Cookie policy
Last updated: 9 October 2026
This policy explains which cookies and similar storage techniques the Oncebook iPhone app and its web pages (the shared family page, the password reset page, the landing page and these legal pages) use, what they are for, how long they live, and how to get rid of them. The controller is Szentiványi András Szilveszter e.v. (2800 Tatabánya, Előd vezér utca 18., hello@oncebook.app); the privacy policy covers how personal data is processed.
In short:
- We only use cookies the service needs to work and to stay secure: four of our own and two Cloudflare security cookies. There are no analytics, advertising or tracking cookies.
- That is why we do not ask for cookie consent; the bar at the bottom of the page only informs you, there is nothing to accept.
- The app itself uses no cookies.
1. What is a cookie?
A cookie is a small text file a website stores in your browser and that the browser sends back with later requests, so the site recognises that you come from the same browser (for example that you already entered the password). The iPhone app is not a browser: it uses no cookies, but keeps your sign-in and a few settings on the device (see section 4).
2. Which cookies do the web pages use?
| Cookie | Purpose | Where | Lifetime | Set by |
|---|---|---|---|---|
oncebook-session | Session: remembers that you entered the shared page's password and links the steps of a form (for example the password reset). Contains a random identifier, no personal data. | All our web pages | Until at most 120 minutes of inactivity | Us (first party) |
XSRF-TOKEN | Security: protects forms against forged requests started from other sites (CSRF protection). | All our web pages | Until at most 120 minutes of inactivity | Us (first party) |
share_id | "Keep me signed in on this device": set only if you tick that option when entering the password. Contains an encrypted check value derived from the share password (not the password itself); becomes invalid when the password is changed or sharing is turned off. | Shared family page | 365 days | Us (first party) |
share_seen_id | Stores the time of your last visit so that next time we can mark which memories are new since then. Contains a timestamp, nothing else. | Shared family page | 365 days | Us (first party) |
__cf_bm | Security: Cloudflare's bot filtering uses it to tell human visitors from automated programs (for example password-guessing scripts). Contains a random identifier. | All our web pages | 30 minutes | Cloudflare (on our behalf) |
cf_clearance | Security: records that your browser passed Cloudflare's check, so it is not checked again on every page. | All our web pages | From 30 minutes up to 1 year, as configured in Cloudflare | Cloudflare (on our behalf) |
The id is the random token in the shared page's link; the cookies cannot be tied to your name, because visitors of the shared page have no account. Every cookie travels only over encrypted connections ("Secure"), and apart from XSRF-TOKEN (which the browser must read for the form protection) none can be read by the page's scripts ("HttpOnly").
The bar at the bottom of the page only informs you: since none of these cookies needs consent, there is nothing to accept or refuse, and the "Got it" button merely hides the bar (we remember that in your browser's local storage, not in a cookie).
3. Cloudflare
Our web pages are served through the network of Cloudflare (Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA): as our processor, Cloudflare filters attacks and automated programs before a request reaches our server. For this it sets the two security cookies above (__cf_bm, cf_clearance) and processes your IP address and technical browser characteristics. Cloudflare also provides the human-visitor check Turnstile on the shared page's password form. Neither tracks you across sites or is used for advertising. There are no other external elements: fonts and every image are served from our own server. Sections 5 and 6 of the privacy policy also cover Cloudflare.
4. What does the app store on your device?
The iPhone app uses no cookies, but keeps a few things on the phone to work; none of this leaves the phone or reaches us:
- Sign-in token in the iOS Keychain, on this device only; for at most 180 days, until you sign out or delete the account.
- Settings: the app language, whether the reminder notification is on, and when the trial banner and the rating prompt were last shown.
- Cache: the list of recently viewed memories and preview images so the app opens without a network, and the list of interrupted uploads so they can be resumed.
All of this disappears when you delete the app; a reinstalled app also clears the sign-in token on its first launch.
5. Legal basis
Each cookie above is needed to provide the service you explicitly asked for or to keep it secure (remembering the password sign-in, protecting forms, the "keep me signed in" option you ticked, the "new" marker, filtering attacks and bots), so under section 155(4) of Hungarian Act C of 2003 on electronic communications (implementing the ePrivacy Directive) no consent is required to set them. The personal data they involve (IP address, browser characteristics, session identifier) is processed on the basis of our legitimate interest in the security of the service (GDPR Art. 6(1)(f)); see section 4 of the privacy policy.
6. How to delete or block cookies
You can view, delete or block cookies in your browser settings at any time (Safari: Settings → Safari → Advanced → Website Data; Chrome: Settings → Privacy and security → Cookies). Without the "keep me signed in" cookie the shared page simply asks for the password again; without the session and security cookies (including Cloudflare's) the password sign-in does not work, or the page asks for checks more often. The family can also invalidate the "keep me signed in" cookie by changing the share password.
7. Changes to this policy
If we introduce a new cookie or change the purpose or lifetime of an existing one, we update this page and, for material changes, tell you in the app or by email. Version: 2026-10-09.