This notice covers cookies and similar storage used on MuffSniffer. MuffSniffer uses two signed first-party cookies for the necessary features described below. It does not store submitted searches in your browser. No analytics, advertising, unrelated preference, or social-media cookies are enabled, and we do not use cross-site behavioural tracking. The necessary age-confirmation token is also transformed server-side into a day-specific keyed digest solely to deduplicate the anonymous daily visitor total described below; the raw token is not copied into analytics storage.
Necessary first-party cookies
| Name | Provider | Purpose and contents | Duration |
|---|---|---|---|
__Host-muffsniffer-age |
MuffSniffer | Stores only a signed token recording that the visitor completed the self-declared adult entry. Keeping this separate prevents an operator login or form-security session from being made persistent. For aggregate visitor counting, a day-specific keyed digest derived from this token is retained in Redis for no more than 48 hours; it is not stored with searches and is replaced by an hourly/daily total. | 365 days, unless site data are cleared sooner. |
__Host-muffsniffer-session |
MuffSniffer | Stores a form-security token, a random report identifier, up to ten authorised case references, and—only for operators—login, role, session-version, and recent-authentication state. The contents are integrity-protected but not encrypted, so no report explanation, email, password, access code, or raw IP address is placed in the cookie. | Normally until the browser session ends. An authenticated operator session can persist for up to eight hours. |
The production cookies are Secure, HttpOnly, SameSite=Lax, host-only, and sent only over HTTPS. They are necessary for the feature you request: remembering entry to the adult service, protecting a form, retaining authorised case access, or signing in as an operator. You may delete them using your browser controls. Deleting the age-confirmation cookie requires confirmation again; deleting the session cookie loses session-based case authorisation and any operator login.
Cloudflare Turnstile
When anti-abuse protection is enabled, pages containing a report form load Cloudflare Turnstile and display its widget. Cloudflare processes technical and interaction signals such as IP address, user agent, browser characteristics, referring page, and challenge outcome to distinguish legitimate submissions from automated abuse. Cloudflare may use cookies or similar storage that it considers necessary to provide the challenge. MuffSniffer receives a short-lived verification token and the validation result, not an advertising profile. See Cloudflare's Privacy Policy.
Why there is no consent banner
The storage described above is limited to what we consider technically necessary for requested functionality and security. It is therefore used without cookie consent. If we introduce any non-essential cookie or similar technology, it will remain off until an appropriate prior choice is offered, and this notice will identify its provider, purpose, data, and duration.