Cookie Policy

Last updated: August 24, 2026

1. Overview

Universal Life Source (ULS) uses cookies to operate the platform and provide a secure authentication experience. This Cookie Policy describes what cookies we set, why we set them, and how long they last.

ULS does not use advertising cookies, tracking cookies, or third-party analytics cookies. All cookies set by ULS are strictly necessary for the operation of the platform.

2. What Is a Cookie?

A cookie is a small text file that a website stores in your browser. Cookies allow websites to remember information between page loads and across sessions. Cookies are not programs and cannot execute code or access other data on your device.

3. Cookies We Set

Cookie Name Purpose Type Duration
access_token Stores your authenticated session after login. Contains a signed JWT token. Allows you to stay logged in across page loads. Essential (First-party) 8 hours from login
csrf_token Protects against cross-site request forgery (CSRF) on the login form. Must match between the cookie and the hidden form field. Essential (First-party) Session (deleted on browser close)
oidc_state Used during the OIDC authentication flow to prevent session fixation attacks. Validates that the authentication response came from the expected identity provider. Essential (First-party) 10 minutes (auth flow only)

4. Third-Party Cookies

ULS does not set any third-party cookies. However, the following third-party services involved in operating the platform may set cookies as part of their own infrastructure:

  • Cloudflare: May set cookies related to security and bot detection (e.g., __cf_bm). These are managed by Cloudflare's security infrastructure and are not controlled by ULS.
  • Logto: May set cookies during the authentication flow when redirecting to the Logto login page. These are managed by Logto's identity service.

Neither ULS nor these third parties use cookies for advertising, tracking, or behavioral profiling.

5. Managing Cookies

You can control and delete cookies through your browser settings. However, please note:

  • Disabling the access_token cookie will prevent you from logging in — the platform cannot function without it
  • Disabling the csrf_token cookie will prevent you from using the local login form
  • Disabling the oidc_state cookie will prevent OIDC (Logto) authentication from completing

All ULS cookies are set with the following security attributes:

  • HttpOnly: The cookie cannot be accessed by JavaScript, preventing XSS-based theft
  • Secure: The cookie is only sent over HTTPS encrypted connections
  • SameSite: The cookie is not sent on cross-site requests, preventing CSRF

6. Changes to This Policy

If we add, remove, or change any cookies, we will update this page and revise the "Last updated" date. We will not add new categories of cookies (advertising, analytics, or tracking) without providing notice and, where required by law, obtaining your consent.

7. Contact

For questions about cookies, contact [email protected].