Cookie Policy
Last updated: 15 August 2026
1. Cookies used by Wody
Wody is operated by Păcurar Ancuța-Narcisa, an individual based in Târgu-Mureș, Romania (the “Operator”). The Operator can be contacted at teamswody@gmail.com. Wody uses only the two first-party cookies listed below for dashboard authentication and the security of the Discord OAuth2 login. This matches the cookie notice shown across the site, which states that Wody uses two strictly necessary authentication cookies. Wody does not use advertising cookies, analytics cookies, profiling cookies or third-party tracking cookies on the dashboard. Wody does not intentionally target children below the minimum age required to use Discord. Users must meet Discord's applicable minimum age for their country or region and any higher minimum age required by local law. Where applicable law requires parental or guardian consent, that requirement remains applicable.
| Name | Provider | Category | Purpose | Duration | Consent |
|---|---|---|---|---|---|
| wody_session | Wody | Strictly necessary | Keeps your dashboard session active and identifies the server side session associated with your login. | Up to 7 days, or until logout; the server-side session may expire sooner | Not required for a strictly necessary authentication cookie |
| wody_oauth_state | Wody | Strictly necessary | Temporarily verifies that the Discord OAuth2 login response belongs to a login started by your browser. | Up to 10 minutes, or until the login response is processed | Not required for a strictly necessary authentication cookie |
- Provider
- Wody
- Category
- Strictly necessary
- Duration
- Up to 7 days, or until logout; the server-side session may expire sooner
- Consent
- Not required for a strictly necessary authentication cookie
- Purpose
- Keeps your dashboard session active and identifies the server side session associated with your login.
- Provider
- Wody
- Category
- Strictly necessary
- Duration
- Up to 10 minutes, or until the login response is processed
- Consent
- Not required for a strictly necessary authentication cookie
- Purpose
- Temporarily verifies that the Discord OAuth2 login response belongs to a login started by your browser.
2. What these cookies contain
wody_session contains a random session identifier and a cryptographic signature. It does not contain your Discord access token, refresh token or profile.
wody_oauth_state contains a random temporary value and a cryptographic signature. It is used only to confirm that the OAuth2 login response matches a login started by your browser.
Both values are Base64URL encoded and signed. They are not encrypted. The signature prevents a modified or forged value from being accepted by the dashboard. The actual session information is stored server side in MongoDB and is associated with the random session identifier. The server-side session contains the cached Discord profile, access token, refresh token and expiry time; these values are not placed in either browser cookie. The access token session expiry is calculated from the lifetime supplied by Discord and is set 60 seconds before that token expires. The refresh token is stored with the session but the current implementation does not use it to refresh an expired access token.
3. Security settings
Both cookies are HttpOnly, which prevents normal page JavaScript from reading them. They are Secure and therefore sent only over HTTPS. They use SameSite=Lax to reduce cross site request risks and are scoped to the root path of the dashboard.
4. Browser storage used for the cookie notice
The dashboard also uses one localStorage entry named wody_cookie_ack_v1. It is created only after you dismiss the cookie notice and stores a simple flag so the notice does not appear again on that browser. It contains no personal information and is not sent to Wody's server. Clearing it only causes the notice to appear again.
5. Cookies used by Discord
During login, you are temporarily redirected to Discord. Discord may set and read its own cookies on discord.com under its own policies. Wody does not control those cookies and does not receive the contents of Discord's browser cookie storage. Information about Discord's own cookies is available in Discord's Cookie Policy and its Privacy Policy.
6. Managing cookies
You can delete or block cookies through your browser settings. If you block or delete wody_session, the dashboard cannot keep you signed in. If you block wody_oauth_state, Discord login cannot be completed safely.
Logging out removes the wody_session cookie and deletes the associated server side session record. The wody_oauth_state cookie is removed after the OAuth2 response is checked and expires automatically after 10 minutes if the login process is not completed.
7. Legal basis
The two Wody cookies are used only where they are necessary to provide and secure the dashboard login requested by the user. They are therefore treated as strictly necessary authentication technologies rather than optional advertising or analytics cookies. Personal data associated with the authenticated session is processed separately under the legal bases described in the Privacy Policy. This Cookie Policy describes the technologies actually used by the Wody dashboard; Discord may use additional cookies on discord.com under its own policies.
8. Changes to this Policy
If Wody introduces another cookie or browser storage technology, this Policy will be updated to describe its purpose, contents and retention period where applicable.
9. Contact
For privacy, legal, or data protection questions, contact Păcurar Ancuța-Narcisa, the Operator, at teamswody@gmail.com.