Cookie Policy
Last updated: 2026-05-14
Marketing site (this site)
thehitsapp.info ships with zero cookies. This site is a static export with no analytics tags, no advertising tags, no session storage of personal data and no third-party fonts loaded from external CDNs. We do not need a cookie banner because we do not set cookies. We may add a strictly-necessary cookie (for example a CSRF token) in the future if we add interactive forms — this page will be updated before that happens.
Admin dashboard & authenticated areas
The admin dashboard at admin.thehitsapp.info and the authentication service at auth.thehitsapp.info use the following cookies. They are set on those subdomains, not on the apex.
| Name | Purpose | Type | Duration |
|---|---|---|---|
__Host-rt-session | Session token. Required to keep you signed in. | Strictly necessary | Session (rolling) |
__Host-rt-csrf | Cross-site request forgery protection. | Strictly necessary | Session |
rt-pref-theme | Remembers your light/dark theme preference. | Functional | 1 year |
rt-mfa-remember | Skips the second factor on a device you marked as trusted. | Functional (opt-in) | 30 days |
All cookies are set with Secure, HttpOnly (where applicable), and SameSite=Lax or stricter. We do not use third-party advertising or analytics cookies on authenticated surfaces.
Native apps
The HITS App for iOS and Android does not use cookies. It uses native, encrypted token storage (Keychain / Keystore) for authentication.
Controlling cookies
You can clear or block cookies from your browser settings at any time. Blocking the strictly-necessary cookies above will prevent the admin dashboard from working.
Questions
Email dpo@thehitsapp.info.