Legal
Cookie policy
Last updated 23 August 2026
MyCA uses a small number of cookies, and none of them are for advertising.
What we set
- Session cookie — keeps you signed in. Marked HttpOnly and SameSite, and sent only over HTTPS in production.
- CSRF token cookie — lets the site verify that a form submission came from a page we served.
What we do not set
No advertising cookies, no cross-site trackers, and no third-party analytics that follow you off this site. The platform loads no scripts, fonts or stylesheets from other origins.
Managing them
You can clear cookies in your browser at any time. Clearing the session cookie signs you out; the site will not work signed-in without it.