Cookie Policy
Last updated: August 24, 2026
1. Overview
Universal Life Source (ULS) uses cookies to operate the platform and provide a secure authentication experience. This Cookie Policy describes what cookies we set, why we set them, and how long they last.
ULS does not use advertising cookies, tracking cookies, or third-party analytics cookies. All cookies set by ULS are strictly necessary for the operation of the platform.
2. What Is a Cookie?
A cookie is a small text file that a website stores in your browser. Cookies allow websites to remember information between page loads and across sessions. Cookies are not programs and cannot execute code or access other data on your device.
3. Cookies We Set
| Cookie Name | Purpose | Type | Duration |
|---|---|---|---|
| access_token | Stores your authenticated session after login. Contains a signed JWT token. Allows you to stay logged in across page loads. | Essential (First-party) | 8 hours from login |
| csrf_token | Protects against cross-site request forgery (CSRF) on the login form. Must match between the cookie and the hidden form field. | Essential (First-party) | Session (deleted on browser close) |
| oidc_state | Used during the OIDC authentication flow to prevent session fixation attacks. Validates that the authentication response came from the expected identity provider. | Essential (First-party) | 10 minutes (auth flow only) |
4. Third-Party Cookies
ULS does not set any third-party cookies. However, the following third-party services involved in operating the platform may set cookies as part of their own infrastructure:
- Cloudflare: May set cookies related to security and bot detection (e.g.,
__cf_bm). These are managed by Cloudflare's security infrastructure and are not controlled by ULS. - Logto: May set cookies during the authentication flow when redirecting to the Logto login page. These are managed by Logto's identity service.
Neither ULS nor these third parties use cookies for advertising, tracking, or behavioral profiling.
5. Managing Cookies
You can control and delete cookies through your browser settings. However, please note:
- Disabling the
access_tokencookie will prevent you from logging in — the platform cannot function without it - Disabling the
csrf_tokencookie will prevent you from using the local login form - Disabling the
oidc_statecookie will prevent OIDC (Logto) authentication from completing
All ULS cookies are set with the following security attributes:
- HttpOnly: The cookie cannot be accessed by JavaScript, preventing XSS-based theft
- Secure: The cookie is only sent over HTTPS encrypted connections
- SameSite: The cookie is not sent on cross-site requests, preventing CSRF
6. Changes to This Policy
If we add, remove, or change any cookies, we will update this page and revise the "Last updated" date. We will not add new categories of cookies (advertising, analytics, or tracking) without providing notice and, where required by law, obtaining your consent.
7. Contact
For questions about cookies, contact [email protected].