Cookie Policy
Every cookie and every setting this site keeps in your browser, what it's for and how long it lasts. There are no ads, no analytics and no tracking, so the list is short.
The short version
A cookie is a small piece of text a website asks your browser to keep. This site sets cookies for one reason only: to keep you signed in with Discord. It also keeps a few display settings in your browser's local storage, such as whether motion is switched off. That's all.
All of them are first-party: they belong to playapoc.xyz and are never shared with or read by another website. None of them is used for advertising, analytics or tracking you across sites. Because everything here is either strictly necessary or a setting you chose yourself, there is nothing to opt in to. The cookie notice is just that: a notice.
If that ever changes, for example if we add analytics or an embedded video, we'll update this page first and ask for your consent before anything optional is set, with a clear choice to refuse.
Cookies
These are set by the site itself (through its API) and only ever sent back to playapoc.xyz. All of them are HttpOnly, so no script on the page can read them, and Secure, so they only travel over HTTPS. The __Host- prefix means the browser refuses to let any other subdomain set or overwrite them.
| Name | Type | What it does | How long |
|---|---|---|---|
__Host-apoc_sid | Strictly necessary | Keeps you signed in with Discord. It holds a random token. The server stores only a hash of it, alongside your Discord ID, display name and avatar. Without it you can still read every public page, but you can't see your survivor file, trade on the Exchange or use your store purchases. Set only when you sign in. | 30 days at most, and it stops working after 14 days without a visit. Signing out deletes it. |
__Host-apoc_oauth | Strictly necessary | Ties a Discord sign-in to the browser that started it, so nobody can finish a sign-in on your behalf. Set when you press Sign in with Discord. | 10 minutes |
__Host-apoc_adm | Strictly necessary | Staff only. Keeps the owner's admin panel session separate from the normal sign-in. Never set for players. | 2 hours at most, and it ends after 15 minutes without activity |
Settings in your browser
These live in your browser's local storage, not in cookies. They are never sent to our server or anyone else. They just remember choices you made on this device, and you can clear them at any time.
| Key | Type | What it does | How long |
|---|---|---|---|
apoc_motion | Preference | Remembers the Motion switch in the footer (on or off), so pages stay calm if you turned animation off. | Until you clear your browser's site data |
apoc-kitmap | Preference | Remembers your Live map settings: temperature unit, which weather overlays and layers are shown, and whether the forecast and key are open. | Until you clear your browser's site data |
apoc_cookie_notice | Strictly necessary | Remembers that you've seen the cookie notice, so it doesn't come back on every page. | Until you clear your browser's site data |
Other companies
- Cloudflare protects and delivers the site. If its security checks run (for example during an attack), it may set its own strictly necessary cookies such as
__cf_bm(30 minutes) orcf_clearanceto tell real visitors from bots. They aren't used to track you. See Cloudflare's cookie policy. - Google Fonts. The site's typefaces load from Google's font servers. That sets no cookies, but your browser does contact Google, which sees your IP address. See Google Fonts' privacy notes.
- Discord. Signing in takes you to discord.com, which uses its own cookies under Discord's privacy policy. When you're signed in, your avatar is loaded from Discord's image server. No cookies are sent with it.
- Tebex. The store at store.playapoc.xyz and its checkout are run by Tebex, which sets its own cookies under Tebex's privacy and cookie policy. This site sets nothing on the store.
This site has no advertising, no analytics, no social media widgets and no embedded videos.
Your choices
You can block or delete cookies and local storage in your browser's settings. Blocking the sign-in cookies means you can't sign in, but every public page still works. Clearing local storage resets the Motion switch and the map settings, and shows the cookie notice once more. You can also sign out from your survivor file, which deletes the sign-in cookie and ends that session on our side. Signing out everywhere ends every session for your Discord account.
For what we do with the data behind your sign-in, see the Privacy Policy.
Changes
If the site starts using a new cookie or storage key, it goes on this page first and the date at the top changes. Questions? Email [email protected].