Legal

Cookie Policy

Last updated October 3, 2026

Alyona uses a small number of cookies and browser storage, all of them needed for the service or set because you asked for them. There are no analytics, advertising or third-party tracking cookies.

1. Cookies we set

NamePurposeTypeDuration
authjs.session-tokenKeeps you signed in. Holds a random token; your session lives on our server and can be revoked.Strictly necessary30 days
authjs.csrf-tokenProtects sign-in and sign-out against cross-site request forgery.Strictly necessarySession
authjs.callback-urlRemembers where to send you after signing in.Strictly necessarySession
authjs.state, authjs.pkce.code_verifierSecurity checks while you sign in with Google.Strictly necessary15 minutes
alyona-localeRemembers the language you chose. Only set when you pick one.Preference1 year

On secure (HTTPS) connections the Auth.js cookie names start with __Secure- or __Host-. All of them are first-party and HTTP-only (scripts on the page can’t read them).

2. Browser storage

KeyPurposeTypeDuration
alyona:volumeRemembers your player volume on this device.PreferenceUntil you clear it

3. Third parties

When you sign in, Google sets its own cookies on its sign-in pages under its own policy. Profile photos are loaded from Google’s servers without sending them which page you are on. Alyona sets no other third-party cookies.

4. Your choices

Because these cookies are strictly necessary or set at your request, we don’t show a cookie banner. You can delete or block cookies in your browser settings — but blocking the strictly necessary ones means you can’t sign in. Questions: legal@alyona.io.