Legal
Cookie Policy
Last updated 19 September 2026
1. What cookies are
A cookie is a small text file your browser stores when you visit a site. It lets the site recognise the same browser on the next request.
Similar technologies such as local storage work the same way for this purpose, and this policy covers them too.
2. The categories we use
We keep this short on purpose. Upsilon runs on strictly necessary cookies, plus optional analytics if you agree to them.
- Strictly necessary: sign in, security and load balancing. These are set without consent because the service cannot work without them.
- Functional: remembering a preference such as your last view. Set only where you use the feature.
- Analytics: aggregated usage figures that show us which parts of the product work. Set only with your consent.
- Advertising: none. We do not run ad or tracking pixels on this site.
3. The session cookie
The one cookie every signed in user gets is the session cookie, named [authjs.session-token].
It holds a signed token that identifies your session, never your password and never your CV. It is HttpOnly and Secure, so scripts on the page cannot read it.
It expires after [30] days or when you log out, whichever comes first. Two short lived helpers, [authjs.csrf-token] and [authjs.callback-url], protect the login flow and are cleared with your session.
4. How to control cookies
You can change or withdraw your consent for optional cookies at any time via [cookie settings link].
Every browser also lets you block or delete cookies in its settings. Blocking strictly necessary cookies will log you out and stop the site from working.
We honour Global Privacy Control signals where your browser sends them.
5. Contact
Questions about this policy go to [privacy@example.com]. The Privacy Policy explains what we do with the data behind these cookies.