Oncebook

Cookie policy

Last updated: 9 October 2026

This policy explains which cookies and similar storage techniques the Oncebook iPhone app and its web pages (the shared family page, the password reset page, the landing page and these legal pages) use, what they are for, how long they live, and how to get rid of them. The controller is Szentiványi András Szilveszter e.v. (2800 Tatabánya, Előd vezér utca 18., hello@oncebook.app); the privacy policy covers how personal data is processed.

In short:

  • We only use cookies the service needs to work and to stay secure: four of our own and two Cloudflare security cookies. There are no analytics, advertising or tracking cookies.
  • That is why we do not ask for cookie consent; the bar at the bottom of the page only informs you, there is nothing to accept.
  • The app itself uses no cookies.

1. What is a cookie?

A cookie is a small text file a website stores in your browser and that the browser sends back with later requests, so the site recognises that you come from the same browser (for example that you already entered the password). The iPhone app is not a browser: it uses no cookies, but keeps your sign-in and a few settings on the device (see section 4).

2. Which cookies do the web pages use?

CookiePurposeWhereLifetimeSet by
oncebook-sessionSession: remembers that you entered the shared page's password and links the steps of a form (for example the password reset). Contains a random identifier, no personal data.All our web pagesUntil at most 120 minutes of inactivityUs (first party)
XSRF-TOKENSecurity: protects forms against forged requests started from other sites (CSRF protection).All our web pagesUntil at most 120 minutes of inactivityUs (first party)
share_id"Keep me signed in on this device": set only if you tick that option when entering the password. Contains an encrypted check value derived from the share password (not the password itself); becomes invalid when the password is changed or sharing is turned off.Shared family page365 daysUs (first party)
share_seen_idStores the time of your last visit so that next time we can mark which memories are new since then. Contains a timestamp, nothing else.Shared family page365 daysUs (first party)
__cf_bmSecurity: Cloudflare's bot filtering uses it to tell human visitors from automated programs (for example password-guessing scripts). Contains a random identifier.All our web pages30 minutesCloudflare (on our behalf)
cf_clearanceSecurity: records that your browser passed Cloudflare's check, so it is not checked again on every page.All our web pagesFrom 30 minutes up to 1 year, as configured in CloudflareCloudflare (on our behalf)

The id is the random token in the shared page's link; the cookies cannot be tied to your name, because visitors of the shared page have no account. Every cookie travels only over encrypted connections ("Secure"), and apart from XSRF-TOKEN (which the browser must read for the form protection) none can be read by the page's scripts ("HttpOnly").

The bar at the bottom of the page only informs you: since none of these cookies needs consent, there is nothing to accept or refuse, and the "Got it" button merely hides the bar (we remember that in your browser's local storage, not in a cookie).

3. Cloudflare

Our web pages are served through the network of Cloudflare (Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA): as our processor, Cloudflare filters attacks and automated programs before a request reaches our server. For this it sets the two security cookies above (__cf_bm, cf_clearance) and processes your IP address and technical browser characteristics. Cloudflare also provides the human-visitor check Turnstile on the shared page's password form. Neither tracks you across sites or is used for advertising. There are no other external elements: fonts and every image are served from our own server. Sections 5 and 6 of the privacy policy also cover Cloudflare.

4. What does the app store on your device?

The iPhone app uses no cookies, but keeps a few things on the phone to work; none of this leaves the phone or reaches us:

All of this disappears when you delete the app; a reinstalled app also clears the sign-in token on its first launch.

5. Legal basis

Each cookie above is needed to provide the service you explicitly asked for or to keep it secure (remembering the password sign-in, protecting forms, the "keep me signed in" option you ticked, the "new" marker, filtering attacks and bots), so under section 155(4) of Hungarian Act C of 2003 on electronic communications (implementing the ePrivacy Directive) no consent is required to set them. The personal data they involve (IP address, browser characteristics, session identifier) is processed on the basis of our legitimate interest in the security of the service (GDPR Art. 6(1)(f)); see section 4 of the privacy policy.

6. How to delete or block cookies

You can view, delete or block cookies in your browser settings at any time (Safari: Settings → Safari → Advanced → Website Data; Chrome: Settings → Privacy and security → Cookies). Without the "keep me signed in" cookie the shared page simply asks for the password again; without the session and security cookies (including Cloudflare's) the password sign-in does not work, or the page asks for checks more often. The family can also invalidate the "keep me signed in" cookie by changing the share password.

7. Changes to this policy

If we introduce a new cookie or change the purpose or lifetime of an existing one, we update this page and, for material changes, tell you in the app or by email. Version: 2026-10-09.