Cookies
One cookie, and only when you sign in
There is no cookie banner on this site. That is not an oversight — it is because we set nothing that requires your permission.
Last reviewed 8 August 2026.
What we set
| Name | What it does | When it is set | How long it lasts |
|---|---|---|---|
| threesafe_session | Keeps you signed in to your own family account | Only after you open a sign-in link from your email | 30 days |
That is the complete list. The cookie is strictly necessary — without it, signing in cannot work — so it is exempt from the consent requirement in the Privacy and Electronic Communications Regulations. It is marked httpOnly and SameSite, so it cannot be read by scripts and is not sent to other sites.
What we do not set
- No advertising or marketing cookies.
- No third-party tracking pixels or social media buttons.
- No cross-site identifiers, and no profile of you anywhere.
- Nothing at all on the pages a person uses to look up a lost child’s family. That flow sets no cookie of any kind.
The anti-abuse check
The lookup page runs Cloudflare Turnstile, which checks that a lookup is being made by a person rather than a script. It is the control that stops somebody sitting and guessing at phrases. It does not set a cookie and does not track you across sites. Cloudflare sees the address the request came from and a short-lived challenge token.
Measurement
If we measure anything — how many people reach the site from a wristband rather than a sign, for example — it will be counted without cookies and without anything that identifies a device or a person. Aggregate counts only. If that ever changes, this page changes first, and you will get the choice before it happens.
If you want to remove it
Signing out deletes the cookie. Clearing site data in your browser does the same. Blocking cookies for this site is fine for everything except signing in to your own account — the lookup flow, which is the part that matters in an emergency, works either way.
Questions about this page go to privacy@threesafe.org.