Cookie policy
This page explains which cookies and other data Porsino keeps in your browser, why, for how long, and what we measure. In short: we only use cookies that are needed, we have no third-party trackers or ads, and that is why we do not show a cookie consent banner.
Last revised: 9 Oct 2026
1. At a glance
- Every cookie belongs to Porsino itself (porsino.com). We have no advertising or social-media cookies and no outside analytics tools (such as Google Analytics or the Meta pixel).
- Cookies are used only for signing in, security, remembering your own choices (language and theme) and making forms, exams and contests work properly.
- We count visits ourselves, without cookies; IP addresses are not stored and a visitor cannot be followed from one day to the next.
- That is why there is no cookie consent banner: these cookies are needed to provide the very service you asked for.
2. What cookies and browser storage are
A cookie is a small text file a site places in your browser, which the browser sends back with later requests to the same site. «Local storage» (localStorage, sessionStorage and IndexedDB) is space inside the browser that only that site's code can read, and it is not sent to the server automatically.
A «session» cookie is deleted when you close the browser; a «persistent» cookie stays until it expires. httpOnly means page code cannot read the cookie, Secure means it is only sent over HTTPS, and SameSite=Lax means other sites cannot use it in hidden requests of their own.
3. Sign-in and security cookies
These are set only when you sign in or start signing in, and the sign-in cookies are removed when you sign out.
fc_access- Purpose:
- Keeps you signed in to the panel
- Duration:
- 15 minutes; renewed automatically with fc_refresh
- Attributes:
httpOnly · Secure · SameSite=Lax
fc_refresh- Purpose:
- Renews your sign-in without retyping your password; sent only to the sign-in renewal address
- Duration:
- 30 days
- Attributes:
httpOnly · Secure · SameSite=Lax
fc_csrf- Purpose:
- Protects against forged requests (CSRF); the panel's code reads it and sends it with every change
- Duration:
- 30 days
- Attributes:
Secure · SameSite=Lax
fc_goauth- Purpose:
- Ties «Sign in with Google» to the browser that started it
- Duration:
- 10 minutes
- Attributes:
httpOnly · Secure · SameSite=Lax
fc_sso- Purpose:
- The same for organisational sign-in
- Duration:
- 10 minutes
- Attributes:
httpOnly · Secure · SameSite=Lax
fc_gsc_state- Purpose:
- Connecting Google Search Console, for the site administrator only
- Duration:
- 10 minutes
- Attributes:
httpOnly · Secure · SameSite=Lax
4. Cookies for your choices
fc_lang- Purpose:
- The language you chose; set when you open the English edition (/en) or use the language switch
- Duration:
- 1 year
- Attributes:
SameSite=Lax
fc_theme- Purpose:
- Light, dark or system theme; set only when you change the theme yourself
- Duration:
- 1 year
- Attributes:
Secure · SameSite=Lax
5. Form, exam and contest cookies
These are set on the public pages of forms, exams and contests, and their value is only a random identifier or token. «…» means the ID of that form or contest is appended to the name.
fc_seed- Purpose:
- A random number that keeps the shuffled order of questions and options stable while the form is open
- Duration:
- Until you close the browser
- Attributes:
httpOnly · SameSite=Lax
fc_p_…- Purpose:
- Remembers that you entered a password-protected form's password, so you are not asked every time
- Duration:
- 1 day
- Attributes:
httpOnly · Secure · SameSite=Lax
fc_r_…- Purpose:
- «You have already responded», only on forms where the owner turned on «One response per person»
- Duration:
- 1 year
- Attributes:
httpOnly · Secure · SameSite=Lax
fc_at_…- Purpose:
- Your exam attempt in progress, so you can carry on after closing the browser or losing the connection
- Duration:
- 30 days
- Attributes:
httpOnly · Secure · SameSite=Lax
fc_dev- Purpose:
- A random device identifier for «device lock», only in exams where the owner has turned it on
- Duration:
- 2 years; renewed on each successful entry
- Attributes:
httpOnly · Secure · SameSite=Lax
fc_ct_…- Purpose:
- Keeps you signed in to a daily contest
- Duration:
- 180 days
- Attributes:
httpOnly · Secure · SameSite=Lax
6. Local browser storage
This data stays in your own browser. None of it is used for advertising or to follow you on other sites.
fc:draft:…- Purpose:
- A draft of the answers in a form you are filling in, so nothing is lost if the page closes
- How long:
- Until you submit; removed after 7 days
fc:fp- Purpose:
- A technical browser fingerprint — a hash of the browser type, language, screen size, time zone, colour depth and how a test text is drawn — used to spot duplicate responses and cheating; made when you submit a form, open an exam or register for a contest
- How long:
- Until you clear your browser data
fc:seed:…- Purpose:
- A stand-in for fc_seed when cookies are unavailable
- How long:
- Until you close the tab
fc.exam.attempt.…, ff_exam_backup_…, fc:scratch:…- Purpose:
- A marker for your exam attempt, a backup of answers not yet saved on the server, and your exam scratchpad
- How long:
- While needed, or until you clear your browser data
fc_theme- Purpose:
- Your chosen theme, alongside the cookie of the same name, so the page does not flash while loading
- How long:
- Until you clear your browser data
fc_promo_off- Purpose:
- The discount codes whose bar you closed
- How long:
- Until you close the tab
fc_cv_view_…- Purpose:
- Counts a view of a public résumé only once per session
- How long:
- Until you close the tab
fc_kiosk_device- Purpose:
- The kiosk device ID, only on a device the owner has set up in kiosk mode
- How long:
- Until you clear your browser data
fc:ui, fc:responses:…, fc.builder.…, xb-…, fc_growth:…, fc_nudge:…, fc_launch_notice:…, fc_activation_burst:…- Purpose:
- How the panel looks (menu, response-table columns and density, recent fields, the exam wizard step) and the notices you closed
- How long:
- Until you clear your browser data
fc:admin:…, fc:contact-…, fc_ai_key_guide_open, fc:impersonating- Purpose:
- Recent items, saved replies and reply drafts, only in the site administrators' browsers
- How long:
- Until you clear your browser data
porsino-offline (IndexedDB)- Purpose:
- The form, device token and responses of an offline interviewer, until the connection returns and the responses reach the server
- How long:
- On the interviewer's device, until browser data is cleared
porsino-app-… (Cache Storage)- Purpose:
- The site's static files and the «no connection» page for the installable app (PWA); it holds no personal data
- How long:
- Until the next version of the site
7. Analytics and tracking: what we measure
Porsino has no third-party analytics or tracking tools: no Google Analytics, no Tag Manager, no Meta pixel, no session recording (such as Hotjar) and no advertising scripts. Instead, on each page view the browser sends a small request to our own server, and only the following is stored:
- The page address (without parameters), the day, and the kind of event (a page view, a search on the site, or a sample-form download)
- Where you came from: the referring site or search engine, the search phrase if the address itself contains it, and campaign (utm) parameters
- The device type, browser family and operating system
- A «daily hash» of the IP address and browser, made with a secret server key and that day's date, used only to count unique visitors for that day. The IP address itself is not stored and a person's hash changes every day, so visits on different days cannot be linked.
- Whether the visitor was signed in (without any account identifier)
These statistics use no cookies and store nothing in your browser; they are shown only in aggregate to Porsino's administrator, go to no other service, and are deleted after 400 days. Crawlers and bots are not counted.
Apart from this: if a form owner invited you with a personal invitation link, the owner sees when the link was opened; views of public résumés are recorded only as anonymous daily counts; and Porsino's emails contain no «open» pixels or click-tracking links.
The phrases people searched for on Google come from Google Search Console only as site-wide totals and are not linked to any particular visitor.
8. Third-party content
- The eNamad trust badge at the bottom of the pages is loaded from trustseal.enamad.ir, and clicking it opens eNamad's page. To fetch the image, your browser sends eNamad your IP address, browser type and our site's address, as with any request. Porsino sets no cookies on eNamad's behalf and has no access to its data; any cookie eNamad sets is governed by eNamad's own policy.
- «Sign in with Google» takes you to Google's own page, and any cookies there are set by Google. Payments likewise happen on the bank gateway's page under that gateway's rules.
- Fonts, images and all the site's files are loaded from Porsino's own server; we do not use an outside CDN.
9. You are in control
- In your browser settings you can view, clear or block cookies and site data: in Chrome and Edge under «Settings › Privacy and security», in Firefox under «Settings › Privacy & Security», and in Safari under «Settings › Privacy».
- If you block the necessary cookies, signing in to the panel, password-protected forms, «One response per person» and resuming an exam will not work. Clearing cookies signs you out and resets your language and theme.
- A private (incognito) window clears all of this when you close it.
10. Why there is no cookie consent banner
- Iranian law does not require a cookie consent banner. European rules (Article 5(3) of the ePrivacy Directive) also do not require consent for cookies and storage that are «strictly necessary» to provide a service the user asked for: signing in, security and fraud prevention, remembering the language and theme you chose, and making a form you opened work.
- Our visit statistics use no cookies, no IP addresses and no persistent identifier, and are aggregate and for our own use only — the kind of audience measurement that data protection authorities (such as France's CNIL) treat as exempt from consent.
- If we ever add something that needs consent — such as an advertising pixel, Google Analytics or any third-party tracker — we will update this page and provide a way to give and withdraw consent before it goes live; it will not run without your consent.
11. Changes and contact
The date of the last revision is at the top of this page. Send questions about cookies through the contact page; for everything else about your data, see the Privacy policy.
Related documents: Privacy policy · Porsino Terms of Service