Cookie Policy
A precise account of the cookies 5mdev uses today. We currently use necessary cookies only—no advertising and no analytics cookies.
Effective and last updated · August 19, 2026
1. What cookies are
Cookies are small text records stored by your browser and returned to a website on later requests. They can keep a session secure, complete a sign-in flow, remember a choice, or—on some websites—measure or advertise. Similar technologies include local storage, pixels, and device identifiers.
2. Our current position
5mdev currently sets only cookies that are strictly necessary to provide authentication, account security, OAuth continuity, safe redirects, and the cookie notice itself. We do not currently load analytics, behavioral advertising, retargeting, or social tracking cookies.
Necessary cookies do not require optional consent in many jurisdictions because the requested service cannot work securely without them. We still provide a clear notice and a permanent “Cookie settings” control in the footer. Closing the notice without saving does not set the notice-choice cookie.
3. Cookie inventory
| Cookie or pattern | Purpose | Typical duration | Category |
|---|---|---|---|
authjs.session-token or __Secure-authjs.session-token | Keeps an authenticated session and helps protect account access. The secure-prefixed form is used over HTTPS. | Session or up to approximately 30 days, depending on session activity and configuration. | Necessary |
authjs.csrf-token or secure host variant | Helps prevent cross-site request forgery during authentication actions. | Session or short-lived. | Necessary |
authjs.callback-url or secure host variant | Returns you to the intended 5mdev page after authentication. | Short-lived or session. | Necessary |
authjs.state, authjs.pkce.code_verifier, authjs.nonce, or secure variants | Validates Discord or Google OAuth flows and helps prevent interception, replay, and request-forgery attacks. | Short-lived; normally deleted or expired after the sign-in flow. | Necessary |
5mdev_cookie_notice | Records the current version of the cookie notice so it is not shown on every visit. | 180 days, unless you delete it earlier or the notice version changes. | Necessary preference |
Not every authentication cookie appears on every visit. Exact secure prefixes and temporary OAuth cookies depend on the protocol, provider, and stage of sign-in.
4. Third parties and external links
Discord or Google may set cookies on their own domains when you choose those providers. Tebex, GitHub, Google Drive, and other external destinations may also set cookies after you follow a link. Those cookies are controlled by the third party and covered by its policy, not this inventory.
Infrastructure providers may process request information to deliver and secure the Service, but 5mdev does not authorize them to place advertising cookies through our pages.
5. Your controls
Select “Accept necessary cookies” in the notice to remember that you have seen the current disclosure. Use “Cookie settings” in the footer to reopen it. You can also inspect, block, or delete cookies through browser settings.
Blocking authentication or security cookies may prevent login, OAuth, protected forms, or other account features from working. Because no analytics or advertising cookies are active, opt-out preference signals such as Global Privacy Control do not change tracking behavior at this time.
6. Future optional cookies
If we later introduce analytics, personalization, or advertising cookies, we will update this policy and the inventory. Where consent is required, those cookies will remain off until you make a specific affirmative choice. A previous acknowledgement of necessary cookies will not be treated as consent to a new optional purpose.
7. Questions
Questions about cookies or privacy can be sent to [email protected].