Cookie Policy
Last updated: July 2026
Raven uses a small number of essential cookies to keep the site secure, remember your sign-in, and protect requests from misuse.
What cookies are
Cookies are small text files a website stores in your browser. They allow the site to recognise necessary state between pages and visits.
Essential cookies Raven uses
Raven uses raven_sid to maintain a signed-in session, raven_csrf to verify request origin and help prevent forged requests, and raven_rl to protect the Raven API from misuse. Sign-in is handled by Auth.js, which also uses session, CSRF, callback-url and Google OAuth-verification cookies (their names may begin with authjs. or __Secure-authjs.). When you use Festival Squad while signed in, raven_backend_token and raven_backend_token_uid securely bind the backend session to your account.
Duration and security
Sign-in and backend-session cookies last up to 30 days; the rate-limit cookie lasts up to one year. CSRF, callback-url and OAuth-verification cookies expire after the verification flow or a shorter period. Security attributes vary by purpose: sensitive session cookies are server-readable only, while the CSRF cookie must be readable by scripts that submit protected requests. Raven-owned cookies use SameSite=Lax and, in production, are sent only over HTTPS.
Your choices
These cookies are necessary for Raven to work safely. You can clear or block cookies in your browser, but sign-in, saved journeys, Festival Squad, and other protected features may no longer work properly. Raven does not use advertising or cross-site tracking cookies covered by this policy.
Contact
For questions about cookies or privacy, contact Raven through the available contact channel.