1. Strict Necessity

We utilize cryptographic session tokens (cs_session, encrypted JWT) and CSRF prevention tokens (csrf_token) exclusively for preserving platform security and authentication state. These are strictly necessary for the delivery of the Service and do not require prior consent under the ePrivacy Directive.

2. First-Party Telemetry

For operational intelligence, we deploy a self-hosted, anonymized instance of Plausible Analytics. No tracking data is syndicated to third-party advertising networks (e.g., Google, Meta), and no cross-site tracking pixels are employed across the CloudStore domain. Users may opt-out of telemetry via the platform dashboard settings.