All policies

Cookie policy

Every cookie CoreSkill sets exists to make the site work: keeping you signed in, remembering your language and your current business, and carrying a freshly created secret to the page that shows it once. No advertising cookies, no third-party behavior tracking.

Effective 22/9/2026

No lawyer has reviewed this text

This page lists exactly what the software puts in your browser, and it is accurate as a technical description. It has not been reviewed by a lawyer. Rules on cookies and on when consent is required differ by country, so Core Skill should have a qualified person read it before relying on it in a dispute.

A cookie is a small piece of data a website asks your browser to hold and send back on later requests. CoreSkill uses cookies for four things: to keep you signed in, to remember your language, to remember which business you were working in, and to carry a freshly created secret to the page that displays it once. Nothing here follows you to another website.

Cookies that CoreSkill sets

NameWhat it is forLifetime
authjs.session-tokenKeeps you signed in. HttpOnly, so scripts on the page cannot read it. It holds a signed token, never your password.Until you sign out, or the session expires
authjs.csrf-tokenProtects the sign-in forms against cross-site request forgery. Without it another site could submit forms on your behalf.Session
authjs.callback-urlRemembers the page you were trying to reach, so you land there after signing in instead of on the dashboard.Session
localeRemembers whether you chose English or Tieng Viet. Set only when you pick a language yourself; without it the server guesses once from the country of your IP address.365 days
orgRemembers the business you last opened, so you land straight back in it instead of choosing again.365 days
mfa_setup, mfa_required, mfa_codesCarry the state of two-factor setup and verification between steps. HttpOnly, and removed as soon as the step finishes.Minutes
gmail_oauth_stateA single-use anti-forgery value for the Gmail connection flow in the admin area. Without it somebody could trick an administrator into connecting an attacker's mailbox.10 minutes, single use

Over HTTPS the session cookies carry a __Secure- prefix, which instructs the browser to refuse to send them over an unencrypted connection.

Cookies that show a secret once

When you have just issued a key or created an invitation, the system puts that value in a very short-lived HttpOnly cookie so the next page can display it, then deletes the cookie as soon as it has been shown. Only a hash of the key is stored, so afterwards nobody can read it back to you, not even a system administrator.

NameSet whenLifetime
new_key, new_keysYou issue one or several service keys on a skill server.120 seconds
new_member_key, new_member_keysYou issue one or several staff keys.120 seconds
new_agent_keyYou issue a management MCP key.120 seconds
new_inviteYou create an invitation and the link is shown for copying.120 seconds

Why a secret never goes in the address bar

A value in a URL ends up in your browser history, in the access log of the server and of every proxy in between, and it travels along whenever somebody pastes the link to a colleague. An HttpOnly cookie that lives for two minutes does none of that. That is why a new key appears on the next page rather than in the address bar.

Cookies set by Cloudflare

CoreSkill is delivered through Cloudflare, which shields the site from attack and filters automated traffic. Cloudflare may set cookies of its own. These are security cookies, not advertising cookies: they describe traffic patterns rather than people, and Core Skill cannot learn anything about you from them.

NameWhat it is forLifetime
__cf_bmTells automated traffic apart from human traffic so that attacks are filtered before they reach the application.30 minutes
_cfuvidGroups the requests of one visitor so that rate limits apply fairly. Set only when the relevant Cloudflare feature is enabled.Session

Stored on your device, but not cookies

  • Light or dark theme and whether the sidebar is collapsed live in your browser's local storage rather than in a cookie. They are therefore never sent to the server, and they are remembered per device.
  • The width and open state of the help panel are stored the same way, for the same reason.
  • These are display conveniences only. Clear them and the interface returns to its defaults; nothing is lost.
  • Local storage is also why your theme survives signing out: it was never tied to your account.

No advertising and no analytics

CoreSkill embeds no analytics suite, no advertising pixel, no session recorder and no third-party behavior tracking of any kind. No cookie here follows you to another website. If an administrator enables Google or Facebook sign-in, those providers set their own cookies on their own sign-in pages, under their own policies, and only at the moment you choose to use them.

Consent, and why there is no banner

Cookies that are strictly necessary for a service the user has asked for do not require prior consent. Every cookie listed above falls in that category: signing in, security, your own language choice, and delivering a secret you have just asked the system to create. Because there is nothing optional to refuse, CoreSkill shows no cookie banner. If tracking or analytics cookies are ever introduced, this page will be updated and consent will be requested before they are set.

What you control

  • Every browser lets you inspect and delete a site's cookies. Deleting the CoreSkill cookies signs you out and resets the language to the default.
  • Block this site's cookies entirely and you cannot sign in, because the session is a cookie. That is a technical limit, not a design choice.
  • On a shared machine use Sign out when you finish, rather than just closing the tab.
  • Clearing local storage resets the theme and the sidebar, and affects nothing else.

Changes and contact

When the list above changes, this page changes with it and the effective date is updated. Questions about cookies and personal data go to [email protected], anything else to [email protected], or by post to Core Skill, coreskill.app. This policy takes effect on 22/9/2026 and is governed by the law of Core Skill.