Cookie Policy

Last updated: 4 August 2026

This policy lists everything goffer stores in your browser, on this marketing site (goffer.app) and in the product app (app.goffer.app). We run no analytics and no advertising cookies. Everything below is either strictly necessary to make the service work or a preference you set yourself.

1. Your choice on this site

Accepting or rejecting the cookie notice stores one cookie, "goffer_consent", which records the choice you made and when. It lasts 180 days and is scoped to goffer.app and its subdomains so you are not asked twice. It is the only cookie this marketing site sets. You can change your mind at any time using the "cookie settings" link in the footer, which clears the record and brings the notice back.

2. Signing you in

The product app keeps your session in two httpOnly cookies, "goffer_access" (15 minutes) and "goffer_refresh" (30 days). httpOnly means no script in your browser — ours or anyone else's — can read them. They are strictly necessary: without them you cannot stay signed in, so they are not subject to consent.

3. Signing in with Google or GitHub

Starting a Google or GitHub sign-in sets two short-lived cookies, "goffer_oauth_state_<provider>" and "goffer_oauth_verifier_<provider>". They last ten minutes, are used once, and are deleted as soon as you come back from the provider. They exist to prove the response really came from the sign-in you started, and are what stops a third party from completing it on your behalf.

4. Bot protection on sign-up

The sign-up form runs Cloudflare Turnstile, which checks that a person and not a script is creating the account. Cloudflare is a third party and may set its own storage in your browser on that page; it is governed by Cloudflare's own privacy terms. This is the only third-party code the service loads, and only on that one page.

5. Preferences kept in local storage

The product app remembers a few things in your browser's local storage rather than in cookies, which means they are never sent to a server: "goffer-theme" (dark or light), "goffer-diff-mode" (how the diff viewer is laid out), "goffer-saboteur-progress" (which saboteur missions you have solved) and one draft per coding challenge, so a half-written answer survives a reload. If you are signed in, your theme is also saved to your profile so it follows you between devices.

6. Analytics and advertising

There are none. We do not run Google Analytics or any equivalent, we load no advertising or social tracking pixels, and we do not build a profile of you across other websites. If that ever changes, nothing non-essential will load until you have accepted the cookie notice, and this page will be updated first.

7. Managing cookies yourself

Beyond the "cookie settings" link in our footer, every browser lets you view, block, and delete cookies and local storage for a site. Blocking the strictly necessary ones will sign you out and stop the product app from working; blocking anything else has no effect, because there is nothing else.

8. Contact

Questions about this policy or anything listed on it can be sent to privacy@goffer.dev.

cookies: only the strictly necessary ones today — they keep you signed in over on the app. no trackers, no ad pixels. if that ever changes, this is the switch. cookie policy