Cookie Policy
MilsimStack uses a small set of first-party, strictly necessary cookies for secure Discord sign-in. There are no advertising or analytics cookies.
Effective August 31, 2026 · Last updated August 31, 2026
1. What cookies are
Cookies are small text values stored by a browser and returned to the site that set them. Similar browser storage can remember a preference without being sent with every request. MilsimStack uses these technologies only for authentication, security, navigation, and remembering that this notice has been read.
2. Storage used by MilsimStack
| Name | Purpose | Type and duration |
|---|---|---|
next-auth.session-token__Secure-next-auth.session-token | Maintains the signed-in Discord session and protects access to unit data. | First-party, strictly necessary; session expiry is controlled by the authentication service. |
next-auth.csrf-token__Host-next-auth.csrf-token | Prevents cross-site request forgery during authentication and account actions. | First-party, strictly necessary; short-lived or session-based. |
next-auth.callback-url__Secure-next-auth.callback-url | Returns a user to the requested MilsimStack page after sign-in. | First-party, strictly necessary; authentication flow or session duration. |
next-auth.state, next-auth.nonce, next-auth.pkce.code_verifier | Validates the Discord OAuth exchange and prevents sign-in substitution or replay. | First-party, strictly necessary; temporary and normally removed when sign-in finishes. |
milsimstack.cookie-notice | Browser local storage indicating that the necessary-cookie notice was acknowledged. | First-party preference; remains until browser storage is cleared. |
Secure production cookies may use a prefixed name. The exact expiry can also change when authentication security settings are updated. MilsimStack does not currently load analytics, behavioral advertising, social tracking pixels, or third-party fonts.
3. Why the necessary cookies do not have an off switch
Authentication and security cookies are essential to the signed-in service a user requests. Disabling them prevents Discord sign-in and protected unit pages from working. The notice informs visitors about them; it does not pretend that an optional tracking choice exists when MilsimStack has no optional tracking cookies.
4. Discord and linked services
Choosing Discord sign-in redirects the browser to Discord. Discord may set its own cookies on its domains under its policies. Following or importing a Google document or spreadsheet may likewise involve Google when the browser opens a Google link. Those cookies are controlled by the relevant third party, not MilsimStack.
5. Browser controls
Browser settings can inspect, block, or delete cookies and local storage. Blocking necessary cookies will disable sign-in. Clearing local storage makes the notice appear again but does not sign a user out; deleting the session cookie signs the user out.
6. Changes and contact
If optional analytics or advertising technology is introduced, it must be blocked until any consent required by law is obtained, and this policy and the notice will be updated. Questions can be sent to support@milsimstack.com.