Pilot Crewroom
Back to home

Cookie policy

Necessary cookies, plainly explained.

Pilot Crewroom does not use advertising or analytics cookies. The cookies below are required for account access, session security, and remembering that this notice was accepted.

Last updated 18 July 2026

Authentication cookies

  • Pilot Crewroom's authentication system sets an HttpOnly session-token cookie after sign-in. It identifies the signed-in session without exposing the token to browser JavaScript.
  • The session can last up to 30 days and is refreshed at most once per day while the account is used. Signing out invalidates the active browser session.
  • Temporary authentication cookies may also be used during email verification, password recovery, and Google sign-in to protect redirects and match a response to the browser that started it.

Security and session cookies

  • Authentication cookies use SameSite protection and are Secure in production. Sensitive tokens are HttpOnly so normal page scripts cannot read them.
  • The standalone administrator console uses a separate HttpOnly, SameSite=Strict cookie. It is not connected to any customer account and expires after eight hours.
  • Room continuity uses browser session storage rather than a cookie. That tab-scoped state is cleared when the tab session ends and does not authenticate the account.
  • Cloudflare Turnstile performs a human-verification check for sensitive email-account actions. It is configured without pre-clearance, so Pilot Crewroom does not ask it to set a cf_clearance cookie on pilotcrewroom.com.

Cookie-notice acceptance

Selecting “Accept necessary cookies” stores pilot-crewroom.cookie-consent=necessary-v1 for up to 12 months. It records only the current notice version; it does not identify you, track browsing, or enable optional cookies.

Because authentication and security cookies are strictly necessary to provide signed-in features safely, the app does not offer an option that disables them while continuing to use an account. Public pages remain readable without signing in.

Cookieless public-page analytics and basic server logs

Cloudflare Web Analytics measures aggregate visits and browser performance only on the public home, pricing, Terms, Privacy, and Cookie pages. It does not use analytics cookies, local storage, or fingerprinting, and it is excluded from signed-in, practice, account, administrator, recovery, API, and saved-run routes.

The server emits a basic structured request record containing the timestamp, request ID, HTTP method, and route path. Query strings, request bodies, passwords, authentication tokens, payment details, microphone audio, and transcript content are not written by this logger.

Hosting and Cloudflare infrastructure may add status, duration, IP-derived network, device, or security information needed to operate and defend the service. Application container logs rotate by storage volume, with at most five files of 10 MB for the app service. Cloudflare and the host keep their own security records under configured retention and legal requirements.

Third-party checkout

Checkout embeds Stripe Managed Payments securely inside Pilot Crewroom. The payment form itself is hosted by Stripe in an isolated frame, and Link is shown as Merchant of Record. Stripe and Link apply their own privacy and cookie notices to the form and may use necessary payment, authentication, fraud-prevention and checkout-continuity storage.

Stripe.js may send device and interaction signals to Stripe for fraud prevention when the embedded checkout loads. Pilot Crewroom cannot read payment details entered into the Stripe frame and does not use Stripe checkout data for advertising or analytics.