Cookies
Mooring sets exactly one cookie, and it exists to keep you signed in. There is no analytics, no advertising, no tracking and nothing from a third party.
The cookie
- Name — moor_session
- Purpose — holds a signed token identifying your account, so that each page you open knows you are logged in.
- Contains — your account’s internal ID and an expiry, signed so it cannot be altered. No name, no email address.
- Expires — 30 days after sign-in, or immediately when you sign out.
- Type — first party, HTTP-only, and marked secure in production, meaning scripts in the page cannot read it and it is only sent over HTTPS.
Why there is no cookie banner
Under the Privacy and Electronic Communications Regulations, consent is needed for cookies that are not strictly necessary — analytics, advertising, and anything that follows you around. A cookie used solely to keep a logged-in user logged in is exempt, because the service you asked for cannot work without it. We have nothing else to ask you about, so we don’t interrupt you to ask it.
If we ever add anything that does require consent, you will get a real choice before it is set, not a pre-ticked box.
Other storage
We do not use local storage, session storage or fingerprinting to identify you. Typefaces are served from our own servers rather than a font CDN, so opening a page does not announce your visit to a third party.
Turning it off
You can block or delete cookies in your browser settings. Blocking this one means you cannot stay signed in, so the account area will not work, though the public pages will read perfectly well.
More detail
What we do with personal data generally is set out in the privacy policy.