Skip to content

Cookies

Cookie policy

Five cookies to sign you in, three security cookies on the verification page, and one that remembers a referral link. No advertising.

Last updated

The short version

Bastion can set nine cookies. Five exist only to sign you in to the dashboard with Discord and keep you signed in. They are set when you start to sign in, not when you just read the site.

Two short ones belong to the web verification page. They are set only when a server asks you to show which Discord account you are, last 10 minutes, and create no Bastion account.

One is a security cookie. It is set only if you verify for a Discord server on our web verification page, and only if that server looks for second accounts. The page tells you about it before you press the button. See the device cookie below.

The last remembers which referral link brought you here. It is set only if you arrive through one, holds the link's label and the time, and holds no ID. See the referral cookie below.

There are no advertising cookies, no cookies from analytics companies and no tracking across websites.

The cookies we set

NameWhat it is forHow long it lasts
__Secure-authjs.session-tokenKeeps you signed in. It holds a random ID that points to your session in our database, and nothing else.7 days, or until you sign out.
__Host-authjs.csrf-tokenStops another website from signing you in or out without you knowing.Until you close your browser.
__Secure-authjs.callback-urlRemembers which page to return you to after you sign in.Until you close your browser.
__Secure-authjs.stateProves that the answer coming back from Discord belongs to the sign-in you started.15 minutes.
__Secure-authjs.pkce.code_verifierA one-time secret that stops a stolen sign-in code from being used by anyone else.15 minutes.
__Host-bastion-deviceA security cookie, not a sign-in cookie. It holds a random ID so that two Discord accounts verified from the same browser can be matched. It is only set when you press the button on a web verification page for a server that looks for second accounts. Your browser sends it back to this site and to no other site or subdomain. Only the verification pages read it.180 days.
__Host-bastion-verify-stateStrictly necessary. Set when you press Sign in with Discord on a web verification page. It holds a random value and the link you came from, so the answer coming back from Discord is only accepted in the browser that asked, and you are returned to the same link.10 minutes, or until you come back from Discord.
__Host-bastion-verify-proofStrictly necessary. Set when you come back from Discord to a web verification page. It holds your Discord ID and the one link it is for, signed so it cannot be changed. It is no use for any other link, and it is not a dashboard sign in.10 minutes, or until you press the button on the page.
bastion_refNot strictly necessary. Set only when you open a page of this site through a referral link, an address that ends in ?r= and a label such as ?r=top.gg. It holds that label and the time, and nothing else: no ID of you, your browser or your visit. It tells us which links bring people to Bastion. It is not set if your browser sends Global Privacy Control or Do Not Track.90 days from the last time you arrived through a referral link.

All nine are first-party cookies set by this site. Scripts cannot read them (they are HttpOnly), they are sent only over HTTPS, and they are not sent with requests that other websites make (SameSite=Lax).

On a development copy of the site that does not use HTTPS, the same cookies appear without the __Secure- or __Host- prefix, for example authjs.session-token.

The device cookie

Some Discord servers ask new members to verify on a page of this site. If the server has switched on second account detection, pressing the button on that page saves the cookie __Host-bastion-device in your browser.

  • What it holds. A random ID. Nothing about you, your Discord account or your device.
  • What it is for. If a second Discord account verifies from the same browser, the server's staff are told the two accounts share a device. That is how servers catch people who come back on a new account after a ban.
  • What we keep. Not the ID itself. We keep a scrambled copy that only works inside that one server, for 90 days. The privacy policy has the detail.
  • When it is not set. When you only open the page without pressing the button, when the server does not look for second accounts, and everywhere else on this site.
  • How it is locked down. The __Host- at the start of its name makes your browser accept it only from this exact site, over HTTPS. No other site or subdomain can set it or change it. Scripts on the page cannot read it.
  • How long it lasts. 180 days from the first time it is set. It is not renewed.

This cookie is not needed to sign in. It is there for the security check the server has asked for, which is why the page tells you about it in plain words before you press the button instead of showing a banner. If you would rather not have it, do not press the button, and ask that server's staff for another way in. You can delete it in your browser at any time.

The referral cookie

Some links to this site end in ?r= and a short label, for example ?r=top.gg. If you arrive through one, the site saves the cookie bastion_ref in your browser.

  • What it holds. The label from the link and the time it was set. Nothing else. There is no ID in it, so two people who arrive through the same link at the same moment hold the same value.
  • What it is for. If you later add Bastion to a server or buy Bastion Pro, we can tell which link brought you. The privacy policy says what is kept then.
  • When it is not set. When you arrive any other way, and whenever your browser sends Global Privacy Control or Do Not Track. With either signal a referral cookie that is already there is removed.
  • How long it lasts. 90 days. Arriving through another referral link replaces the label and starts the time again.

This cookie is not needed for the site to work, and nothing changes for you without it. You can delete it in your browser at any time, or switch on Global Privacy Control or Do Not Track and it will not come back.

Other storage in your browser

None. The site does not use local storage, session storage or any other way of saving data in your browser.

Other companies

  • Before you sign in, your browser talks only to this site. Fonts, scripts and images all come from our own address.
  • Discord. Signing in, to the dashboard or on a web verification page, takes you to discord.com, which sets its own cookies under its own policy. Once you are signed in, your browser loads your avatar and your servers' icons from Discord's image servers. Those requests carry no cookies of ours and do not say which page you were on.
  • Stripe. You pay for Bastion Pro on our own checkout page, in the dashboard. That one page loads Stripe's payment form, and Stripe sets two cookies there to spot card fraud: __stripe_mid, which lasts 1 year, and __stripe_sid, which lasts 30 minutes. They are strictly necessary for taking a payment safely, they are set by Stripe and not by us, and no other page on this site loads anything from Stripe. The form runs in frames from Stripe's own addresses, which may keep cookies of their own (such as m) under Stripe's policy. If you open the billing portal to change your card or see invoices, you are taken to a page on stripe.com, which also sets its own cookies.

Turning cookies off

You can block or delete cookies in your browser's settings. The public pages of this site work without them, and so does the web verification page on a server that does not ask who you are. Signing in does not, because there would be no way to know it is you.

Changes

If we ever add an advertising cookie, a cookie from an analytics company, or any cookie that identifies you for something other than signing in or security, we will ask for your consent first and list it here. Questions go to support@bastionbot.xyz. See also the privacy policy.