1. Scope
This policy explains cookies and similar browser storage used on deetnuts.com. A cookie is a small value a website asks a browser to return with later requests. Local storage keeps a value in the browser but does not automatically send it with every request. Both are covered here so the controls are not hidden behind technical terminology.
Storage is divided into strictly necessary or requested-function storage and optional analytics. Necessary storage supports authentication, security, usage limits, consent memory and a setting or profile you explicitly ask the browser to remember. Optional analytics is disabled unless you select Allow.
2. First-party storage inventory
| Name or pattern | Type | Category | Purpose | Typical duration |
|---|---|---|---|---|
deetnuts_analytics_consent | First-party cookie readable by the site | Necessary preference | Stores the current policy version and whether optional analytics is granted or denied. It prevents the banner from repeatedly asking and allows withdrawal to be applied. | 180 days from the latest choice. |
mht_cet_state_cutoff_anonymous_requests | First-party HttpOnly cookie | Security and access control | Maintains a bounded anonymous search count to protect the state-cutoff endpoint from excessive use. It is not available to page JavaScript. | 7 days; removed when the relevant authenticated flow clears it. |
sb-…-auth-token and related Supabase values | First-party authentication cookies | Strictly necessary when signed in | Maintain and refresh the authenticated session, carry access and refresh tokens, and protect account-only features. Exact names and chunks depend on the Supabase project and token size. | Controlled by the authenticated session and Supabase configuration; removed or replaced during sign-out, expiry or token rotation. |
deetnuts_theme | Local storage | Requested preference | Remembers a manual Light or Dark selection. System mode removes this value and follows the device preference. | Until System is selected or site storage is cleared. |
deetnuts:admissions-profile:v1:mht-cet | Local storage | Requested feature | Saves the candidate comparison profile on the current device after you choose to save or compare it. | Until Clear profile is used, the value is replaced, or site storage is cleared. |
deetnuts:mht-cet-state-cutoffs:anonymous-actions | Local storage | Security and access control | Maintains the browser-side anonymous action count used by the state-cutoff experience. | Until reset by the feature or site storage is cleared. |
Browsers and provider libraries may split a large authentication token across multiple cookies or change a technical suffix without changing the purpose described above.
4. How consent works
- On a browser with no current versioned choice, the banner presents Decline and Allow with equal access.
- Until Allow, no external Google Analytics script is loaded and no analytics request is intentionally sent to Google.
- Allow stores the versioned preference, loads the Google tag and enables only analytics storage.
- Decline stores the versioned preference and leaves analytics disabled. Public pages and ordinary cutoff filters remain available.
- Cookie settings reopens the choice. Revoking a prior Allow removes known first-party Google Analytics cookies and reloads the page without the Google tag.
- A materially changed analytics purpose or consent design uses a new consent version and asks again.
If the browser exposes an active Global Privacy Control signal, DEETNUTS treats optional analytics as denied on that device and does not offer an override while the signal remains active.
5. Embedded and external services
Some pages request images from Cloudinary or display a YouTube player using the youtube-nocookie.com privacy-enhanced domain. Those requests disclose ordinary network information to the provider. The privacy-enhanced player is configured to limit personalisation, but YouTube may use cookies or comparable player storage when the embed loads or is used, according to its own controls.
Selecting Google sign-in, opening a contribution checkout, or following an external link takes you into an independently operated service that may set its own storage. DEETNUTS’s analytics choice does not delete or control cookies already set by another domain.
6. Your controls
- Use Cookie settings in either footer to review, decline, allow or revoke analytics.
- Use Theme settings to choose System, Light or Dark and remove the manual theme value.
- Use Clear profile in the candidate tool to remove its saved browser value and profile fragment.
- Use browser settings to inspect or delete site data, block cookies, clear local storage, or restrict third-party content.
- Use sign out to end the addressed local account session. Contact privacy support to request account deletion.
Blocking strictly necessary authentication or security storage may prevent sign-in, usage-limit enforcement or saved settings from working. It does not prevent ordinary access to public cutoff pages.
7. Verifying the promise
Before analytics consent, developer tools should show no request to googletagmanager.com or google-analytics.com from the DEETNUTS analytics component. After Decline, the same remains true. The site’s automated browser test checks this behavior on a real page.
Authentication, hosted images, embedded media and links are separate from optional analytics and are described separately above and in the Privacy Policy.
8. Changes and contact
The effective date and version at the top apply to this inventory. If a new non-essential cookie or materially different analytics purpose is introduced, this policy and the consent mechanism must be updated before that use begins.
Questions or a report that stored behavior differs from this policy may be sent to help@deetnuts.com. Include the browser, page URL, approximate time and the cookie or request observed; do not include authentication token values.