Essential session cookie
hh_session identifies your secure server session. It is HttpOnly and normally lasts up to two hours of inactivity. It supports sign-in, sign-out and account actions. The production session cookie uses the Secure attribute and is sent over HTTPS.
Request protection
XSRF-TOKEN helps protect state-changing requests from cross-site request forgery. It follows the session lifetime. Disabling essential cookies can prevent sign-in and forms from working. The server also provides a CSRF value to the same-origin application.
Remembering your choice
hh_consent records your separate comfort and analytics choices and the policy version for up to 180 days. Existing permission for comfort cookies does not grant analytics permission. This cookie is needed to honour your choices.
Optional comfort preference
hh_light stores classic or warm reading light only after you allow comfort preferences. It lasts for up to 180 days. When you withdraw permission, the saved cookie is removed. You can still change the light for the current view without persistent storage.
Optional Google Analytics cookies
_ga distinguishes browsers and _ga_KJEPVZV6M6 stores analytics session state. They are created only after analytics consent, with a maximum configured lifetime of 180 days. Google Analytics measures visits and public-page navigation. Advertising cookies are not enabled. When you withdraw analytics permission, this site stops collection and removes its analytics cookies.
Changing your mind
Open Cookie Preferences from any footer to allow or withdraw comfort storage and analytics separately. Your browser can also delete or block cookies. Deleting essential cookies may sign you out; it does not erase your server-stored account or credit history.