ToZ Rituals
RitualsScheduleAboutGuideForumTemple of Zeus

COOKIE & PRIVACY: COOKIE POLICY

ToZ Rituals · tozrituals.org

Operated by: Temple of Zeus Foundation, a private interest foundation under Law No. 25 of 12 June 1995 of the Republic of Panama.

Website: tozrituals.org (“ToZ Rituals”)

Last updated: 18 August 2026

Version: 1.0

Contact: [email protected]

Contents

  1. About this policy
  2. Our approach, and why there is no consent banner
  3. Cookies we use
  4. Browser storage we use (not cookies)
  5. What we do not use
  6. Related data flows that do not use cookies
  7. Managing cookies and storage
  8. Do Not Track and Global Privacy Control
  9. Changes to this policy
  10. Contact

1. About this policy

1.1 This Cookie Policy explains the cookies and similar browser-storage technologies used on tozrituals.org (“ToZ Rituals”, the “Site”), which is operated by Temple of Zeus Foundation. It should be read together with our Privacy Policy.

1.2 Cookies are small text files that a site stores in your browser. Similar technologies include localStorage, sessionStorage, and cache storage, which store information in your browser but are not transmitted to our servers in the way a cookie is.

2. Our approach, and why there is no consent banner

2.1 The Site sets only two cookies. Both are first-party, set by our own backend. We use no analytics, advertising, marketing, or tracking cookies, and no third-party cookies of any kind.

2.2 Both cookies are strictly necessary and are received by every visitor. Cookies that are strictly necessary to provide a service you have requested are exempt from prior-consent requirements under the EU ePrivacy Directive (Article 5(3)) and the UK Privacy and Electronic Communications Regulations (regulation 6(4)). Because every visitor receives only strictly-necessary cookies, the Site operates without a consent banner. If we ever introduce a non-essential cookie, we will ask for your consent first.

3. Cookies we use

toz-rituals-session

Category: Strictly necessary.

Purpose: Encrypted session identifier for our Laravel / Sanctum backend. All session state is held server-side; the cookie value is an encrypted session ID only. It is issued to every visitor, because the Site fetches ritual data from the same-origin API after the page loads. It is not used for tracking, profiling, or analytics.

Lifetime: 2 hours (Max-Age=7200), sliding, re-stamped on each request.

Flags: HttpOnly · Secure · SameSite=Lax · Path=/ · Domain=tozrituals.org.

Set by / recipients: First-party (our backend). Received by all visitors with JavaScript enabled.

Related data: The server-side session record stores your IP address and user-agent (standard framework behaviour), retained until the session expires. See the Privacy Policy.

XSRF-TOKEN

Category: Strictly necessary.

Purpose: Cross-site request forgery (CSRF) protection. The front-end reads this token and echoes it back in the X-XSRF-TOKEN header, so the backend can confirm that a state-changing request genuinely came from our own site. It is a security control, not an identifier, and contains no personal data.

Lifetime: 2 hours (Max-Age=7200), refreshed on each response.

Flags: Secure · SameSite=Lax · Path=/ · Domain=tozrituals.org. It is readable by JavaScript by design (not HttpOnly), because the front-end must read it.

Set by / recipients: First-party. Received by all visitors with JavaScript enabled.

4. Browser storage we use (not cookies)

4.1 The following items are stored in your browser only and are never transmitted to our servers. None of them contains personal data.

KeyMechanismAudiencePurpose
toz-ritual-settingslocalStorageAll visitorsReading preferences for ritual pages: font size, line height, page width, step spacing, mantra layout, and sigil size and position.
timeFormat12hlocalStorageAll visitors12-hour vs 24-hour clock preference for the ritual schedule widget.
pwa-banner-dismissedsessionStorageAll visitorsRemembers, for the current tab only, that the “install this app” banner was dismissed.
toz-v1Cache Storage (service worker)All visitorsOffline / progressive-web-app cache. Precaches the homepage, manifest, and icons, then network-first caches pages you open.

5. What we do not use

5.1 Each of the following was actively checked and confirmed absent, rather than assumed:

  • Google Analytics, Google Tag Manager, and similar (for example _ga, _gid): not used.
  • Advertising or remarketing pixels (Meta, DoubleClick, AdSense): not used.
  • Alternative or self-hosted analytics (Plausible, Matomo, Fathom, Umami, Hotjar, Mixpanel): not used.
  • Cloudflare bot-management or challenge cookies (__cf_bm, cf_clearance): not set; the Site is served through Cloudflare, but those features are not enabled.
  • Third-party embeds or widgets (YouTube, Vimeo, Disqus, Stripe, reCAPTCHA): not used.
  • Visitor tracking or device fingerprinting: not used.

5.2 A maintenance-bypass cookie (toz_maint) exists in the code but is issued only while maintenance mode is switched on. It is not set during normal operation.

5.3 If any of these features is enabled in future (for example, Cloudflare bot management), we will update this policy and, where the law requires, obtain your consent.

6. Related data flows that do not use cookies

6.1 Google Fonts. The Site loads fonts from fonts.googleapis.com and fonts.gstatic.com. This sets no cookie, but it transmits your IP address and user-agent to Google. See the Privacy Policy.

6.2 Server-side sessions. Session data is stored in our own database, keyed by the session cookie; the data itself never lives in your browser.

6.3 Hall of Osiris schedule. The ritual schedule is fetched by our own backend, so your browser never contacts the Hall of Osiris API directly, and no third-party cookie is set by it.

7. Managing cookies and storage

7.1 You can control or delete cookies through your browser settings, and you can clear localStorage, sessionStorage, and cache storage there too. Because the two cookies that every visitor receives are strictly necessary, blocking them may prevent parts of the Site (such as fetching ritual data or submitting secure requests) from working.

7.2 Most browsers let you refuse or remove cookies; see your browser’s help pages for how to do this.

8. Do Not Track and Global Privacy Control

8.1 Because we do not track visitors across sites or over time, and use no advertising or analytics cookies, there is nothing for a Do Not Track or Global Privacy Control signal to stop. We honour these signals by not engaging in such tracking at all.

9. Changes to this policy

9.1 We will update this policy whenever the cookies or storage we use change, or when third-party services, edge features, or authentication behaviour change. The current version is posted on the Site with its date.

10. Contact

Temple of Zeus Foundation, ToZ Rituals

[email protected]  ·  [email protected]

ToZ Rituals

“The Falsehoods of the Wrongful, Will be replaced in the Divine Laws of Justice”

Zeus

Platform

AboutReleasesContributors

Support

Contact

Community

ForumTemple of Zeus

Legal

Terms of ServicePrivacy PolicyCookie Policy

© Copyright Temple of Zeus · Swissreg 848781 · EUIPO 019363328