Cookie Policy
Last updated: 02-05-2026 | Xefeladi
1. What cookies are
A cookie is a small text file that a website asks your browser to store and send back on later visits. It lets a site recognise a returning browser without knowing who is using it.
The word “cookies” here is shorthand. It includes local storage, session storage and tracking pixels, which raise the same questions.
Documents on your disk are out of a cookie's reach, and nothing inside one can infect them; it records only that this browser has been in touch before.
2. How we use cookies
There are two groups of cookie behind xefeladi.world. The first is required for pages to load and behave correctly; the second stays dormant while the question is unanswered.
Consent is not inferred from scrolling or from continued browsing. Until you make a choice, optional cookies are not set.
Whether the answer given is yes or no, the site that loads is the same one; a refusal removes no page and closes no route to us.
3. Categories of cookie we use
Strictly necessary. Three jobs fall to this group: keeping a visit continuous from one page to the next, holding the answer already given to the cookie notice, and letting the server reject requests forged elsewhere. There is no consent step for this group, and no switch that disables it; the lawful basis is legitimate interest.
Functional. Where you have told the site how you would like it to appear, that instruction is kept here rather than being asked for a second time. Nothing here is compulsory.
Analytics. What this group produces is a table of numbers about pages. It shows that an article goes unread without saying anything about the people who skipped it. Nothing in this group runs before permission is given.
Marketing. Any cookie of this kind exists to show whether an advertisement led anywhere. The default state is off, and it changes only by a deliberate act on your part.
4. Cookies set by third parties
Where a page loads material hosted elsewhere, the host of that material may write its own cookie. Two sets of rules then apply to it, theirs and ours.
We keep embedded third parties to a minimum precisely because each one adds a party you did not choose to deal with.
Disclosure comes ahead of storage. If an outside cookie is due to be set, it appears in the consent panel while there is still a decision to make.
5. How long cookies last
Cookies fall into two groups by lifespan:
- Session cookies are erased when you close the browser. They exist only for the visit.
- Persistent cookies remain for a set period so a preference survives between visits.
Lifespans are set to the minimum that works. The consent record itself is the longest-lived, because re-asking on every visit defeats the point of asking.
6. Managing your preferences
Withdrawal runs through the same panel as consent: open it again, move the category back, and the earlier answer is replaced.
Whatever a website would prefer, the same decisions can be enforced at browser level, where you may:
- refuse every cookie, or refuse only those arriving from other domains
- delete what has already been stored, either selectively or in one sweep
- ask to be warned whenever a site wants to write something
- wipe the store on exit, without having to remember to do it
You will find these controls under privacy or security in browser settings. Blocking essential cookies breaks functionality on most websites, this one included.
7. Cookies and personal data
The test is whether one visitor can be told apart from the next, not whether anyone knows who that visitor is. A string that passes the test is treated as personal data here.
Nothing about the technical origin of the data narrows your rights over it. What applies to a message you sent us applies equally to an identifier stored in your browser.
Statistics are consulted at the level of the page rather than the person; nobody sits down to follow one browser through a week of visits.
8. Records of consent
When you make a cookie choice we record what you chose and when. Nothing else tells the site how to behave next, or shows a regulator that a decision took place.
Two fields make up the entry: the categories you allowed, and the time you allowed them. Neither carries an identity, and the entry means nothing away from the browser it sits in.
Delete the site's stored data and the entry goes too. The banner returns on your next visit, since nothing is left to say what you decided.
9. Do Not Track and global signals
Certain browsers and extensions attach an opt-out signal to outgoing traffic. The mechanism arrived without an agreed rule for the receiving end, so treatment is uneven.
The cookies in use are the necessary ones and, with consent, analytics; an opt-out signal finds none of the kind it was designed against.
10. Turning cookies off in your browser
What follows belongs to the browser, not to this site, and takes effect everywhere it goes. Menus are reorganised between releases, so the names may sit a little differently on your screen.
- Chrome. The settings hold a privacy and security section; cookies from other domains are governed there, and the permissions for one particular site under the per-site settings.
- Firefox. Open the settings, then the privacy and security panel, where the enhanced tracking protection and the block for cookies and stored site data both live.
- Safari. Open the settings, then the privacy section, for cross-site tracking and stored data; on a phone or tablet the same options sit in the device settings, under the list of apps.
- Edge. Look in the settings for the page on cookies and site permissions; blocking rules and the delete-on-close option are both there.
The incognito mode most browsers offer keeps a separate store and throws it away at the end, which spares you changing any setting at all.
11. Cookies on phones and tablets
A mobile browser handles cookies exactly as a desktop one does, and this policy applies unchanged when the site is opened on a phone.
The settings, though, are in a different place. On iOS the controls for Safari sit in the system Settings app rather than in the browser; on Android each browser keeps its own.
One consequence is worth naming: a choice made in one browser does not travel to another on the same device, and a phone and a laptop are, for this purpose, two strangers.
12. Seeing what is stored at this moment
You do not have to take this page on trust. Every modern browser can list what a site has actually stored, and the list is authoritative in a way that a policy document cannot be.
Press F12 in Chrome or Edge and the Application panel breaks the store down by origin. Firefox files it under Storage, while in Safari the Develop menu has to be switched on before the equivalent appears.
If the developer tools are more than you want, the icon next to the address bar gives a shorter answer and a single control for deleting what it finds.
13. Why you are asked at all
Permission is required before anything inessential is written to your device. Hence the notice on arrival, and hence the fact that one category is listed without a control.
Consent has to be a real choice, which means refusing must be as easy as accepting and must cost nothing. Both buttons on our notice carry the same weight, and neither is hidden behind an extra step.
Nothing here is settled permanently: the stored answer runs out in time and the question is put afresh.
14. What a refusal actually changes
The honest answer is short. Declining costs you no content whatsoever — the same pages load, in the same order, with the same text on them.
What does change is small and entirely to do with memory. Preferences you set by hand are forgotten between visits, so a language or display choice has to be made again on arrival.
The consent notice is itself an example. Where the record of your answer cannot be stored, the question is asked again on the following visit — not to pester you, but because there is nowhere to keep the reply.
15. How the stored items are protected
Alongside its value, each cookie carries instructions about how it may travel. Those instructions are configured, not inherited.
- Secure means an unencrypted request leaves the cookie behind rather than carrying it into the open.
- HttpOnly hides the value from JavaScript altogether, closing the most common path to reading it from the page.
- SameSite withholds the cookie when the request comes from somewhere else, and that restriction is what defeats forged cross-site requests.
These attributes reduce exposure; they do not create a vault. What goes into a cookie on this site is a session marker or a preference, never a credential.
16. Changes to this policy
When the list of cookies is altered, this text is brought into line with it and carries the date of that revision.
In the event that optional cookies are added rather than dropped, a fresh decision is sought, the old one having been given about something else.
17. Contact
Questions about this document, or a request concerning your data, can be sent to the address below. We answer written enquiries in the order received and aim to reply within one calendar month.
Xefeladi
352 Patel Road
248001 Dehradun
India
[email protected]
+91 135 2321252