Cookie Policy
Version of 28 September 2026.
In short
- The spacy.site website uses only the cookies that sign-in and payment can't work without, plus two cookies that remember your choices: your language and your answer to the cookie notice.
- There are no analytics or advertising cookies. We don't use visitor counters, pixels or third-party trackers.
- Sign-in and payment cookies can't be read by scripts on the page. The session cookie is also encrypted.
- The website doesn't use localStorage or sessionStorage.
- You can delete cookies in your browser settings. You will then need to sign in to your account again.
1. What cookies are
A cookie is a small file that a website saves in your browser. The browser sends it back with later requests to the same site. That's how the site knows you are already signed in, or remembers your language.
2. Cookies we use
2.1. Cookies set by spacy.site
The browser accepts cookies with the __Host- prefix only from spacy.site itself and only over HTTPS. Other sites and our subdomains can't read or replace them.
| Name | Purpose | Lifetime | Set by |
|---|---|---|---|
__Host-spacy_session | Keeps you signed in to your account. Holds encrypted session tokens | 60 days; removed when you sign out | site |
__Host-spacy_signed_in | A "you may be signed in" hint, so the home page can show your account name. Contains only "1" and grants nothing without the session cookie | 60 days | site |
__Host-spacy_web_device | A random browser ID. It makes your browser appear as a single device in your account's device list | 2 years | site |
__Host-spacy_tg_flow | Binds a Telegram sign-in to the browser that started it. Protects against forged requests and hijacked sign-ins | 10 minutes; removed after sign-in | site |
__Host-spacy_pairing | The secret for QR code sign-in while the code is on screen | the code's lifetime plus 30 seconds | site |
__Host-spacy_handoff | A one-time token when you move from the app to the website, kept until you confirm | 150 seconds | site |
__Host-spacy_retry | Stops the page from redirecting in a loop if a session refresh fails | 30 seconds | site |
__Host-spacy_payment | The number of the payment you just created, so we can show its status after YooKassa | 10 minutes; removed once checked | site |
lang | Your chosen site language. Set only when you switch language | 1 year | site |
spacy_consent | A mark that you have seen the cookie notice, so we don't show it again | 1 year | site |
2.2. Cookie set by the API server
| Name | Purpose | Lifetime | Set by |
|---|---|---|---|
spacy_tg_login | Encrypted one-time Telegram sign-in parameters (state, nonce, PKCE). Sent only to the Telegram sign-in addresses | 10 minutes; removed after sign-in | API (api.spacy.site) |
2.3. Third-party sites
When you sign in with Telegram, Apple or Google, or pay for a subscription on the YooKassa page, you go to their sites. Those sites may set their own cookies under their own rules. We don't control or receive them.
3. What we don't use
- analytics cookies or visitor counters;
- advertising cookies or pixels;
- localStorage or sessionStorage.
If this changes, we will update this policy and ask for your consent to optional cookies in advance.
4. Can you opt out?
Sign-in and payment cookies are necessary. Without the session cookie you can't sign in to your account; without the others, Telegram sign-in, QR code sign-in and payment checks don't work. That's why they can't be switched off individually. The lang and spacy_consent cookies appear only after you act and only remember your choice.
The cookie notice has one button, "Got it". The site has no optional cookies, so there is nothing to choose between: the notice only tells you which cookies are in use and remembers that you have seen it.
5. How to delete cookies
You can delete or block cookies in your browser settings:
- Safari (iPhone, iPad): Settings → Apps → Safari → Advanced → Website Data, then find spacy.site.
- Safari (Mac): Safari → Settings → Privacy → Manage Website Data.
- Chrome: Settings → Privacy and security → Delete browsing data.
- Firefox: Settings → Privacy & Security → Cookies and Site Data.
After deleting them you will be signed out of your account, and the site will ask about cookies again. If cookies are blocked completely, you won't be able to sign in to your account. The rest of the site will still work.
For how we handle data in general, see the Privacy Policy.
6. Contact
- Email: legal@spacy-network.xyz
- Support: on the website, in the app (Settings → Support) or in Telegram at @spacy_support