Legal · Cookies

Your choice comes first.

MathCoder uses two strictly necessary first-party cookies and optional, cookie-free PostHog statistics only after you accept them.

Contact security cookie

Name: mathcoder_contact_session
Provider: MathCoder, using Hostinger infrastructure
When set: when you open the contact form
Purpose: to bind an anti-forgery token to your browser, protecting the form from forged requests; rate limiting is handled separately on the server
Duration: the cookie expires when the browser session ends; its server-side anti-forgery token is valid for no more than one hour, and the session is destroyed earlier after a successful submission
Scope and safeguards: first-party, restricted to /contact.php, HttpOnly, SameSite=Strict and Secure on the production HTTPS site

This cookie is not used to recognise you across visits, measure audiences, advertise or build a profile. It is strictly necessary to provide the contact service you request, so prior consent is not required. It is not created if you do not open the form.

Consent preference cookie

Name: mathcoder_consent
Provider: MathCoder
When set: after you select either “Accept analytics” or “Reject analytics”
Purpose: to remember and honour the choice and the version of the information shown
Stored value: accepted or rejected, the choice timestamp and consent version; no name, email address or PostHog identifier
Duration: 180 days for both acceptance and rejection
Scope and safeguards: host-only first-party cookie, Path=/, SameSite=Lax and Secure on the production HTTPS site; JavaScript-readable because the consent controller must apply and update the choice

This preference is strictly necessary to avoid repeatedly asking and to respect a rejection or withdrawal, so it does not require separate consent.

Optional PostHog statistics

PostHog is a tracker even though this implementation does not use PostHog cookies, localStorage or its browser SDK. It remains fully off until you select “Accept analytics”. After acceptance, a first-party script sends only allowlisted page and interaction events to PostHog EU Cloud. It uses a random identifier held in memory for the current page and sends only a fixed, allowlisted route label; unknown addresses are recorded as /404. The receiving service also sees ordinary connection information such as the IP address and user-agent. No contact-form name, email address or message is sent.

Rejecting does not affect the site. You can change or withdraw your choice at any time; withdrawal stops future PostHog requests immediately.

Other optional technologies

The website does not use Google Analytics, advertising pixels, third-party embeds, fingerprinting or other optional browser storage. Any future optional purpose will remain disabled until the information and consent choice are updated.

Browser caching is different

Your browser, network or hosting provider may temporarily cache ordinary site files to deliver pages efficiently. That routine technical caching is not used by MathCoder to identify or track visitors.

External links

Google Play, the Apple App Store, LinkedIn, YouTube and other linked sites may use their own cookies after you choose to visit them. Their policies and controls apply on those services.

Questions

For more detail, read the Privacy Notice. Questions can be sent to tsoukalos@mathcoder.com.

Version dated 4 September 2026; effective when this version is released to production.