Legal

Ultron — Cookie Policy

Ultron browser-storage policy: necessary cookies, local storage, lifetimes, access, and deletion.

Effective / last updated: 10 August 2026

Cookies and browser storage

Browser storage includes cookies, localStorage, and sessionStorage. Under Article 4(5)–(6) of Romanian Law 506/2004, storing or accessing information on terminal equipment generally requires clear information and agreement, except when used solely to transmit a communication or when strictly necessary for an information-society service expressly requested by the user. Ultron uses the first-party items below for request-forgery protection, temporary server sessions, language or notice preferences, and device-local features triggered by the user.

Ultron first-party cookies

  • ultron_cookie_notice — records dismissal of the necessary-storage notice; purpose: avoiding repeat display after that choice; lifetime: 180 days; JavaScript-readable, SameSite=Lax, and Secure on HTTPS; deleted automatically at expiry or earlier through browser controls.
  • ultron_locale — stores the selected language; purpose: showing the same language on later requests; lifetime: 1 year; HttpOnly, SameSite=Lax, and Secure on HTTPS; deleted automatically at expiry or earlier through browser controls.
  • csrf_cookie_name — stores a randomized request-forgery-protection token; purpose: rejecting forged form submissions initiated by another site; lifetime: up to 2 hours and regenerated after a valid submission; HttpOnly, SameSite=Lax, and Secure on HTTPS; necessary for protected forms.
  • ci_session — is created for flows requiring temporary server-side state, including form feedback and payment-return messages; the browser holds only a random session identifier; lifetime: up to 2 hours and may be renewed during use; HttpOnly, SameSite=Lax, and Secure on HTTPS; necessary for those flows.

Ultron first-party local storage

localStorage is stored on the device, is readable by JavaScript from the same origin, and is not sent automatically with HTTP requests. Ultron’s current scripts use the values below only in the browser and do not transmit them.

  • ultron.siteDoctor.checklist.v2:<24-hex> — the key ends with a 24-hex-character SHA-256 fingerprint derived server-side from the report access key; the fingerprint is not the bearer key and cannot open the report. The JSON value contains expiresAt and completed remediation-item IDs. It is written only after a checklist checkbox is changed, to retain that device-local selection. Its logical lifetime ends at the report expires_at value, normally 30 days. Expired or invalid entries are removed the next time Site Doctor checklist code runs; without a later visit, the browser may retain the expired record until site data is cleared.
  • ultron.opsGuardian.dismissed.v1 — stores JSON containing value: true and expiresAt only after the Ops Guardian tip is expressly closed; purpose: retaining that dismissal on the device; lifetime: 180 days. It is removed when it is expired or invalid and read again, or immediately when the tip is reopened. Without a later visit, the browser may retain the expired record until site data is cleared.
  • ultron-site-doctor:<48-hex> — is a legacy key containing the former 48-hex-character report bearer. Current code no longer writes it and removes matching legacy keys whenever a Site Doctor checklist loads.
  • sessionStorage — Ultron currently writes no value to sessionStorage. The former ultron.opsGuardian.introduced.v1 record is no longer written.

Third-party storage

  • Cloudflare Turnstile: when Site Doctor abuse protection is enabled, Cloudflare’s script may use technical signals and necessary storage to determine whether a request is human and legitimate. It is loaded as a security function, not advertising. Cloudflare’s notice applies. Cloudflare privacy notice.
  • Stripe Checkout: when payment is started, the browser leaves ultron.ro for Stripe’s hosted page. Stripe may use cookies or similar technologies for payment, fraud prevention, and its own legal obligations. Ultron does not set them, and they become active only when Stripe’s page is opened. Stripe privacy notice.
  • Google / Microsoft: if an optional Search Console or Bing Webmaster connection is initiated, the provider may use its own cookies for sign-in, security, and authorization on its site. Without a connection, those provider pages are not loaded.

Current analytics and marketing status

Ultron currently loads no analytics or marketing tracker on public pages, so it does not request advance consent for trackers that do not exist. If that changes, the provider list and this notice will be updated, and an appropriate consent mechanism will be introduced before activation.

Managing and deleting browser storage

Browser controls can delete or block cookies and local storage at any time. Blocking cookies may prevent language memory, request-forgery protection, temporary sessions, or payment-return messages. Clearing local storage resets checklist selections and the Ops Guardian dismissal preference. It does not delete the server-side Site Doctor report; that report follows the separate retention period in the Privacy Notice. A data-erasure request may be sent through the privacy contact where the legal conditions apply.

Contact

For browser-storage or privacy questions: [email protected].