can control cookies in the following ways: (1) Cookie banner — use the Reject Non-Essential or Manage Preferences option when the banner appears, or reset your choice by clearing your browser's local storage and revisiting the site. (2) Browser settings — most browsers allow you to block or delete cookies through their settings menu. Note that disabling essential cookies will prevent you from logging in to Plutton. (3) Google opt-out — visit myaccount.google.com/data-and-privacy or install the Google Analytics browser extension to stop Google Analytics tracking across all websites.

