Ruling

Cookies.

Ruling only uses strictly necessary cookies for sign-in and spam prevention. Analytics are cookieless, and there are no advertising cookies.

Last updated: October 6, 2026

Sign-in cookies (strictly necessary)

Ruling's sign-in system (Auth.js) sets authjs.session-token to keep you signed in and authjs.csrf-token to protect forms against cross-site request forgery. During sign-in it may briefly set authjs.callback-url, and for Google or GitHub sign-in authjs.state and authjs.pkce.code_verifier. On ruling.so these names carry a __Secure- or __Host- prefix. They are required for accounts, reviews, and submissions, and are never used for tracking.

Security and spam-prevention (strictly necessary)

Ruling uses Cloudflare Turnstile on sign-in, review, and submission forms to stop automated spam. Turnstile runs from Cloudflare's own domain and may set or read a security cookie there and process browser and interaction signals to verify that a form submission is legitimate.

Analytics (no cookies)

Ruling's product analytics (PostHog, EU Cloud) run in cookieless mode: they set no cookies and store no identifier in your browser. Visits are counted with a privacy-preserving hash so we can see page views, searches, comparison usage, and form events without tracking you across sites.

No advertising cookies

Ruling runs no advertising pixels and sets no advertising or cross-site tracking cookies.

Your choices

Because these cookies are strictly necessary, we do not show a consent banner. You can still block or delete cookies in your browser, but signing in and protected forms will not work if sign-in cookies or Turnstile are blocked.