This page is not final: the entity details in square brackets are still to be filled in.

Legal

Cookie policy

Only strictly necessary authentication and security technology is used. There are no analytics, advertising, or profiling cookies.

Last updated: 21 July 2026

The short version

The public marketing site does not create an Eutetic login session and does not use analytics, advertising, or profiling cookies.

When you log in on app.eutetic.com, strictly necessary host-only session cookies keep you authenticated. Security-sensitive forms also load Cloudflare Turnstile to reduce automated abuse.

What gets set, exactly

On login, our Supabase authentication layer sets:

  • One logical session, which may be split across more than one cookie when required by browser size limits. It contains the credentials needed to refresh and prove the session; its signed claims can include your user identifier and email.
  • The cookies are Secure in production, HttpOnly, SameSite=Lax and host-only: they are sent to app.eutetic.com, not to eutetic.com or unrelated subdomains.

They are first-party and exist only to keep you logged in and protect authenticated requests. Their lifetime follows the configured Supabase session policy; logging out clears the current session.

External security service

Login, signup and password-recovery forms load Cloudflare Turnstile from challenges.cloudflare.com. The managed challenge evaluates browser and interaction signals and returns a short-lived, one-use token that our authentication service validates. Turnstile pre-clearance is not enabled by Eutetic, so the widget is not used to create a cf_clearance cookie.

The home-page video is served by Eutetic rather than embedded from a video platform. There is no analytics, tag manager, advertising script, social button, or tracking pixel.

Why there is no consent banner

This is the part worth reading, because it is a conclusion and not a preference.

Article 5(3) of the ePrivacy Directive (2002/58/EC) says that storing information on a user's device requires consent — but it carves out storage that is strictly necessary in order to provide a service the user has explicitly asked for. The Garante's cookie guidelines of 10 June 2021 say the same in Italian practice: technical cookies need an information notice, not consent, and session cookies that keep a login alive are the textbook example.

Our session cookie is exactly that. You asked to log in; the cookie is what makes being logged in possible; without it the service you requested does not work. It is strictly necessary, so it needs no consent — and since there is nothing else on this site to ask you about, a banner would have nothing to ask.

So this site has a cookie page, which is required, and no cookie banner, which is not. A banner offering a choice that does not exist is not compliance; it is noise.

What would change this

The reasoning above holds only while the list above stays as short as it is. If anything is ever added to this site that stores or reads information on your device beyond what is strictly necessary, consent becomes mandatory and a banner has to appear before that thing loads.

That includes analytics, embedded video, embedded maps, social buttons, chat widgets, advertising and any measurement pixel.

Whoever adds one of those is the person who has to add the banner, update this page, and stop the new thing from loading until consent is given. Please treat this paragraph as part of the definition of done.

Refusing or removing the cookie

The straightforward way is not to log in — no login, no cookie. If you are logged in, logging out clears it.

Every browser also lets you see, block and delete cookies from its settings, and you can do that here at any time. Fair warning: block this one and the login stops working, because it is the mechanism by which the login works. That is not a penalty for refusing, it is the same fact stated from the other side.

The rest

The session cookie is personal data, so the privacy policy applies to it: who the controller is, how long we keep it, and your rights over it are all set out there.

Questions about this page go to [EMAIL PRIVACY].