Skip to content
CardCura

Cookie Policy

Effective September 10, 2026

CardCura sets 2 cookies. Both are strictly necessary session cookies: one for an adult Parent Hub session and one for a paired Kid Portal session. That is the whole list.

What we do not set

  • No analytics or measurement cookies.
  • No advertising, retargeting, or profiling cookies.
  • No third-party cookies. Nothing on any page is loaded from another domain.
  • No cross-site tracking, and no advertising identifier.

Because there are no optional cookies, CardCura does not show a consent banner or set a separate cookie merely to remember that you dismissed one. If optional cookies are introduced later, they must be off until you choose otherwise.

Every cookie we set

cardcura_parent_sessionStrictly necessaryHttpOnly

Keeps an adult signed in to the Parent Hub. The cookie contains a random session secret; account details are resolved server-side from its hashed database record.

Expires after 30 days

kid_session_idStrictly necessaryHttpOnly

Keeps one paired device signed in to one child’s limited Kid Portal. It can view that child’s information and submit routine check-ins, but it cannot change balances or family settings.

Expires after 12 hours

Controlling cookies

You can delete or block cookies in your browser settings at any time. If you block the two session cookies, signing in to the Parent Hub and pairing a child's tablet will stop working — those cookies are how the app knows who you are.

Children

A paired child device holds one cookie for a limited Kid Portal session. It can view that child's information and submit routine check-ins, but it cannot change balances or family settings. No analytics, advertising, or tracking script loads on a child-facing page.

Questions go to privacy@cardcura.com. See also our privacy policy.