Skip to main content
Private Preview·Early access by invitation.Request access →
Kirimana.
Legal

Cookies + browser storage

Status: living document. Updated alongside the privacy policy. Last updated: 26 April 2026.

What this page is

This page explains every cookie and localStorage entry the kirimana.io website may set in your browser, why, and how to control it. The cookie banner you see on first visit is the primary control surface.

Categories

CategoryDefaultPurpose
Necessaryalways onRequired for sign-in + security
PersonalizationoffReorder the site for your role
Analyticsoff(Reserved, currently unused)
Marketingoff(Reserved, currently unused)

You cannot disable Necessary, without it, the site cannot keep you signed in or protect the early-access form against abuse. You can disable any other category at any time.

What’s set in each category

Necessary

NameTypeLifetimeWhat it does
better-auth.session_tokenHttpOnly cookie30 daysKeeps you signed in (after invitation)
better-auth.csrf_tokenHttpOnly cookiesessionCross-site request forgery protection on auth endpoints
kirimana:play:v1localStorageuntil clearedRemembers your progress in the Kiri: Data Cruncher game (levels cleared, best scores, skill tier, effects setting). Written only if you play. Sent to us only if you are signed in, so your scores follow your account.
kirimana:invaders:v1localStorageuntil clearedThe same, for the Kiri: Data Defender game (waves cleared, best scores, effects setting).
kirimana:memory:v1localStorageuntil clearedThe same, for the Kiri: Runbook game (levels cleared, best scores, effects and mute settings).

Personalization (off until you accept)

NameTypeLifetimeWhat it does
kirimana.persona.slugcookie (non-HttpOnly)1 yearTells the server which role to render content for
kirimana.personalocalStorageuntil clearedStores your full persona profile (role, stack, pain) so the Kiri interview doesn’t repeat
kirimana.consentlocalStorageuntil clearedRecords which cookie categories you’ve accepted

When you revoke Personalization consent, both the cookie and the two localStorage entries are cleared immediately.

The game leaderboard

If you play any game under Play & Learn while signed in, your best score per level or wave is stored against your account so it survives a new browser. That alone lists you nowhere.

You appear on a public high-score board only after you choose a display name on the game’s page — an optional, free-text name that is the only thing published, and the same name across every game. Your email address never appears. Remove the name at any time and you drop off the board immediately while keeping your scores; deleting your account removes both.

Analytics (reserved)

We don’t run analytics today. When we do, we’ll choose a privacy-respecting provider that:

  • Honors Do-Not-Track / Global Privacy Control
  • Doesn’t fingerprint visitors
  • Stores aggregate data only
  • Hosts data in the EU

We’ll update this page before turning anything on.

Marketing (reserved)

We don’t run marketing pixels today. When we add a newsletter, we’ll add an explicit opt-in to the cookie banner.

What we DO NOT use

  • ❌ Google Analytics
  • ❌ Meta Pixel
  • ❌ Hotjar / FullStory / session-replay tools
  • ❌ Cross-site tracking pixels of any kind
  • ❌ Browser fingerprinting

Manage your preferences

Use the cookie banner (re-open it from any page footer link when we add the trigger). Or:

  • Sign out to remove the session cookie
  • Visit /account → Consent to revoke Personalization
  • Clear site data in your browser to remove everything

Questions

privacy@kirimana.io, we respond within 30 days.