HOLYFRAG
Cookies policy
Last updated:
We use necessary forum cookies for secure sign-in and ordinary site functions, and a necessary cookie to remember your analytics choice. If Google Analytics is enabled, it runs only with your permission. We do not add advertising cookies. The optional Discord widget on the main website is loaded only when you ask for it.
Forum cookies and their duration
_community_session — set by the HolyFrag forum for the browser session, form security, sign-in state and temporary messages. It has no fixed expiry date and is normally removed when the browser session ends; a browser’s session-restore settings may retain it.
member_session_id — set after successful sign-in to recognise your signed-in session. It expires after 30 days. Signing out deletes this cookie and resets the browser session.
Both cookies are limited to the forum host and use HttpOnly and SameSite=Lax protections, with Secure enabled in production. They are used to deliver and protect the functions you request, so we do not ask you to accept them through a consent banner. Blocking them can stop sign-in, forms and account features from working.
Remembering your privacy choice
hf_analytics_consent — a first-party preference cookie storing only the versioned choice v1.granted or v1.denied. We set it after you allow or reject analytics so that the main website and forum can respect the same choice. It is shared on holyfrag.com and its subdomains, uses SameSite=Lax and Secure on HTTPS, and expires 180 days after you save your choice. It does not contain an account ID.
This choice cookie is necessary to remember and apply your privacy preference; it is separate from optional measurement cookies and is also used when you reject analytics. It is readable by our page code so the consent controls can work. Deleting it resets the choice: analytics stays off until you allow it again.
Optional analytics cookies
If analytics is enabled, Google Analytics 4 loads only after you choose “Allow analytics”. Before that choice, our integration makes no Google Analytics requests, including measurement without cookies. Choose “Reject analytics” to continue without it. No Analytics tag loads without a valid measurement ID.
_ga — an optional first-party Google Analytics cookie used to distinguish browsers. _ga_<stream> — an optional first-party Google Analytics cookie used to maintain session state. We configure these cookies on holyfrag.com with a 180-day lifetime; activity-based renewal is disabled, and your browser may impose a shorter lifetime. These cookies can recognise a browser across the main website and forum. They do not use your HolyFrag account ID.
Analytics helps us understand visits and engagement. We send sanitised page classifications and generic page titles, not account names, post text, search queries or sign-in tokens. Google also receives technical browser information and request data. Our integration disables Google signals and advertising personalisation, and keeps advertising storage and advertising user-data consent denied. Read the privacy policy for recipients and international processing.
Open “Cookie settings” and choose “Reject analytics” at any time to withdraw consent. Our code disables further measurement and clears the Google Analytics cookies it can access. If Google’s tag was loaded, the page reloads to unload it. Already received data is not deleted by this action. Other open pages apply the shared choice when they become active or reload; reload those pages to apply it immediately. The shop has separate consent controls.
The 180-day cookie lifetime is a browser-storage limit, not a promise to erase server-side analytics data after 180 days. Analytics record retention depends on the configured property and Google’s applicable terms; contact hello@holyfrag.com for information or to exercise your data rights.
Optional Discord content
The main website shows a placeholder instead of automatically contacting Discord. Selecting the load button allows the widget to connect to Discord, sharing technical information such as your IP address and browser details. Discord may use its own cookies or similar technologies under its privacy policy.
Your choice is remembered only in the current page’s memory, not in a persistent cookie or browser storage. Use the hide or disable control to remove the widget and stop further requests from it; reloading or closing the page clears the choice. This does not erase information already received by Discord or its existing cookies. You can also join through the ordinary Discord link without loading the widget.
Sign-in providers and external links
Choosing an available Google, Steam or X sign-in option takes you through that provider’s service, which has its own cookies and privacy settings. Following a link to Discord or another site also makes that service’s rules relevant. These external cookies are not our forum sign-in cookies.
Cloudflare delivers and protects the main website and may use security technologies when needed to handle a request. We do not use Cloudflare Web Analytics or an advertising tracker on these pages. We will update this notice and obtain consent where required before adding non-essential tracking.
Your browser controls
You can inspect, delete or block cookies in your browser’s privacy settings. Deleting forum cookies signs this browser out; it does not delete your account or server records. Blocking third-party cookies may affect optional embeds or provider sign-in.
For questions or a data-rights request, contact hello@holyfrag.com. The privacy policy explains server-side information, including any presence timestamp; changing browser cookies alone does not erase those records.