Cookie Policy

Last updated: July 2026

1. What a cookie is

A cookie is a small text file stored in your browser, allowing a website to recognize your browser or device on subsequent visits. This Policy covers cookies set by this dashboard and, separately, cookies set by Discord when you are redirected to its domain to log in. It should be read together with our Privacy Policy and Terms of Service.

2. Cookies this site sets

As of the date of this Policy, Wody sets two first-party cookies, both used exclusively for authentication. We do not use analytics, advertising, profiling, or third-party tracking cookies.

wody_session
Provider
Wody (first-party)
Category
Strictly necessary
Duration
7 days maximum, or until you log out
Consent
Not required (strictly necessary)
Purpose
Keeps you signed in and lets the dashboard act on your behalf with the Discord resources you've authorized.
wody_oauth_state
Provider
Wody (first-party)
Category
Strictly necessary
Duration
10 minutes maximum, deleted immediately after login completes
Consent
Not required (strictly necessary)
Purpose
Temporary anti-CSRF token used only during the Discord login redirect, to verify the login request came from your own browser.

Neither cookie value carries your Discord tokens or profile. wody_session carries only a random session identifier plus a signature; wody_oauth_state carries only a random one-time value plus a signature, used solely to confirm that the Discord login redirect you completed was one your own browser initiated. Both are Base64URL-encoded and cryptographically signed to prevent tampering. They are not encrypted, and any modification invalidates the signature, causing the value to be rejected. The actual session data (your cached profile and Discord tokens) lives server-side and is looked up using the session identifier. Technical attributes for both: HttpOnly (inaccessible to page JavaScript), Secure (HTTPS only), SameSite=Lax (CSRF protection), scoped to path /.

3. Cookies set by Discord (third-party, outside our control)

To log in, you are redirected to discord.com to authorize the dashboard, and back. While on Discord's own domain, Discord sets its own cookies under its own policies, generally falling into the following categories:

  • Strictly necessary — required for Discord's login and security to function;
  • Functional — remembering preferences such as language;
  • Performance / analytics — used by Discord to understand usage of discord.com.

We do not control these cookies and cannot configure, modify or disable them, as they are set solely by Discord, acting as an independent data controller. Further detail, and the means to manage them, are available in Discord's Cookie Policy and Discord's Privacy Policy.

4. Legal basis for the use of cookies

Under Article 5(3) of Directive 2002/58/EC (the ePrivacy Directive), as transposed into Romanian law by Article 4(5) of Law No. 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector, as amended, storing a cookie generally requires the user's consent, unless the cookie is strictly necessary to provide a service explicitly requested by the user.

Because Wody only uses strictly necessary authentication cookies, no consent banner is required under applicable ePrivacy legislation. Any personal data reachable through these cookies (your Discord identity) is otherwise processed under the GDPR, as described in our Privacy Policy.

5. Controlling or removing cookies

Clicking Logout removes the wody_session cookie immediately. The wody_oauth_state cookie deletes itself automatically once the Discord login redirect completes, and expires on its own after 10 minutes even if it doesn't. You can also clear either manually, or block cookies outright, from your browser's settings — every major browser (Chrome, Firefox, Safari, Edge, Opera) has a section for this, usually under Privacy & Security. On mobile, this is managed in your device's browser app settings.

Blocking or deleting wody_session will prevent you from remaining authenticated, since the dashboard relies on it to identify you; login and server management will not function until it is allowed again. Blocking wody_oauth_state will prevent you from logging in at all, since it is required to complete the Discord OAuth redirect safely. Neither affects Wody the bot itself, which runs independently on Discord.

6. How long we keep this data

The session cookie expires automatically after 7 days at most, or immediately upon logout, whichever occurs first. The OAuth state cookie expires after 10 minutes at most, or immediately once the login redirect completes, whichever occurs first. We do not maintain a separate history of authenticated sessions beyond what is technically necessary to operate, secure and troubleshoot the Service.

7. Your rights

Since our cookies touch personal data (your Discord identity), the same GDPR rights apply as to the rest of our processing: access, rectification, erasure, restriction, objection, and portability, plus the right to complain to your national data protection authority — in Romania, ANSPDCP (the National Supervisory Authority for Personal Data Processing). Full detail on how to exercise these is in our Privacy Policy.

8. Changes to this Policy

If a future feature requires an additional cookie (for example, storing a dashboard preference), this page and the revision date above will be updated before that feature is released. If the new cookie is not strictly necessary, consent will be requested beforehand.

9. Contact

For any privacy, legal, or data related question, contact us at wodyteams@gmail.com.

Cookie Policy — Wody