Cookie Policy
What cookies WebList uses, for what and for how long.
Last updated: September 9, 2026
What cookies are
Cookies are small files your browser stores on your device when you visit a website. Many website features depend on them: keeping you signed in, remembering preferences and protecting forms from abuse.
WebList uses only **strictly necessary** cookies and preference cookies. We use no marketing cookies, we do not follow you across other websites and we do not sell browsing data. Optional statistics run only with your consent and never store information that identifies you.
Cookies used by WebList
| Name | Category | Duration | Purpose |
|---|---|---|---|
| authjs.session-token | Essential | 30 days | Keeps you signed in. In production it carries the `__Secure-` prefix and cannot be read by scripts (httpOnly). |
| authjs.csrf-token | Essential | Up to 24 hours | Protects authentication forms against CSRF attacks. |
| authjs.callback-url | Essential | Up to 24 hours | Returns you to the page you started the sign-in from. |
| NEXT_LOCALE | Preference | 1 year | Remembers the language you chose. |
| wl_consent | Preference | 1 year | Stores your cookie-banner decision so we do not show the banner on every visit. |
The cookie banner
On your first visit we show a small banner with two choices: essential cookies only (the site works the same) or also allowing statistical analysis. Your choice is stored in the `wl_consent` cookie and you can change it anytime from the “Cookie preferences” link in the page footer.
Optional statistics
Usage statistics are enabled by default and use our own cookieless tool: daily-aggregated page views and a visitor counter based on a code rotated every day. Your IP address is never stored. Turning them off in preferences limits no functionality.
Changes
If we ever add new cookies, we will update this document and the banner and, where required, ask for your consent again.