Cookies Notice (EN)
⚠ Документ - DRAFT, требует проверки юристом до публикации.
Cookies Notice (English)
Version: 2026-09-03
This site uses strictly-necessary cookies only. We do not use cookies for analytics, advertising, behavioural targeting, or third-party tracking.
Cookies in use
| Name | Purpose | Lifetime | Type |
|---|---|---|---|
| `mtt_session` | session authentication | 30 days | strictly necessary |
| `mtt_csrf` | CSRF protection (double-submit pattern) | 30 days | strictly necessary |
| `mtt_lang` | language preference (ru / en) | 365 days | strictly necessary |
| `mtt_cookie_seen` | informational banner dismissal | 365 days | strictly necessary |
| `mtt_uh` | email hash the intermediate Russian node journalled requests by; no longer set as of 3 September 2026, copies already issued expire or are cleared on logout | 30 days | strictly necessary |
| `region` | marked that a Russian visitor had been redirected to the Russian address of the site; no longer set as of 3 September 2026, there is no redirect any more | 30 days | strictly necessary |
Strictly-necessary cookies are exempt from the prior-consent requirement under the UK PECR (Privacy and Electronic Communications Regulations 2003, reg. 6(4)) and the ePrivacy Directive 2002/58/EC, Article 5(3). Nonetheless, we display an informational banner the first time a user visits the site, so the disclosure is plainly visible regardless of legal exemption.
No third-party cookies
We do not embed third-party scripts that set their own cookies (no Google Analytics, no Facebook Pixel, no Hotjar, no Sentry-with-cookies, no Cloudflare-bot-detection-cookies). Two third parties receive data without setting a cookie. Google LLC receives the IP address and User-Agent of every visitor, because the page loads its webfonts from Google Fonts. Telegram FZ-LLC receives notification data after the user opts in (`consent_kind='tg'`, see `/legal/consent-tg`), and separately receives the operator's own internal alerts, which carry the user's email and IP and are not gated by that consent. Both are described in `/legal/privacy-en` § 4 and § 4a.
Browser controls
You can clear or block cookies through your browser settings. Blocking strictly-necessary cookies will prevent log-in and CSRF protection from functioning, so the site will not be usable in that mode.
Version history
- v1 - initial notice.
- v2 - 2026-08-31: corrected the CSRF entry, which named the form field `_csrf` rather than the cookie `mtt_csrf` and called it session-scoped when it lasts 30 days; added `mtt_uh` and `region`, both set by the Russian contour and both ending with it; corrected the claim that Telegram was the only third party receiving data, which left out Google Fonts.
- v3 - 2026-09-03: `mtt_uh` and `region` are no longer set. Both served the intermediate Russian node, which no longer receives traffic. Their rows stay in the table because copies issued earlier sit in browsers for up to 30 days, and a cookie a visitor still carries has to stay disclosed.
- v4 - 2026-09-03: the node those two cookies served was deleted, disk and all. Nothing changes for a visitor who still carries one - the rows stay until the copies expire.
Contact
support@measurethetreasure.com.