Summary: CitedCV sets only the cookies it needs to keep you signed in, remember your theme, run the quiz and stop bots; there are no advertising or third-party analytics cookies.
Cookie Policy
Version 1.0.0 — effective 15 September 2026.
1. What cookies are
Cookies are small text files that a website stores in your browser. Similar technologies include local storage and session storage. This policy explains which cookies the CitedCV Service (citedcv.com and successor domains), operated by {{COMPANY_NAME}}, uses and why.
2. Our approach
We use only strictly necessary cookies and a bot-protection service. We do not use advertising cookies, tracking pixels, social-media plug-ins or third-party analytics cookies. Our usage analytics are collected server-side, without cookies, and produce only aggregated measures such as page views and action counts; they do not build profiles of individual visitors. Because every cookie we set is necessary for the Service to work or to protect it, no consent banner is required under the ePrivacy rules or the Turkish cookie guidelines, and we do not show one.
3. The cookies we set
cvz.session_token
- Purpose: keeps you signed in after you log in and protects your session against forgery. It also carries a short-lived signed cache of your session so that pages load without a database round-trip.
- Type: strictly necessary, first-party.
- Attributes: HttpOnly (not readable by scripts), Secure, SameSite=Lax.
- Duration: the length of your session; renewed while you are active and removed when you sign out or when the session expires.
cited_theme
- Purpose: remembers whether you chose the light, dark or system colour theme.
- Type: strictly necessary preference cookie, first-party.
- Attributes: Secure, SameSite=Lax. It contains only the word light, dark or system.
- Duration: 1 year.
__Host-citedq
- Purpose: identifies your anonymous quiz session before you sign up so that your answers are kept between quiz steps. The __Host- prefix means the browser sends it only over HTTPS and only to the exact host that set it.
- Type: strictly necessary, first-party.
- Attributes: HttpOnly, Secure, Path=/, SameSite=Lax.
- Duration: 7 days. When you create an account, the quiz session is linked to it and the cookie is no longer needed.
CSRF protection
Where a form needs a cross-site request forgery token, the token is bound to the session cookie above; no additional persistent cookie is set.
Cloudflare Turnstile (cf_clearance and challenge cookies)
- Purpose: Cloudflare Turnstile checks that a visitor is human before sensitive actions (sign-up, quiz completion, checkout) without showing a CAPTCHA puzzle. To do so, Cloudflare may set cf_clearance and short-lived challenge cookies (for example __cf_bm) on our domain.
- Type: strictly necessary, security; set by Cloudflare acting as our processor.
- Duration: typically from 30 minutes up to a few hours; cf_clearance may last longer depending on Cloudflare's configuration.
- Cloudflare does not use these cookies to track you across other websites. Cloudflare's own privacy policy explains its processing.
4. Cookies set by our payment provider
When you buy Credits you are taken to a checkout page hosted by Stripe. Stripe sets its own cookies on its own domain for fraud prevention and to operate the checkout. Those cookies are governed by Stripe's cookie policy, not by this one.
5. Local storage
We may use your browser's local storage for non-personal, per-device conveniences, for example remembering a collapsed panel. Nothing stored there identifies you, and it is never sent to third parties.
6. What the cookies contain and how that relates to your privacy
The session cookie contains only a random session identifier and a short-lived signed cache; the details of your account stay on our servers. The theme cookie contains a single word, and the quiz cookie a random session id; your quiz answers themselves are stored in our database, not in the cookie. Data processed through these cookies is subject to the retention periods in the Privacy Policy and, for users in Türkiye, the KVKK Aydınlatma Metni. Turnstile cookies are processed by Cloudflare as our processor, solely for bot protection; Cloudflare may not use them for its own purposes.
7. How to control cookies
- Signing out removes the session cookie. Setting the theme back to "system" resets the theme cookie.
- You can delete or block cookies in your browser settings. Most browsers let you block all cookies, block third-party cookies only, or clear cookies when you close the browser; on mobile browsers these options are usually under privacy or site settings. If you block cvz.session_token you will not be able to stay signed in; if you block the Turnstile cookies, some actions may fail the human check.
- Because we set no optional cookies, there is nothing to opt in to or out of. If we ever add optional cookies, we will ask for your consent first and update this policy.
8. Do Not Track and Global Privacy Control
We do not track you across websites and do not sell or share personal data, so browser signals such as Do Not Track or Global Privacy Control are already honoured by default. Enabling them does not change how the Service works.
9. Changes
We update this policy when the cookies we use change. The version number and effective date are shown at the top. Material changes are announced as described in the Terms of Service.
10. Contact
Questions about cookies: {{DPO_EMAIL}} or {{SUPPORT_EMAIL}}. {{COMPANY_NAME}}, {{COMPANY_ADDRESS}}, {{COMPANY_COUNTRY}}.