Cookie Policy
Download PDFLast updated: 31 July 2026
1. What this document covers
1.1. This Cookie Policy describes what information vulcode.com stores in your browser, for what purpose, and how you can delete it.
1.2. It supplements the Privacy Policy, which describes how VulCode ("VulCode", "we", "us") processes personal data.
1.3. vulcode.com does not set any cookies. We use browser storage only (localStorage and sessionStorage). Because these technologies work similarly to cookies and are subject to similar rules, we describe them here in the same way.
2. What cookies and similar technologies are
2.1. Cookies are small text files stored by a website on the user's device and sent back to the server with subsequent requests.
2.2. localStorage is browser storage bound to a specific domain. Data stored there remains on the device until removed by the user or by the website. It is not automatically sent to the server with every request.
2.3. sessionStorage works the same way as localStorage, except that the stored data is removed when the browser tab is closed.
2.4. First-party technologies are data stored by vulcode.com itself. Third-party technologies are data stored by external providers whose resources are embedded on the site - their scope is described in section 6.
3. Categories used
3.1. Strictly necessary - required for core functions of the site, including authentication in the admin panel. Without them the site cannot work correctly.
3.2. Functional - remember settings and data that improve the experience, such as the interface translation cache.
3.3. Analytics - allow us to count visits and understand how the site is used. We use our own analytics system only; we do not share this data with external analytics providers.
3.4. Marketing - in our case limited solely to remembering a referral code if you arrived through a referral link. We do not use advertising technologies, ad networks, remarketing or user profiling for marketing purposes.
4. What exactly we use
4.1. The table below is the complete list of data stored by vulcode.com in the browser:
| Name | Type | Category | Purpose | Storage period |
|---|---|---|---|---|
kd_sid | localStorage | analytics | analytics session identifier, so a visit is counted as one session rather than a set of unrelated page views | until removed by the user or invalidated server-side; no automatic expiry in the browser |
kd_prev_path | sessionStorage | analytics | previously visited page, used to reconstruct the navigation path | until the browser tab is closed |
kd_faq_history | sessionStorage | analytics | most recently opened FAQ questions (up to 5), so we know which content is needed | until the browser tab is closed |
kd_reflink | sessionStorage | marketing | referral code taken from a referral link, attributed to the visit and to messages sent via the contact form | until the browser tab is closed |
admin_token | localStorage | strictly necessary | token authenticating a session in the admin panel; stored only after an authorised person logs in, never for an ordinary visitor | the token expires after 7 days; the entry is removed on logout or when the server rejects the token |
4.2. Apart from the items listed above, vulcode.com does not store any other data in the browser and, in particular, does not set cookies.
5. Legal basis
5.1. The table below indicates the basis for processing personal data associated with each category:
| Category | Basis |
|---|---|
| Strictly necessary | necessity for providing the service requested by the user (access to the admin panel) |
| Functional | VulCode legitimate interest in the correct and convenient operation of the site - Art. 6(1)(f) GDPR |
| Analytics | VulCode legitimate interest in studying and improving how the site is used - Art. 6(1)(f) GDPR |
| Marketing (referral code) | legitimate interest of VulCode and of the referral programme participant in correctly settling a referral - Art. 6(1)(f) GDPR |
5.2. Storing information on, and accessing information stored in, the user's terminal equipment is also subject - independently of the GDPR - to electronic communications law.
5.3. If the law requires consent for particular categories, we will ask for it before storing the data and allow it to be withdrawn at any time.
6. Third parties
6.1. Google Fonts - the typefaces used on the site are loaded from Google servers (fonts.googleapis.com, fonts.gstatic.com). The provider does not store data in your browser under our domain on that account, but loading the files does disclose your IP address and browser information to it.
6.2. flagcdn.com - the flag icons in the language switcher are loaded from an external image service. This concerns only the download of the image file, which discloses the IP address and browser information.
6.3. Embedded portfolio previews - on pages presenting completed projects we embed a live preview of the site in a frame. The embedded site may store its own cookies and data in the browser in accordance with its owner's policy. This applies only to portfolio pages containing such a preview.
6.4. Links to external services (including social media and Discord) do not cause any data to be stored until they are clicked. Once you move to an external service, its own rules apply.
6.5. We do not use third-party analytics, advertising or tracking tools, in particular: Google Analytics, Google Tag Manager, Meta Pixel, TikTok Pixel, LinkedIn Insight Tag, Hotjar, Microsoft Clarity, Matomo, Plausible, or remarketing-type advertising systems.
7. How to delete stored data and withdraw consent
7.1. You can delete all data stored by the site in your browser at any time using your browser settings - usually under privacy, site data or clearing browsing data. Clearing site data covers both cookies and browser storage.
7.2. You can also use the site in private (incognito) mode - data stored in such a session is removed when the window is closed.
7.3. Deleting the data does not restrict access to the site. The effect is that a new analytics identifier is generated on your next visit, interface translations are downloaded again, and you are logged out of the admin panel if you were logged in.
7.4. If you wish to object to analytics based on our legitimate interest or request deletion of data concerning you, write to hello@vulcode.com. Your remaining rights are described in the Privacy Policy.
8. Storage period
8.1. The storage period in the browser is indicated in the table in section 4.
8.2. The retention period for analytics data on the server side is described in the Privacy Policy.
9. Changes to this Cookie Policy
9.1. We update this Policy when the technologies we use or the applicable rules change. We announce changes by updating the date at the beginning of the document.
9.2. We encourage you to review this document periodically.
10. Contact
VulCode E-mail: hello@vulcode.com Website: https://vulcode.com
Form protection (Cloudflare Turnstile)
The only third-party mechanism that may store technical data in your browser is Cloudflare Turnstile - a tool that protects the site's forms (including the contact form) against spam, provided by Cloudflare, Inc. Turnstile may store a technical token needed to verify that you are not a bot. This token is not used for tracking, advertising or profiling and is limited to handling forms. Apart from this single exception, the statement in sections 1.3 and 4.2 stands: the site does not set any cookies of its own.
Have questions about this document? Contact us: hello@vulcode.com