Cookie policy
Last updated: August 2026
No advertising or analytics
Nutria uses no advertising cookies, third-party analytics or tracking. Every cookie we use is strictly necessary for the service to work, so they are exempt from the consent requirement and you will see no cookie banners.
We do measure which pages bring people to Nutria, using our own Umami instance on our own servers. It sets no cookies, records no personal data and never follows you to another site, which is why it changes nothing above.
First-party cookies (strictly necessary)
nutria_session: keeps you signed in. It is an httpOnly cookie (code running on the page cannot read it, which protects your session from malicious scripts), it is sent over HTTPS only and lasts 30 days or until you sign out.
nutria_csrf: a security token the application sends back with every action to stop other websites from making requests on your behalf (CSRF protection). It lasts 30 days or until you sign out.
Browser local storage
Besides cookies, we keep in local storage: your preferred language, drafts of foods or dishes you leave half-created and, only in the native iOS and Android apps, the session token. They are removed when you sign out or clear the browser or app data.
Third-party cookies on specific features
On payment pages, Stripe (our payment processor) sets its own cookies (such as __stripe_mid and __stripe_sid) to process the payment securely and prevent fraud.
On the registration form we use Cloudflare Turnstile to block bots; Cloudflare may set a technical cookie for that sole purpose.
These cookies only appear when you use those features and are necessary to provide them securely. Outside those cases no third-party service is loaded in your browser.
