Legal

Cookie Policy

The Wyvern Fellowship Ltd · Last updated: 6 September 2026. This page reflects a review of the cookies our website technically sets, current as of that date; as with our other legal pages, it should be checked by a solicitor before the site goes fully live.

The Wyvern Fellowship's website currently uses only strictly necessary cookies, the kind that UK law (the Privacy and Electronic Communications Regulations) allows without asking for your consent, because the site simply can't work without them. We do not use advertising, analytics, or any other non-essential cookie.

Strictly Necessary Cookies

These cookies are set only when you sign in or take a specific action that needs them, are never used to track you across other websites, and are all removed automatically once they expire or you sign out.

CookiePurposeExpires
twf_sessionKeeps you signed in to your member account as you move between pages.30 days, or when you sign out
twf_studio_sessionThe same, for staff signed in to the Studio admin area.12 hours, or when you sign out
twf_trusted_device Set only if you tick "remember this device" when completing two-factor sign-in on your member account, so you're not asked for a code again on that device for a while. 30 days
twf_studio_trusted_deviceThe same, for two-factor sign-in to the Studio admin area.30 days
twf_discord_oauth_state Set only momentarily while you connect a Discord account from your member settings, to confirm the request genuinely came from you rather than a forged link. 10 minutes, or once the connection completes

Payments

When you make a payment or take out a Subscription, we redirect you to Stripe's own secure checkout page (a stripe.com address) to enter your card details — we never see or handle your card number ourselves, and no payment-related cookie is set on our own domain. Stripe may set its own cookies while you're on that page, under its own privacy and cookie notices, which we don't control.

Analytics

We use Cloudflare's basic website analytics to see aggregate traffic figures such as page views, visitor counts and countries visited from. This works entirely from Cloudflare's own server-side request logs at the network edge; it does not use a cookie, script, or any other identifier placed on your device, and does not track you individually or across other websites. Because no cookie is involved, it doesn't require the consent banner that cookie-based analytics would.

What We Don't Use

We do not use advertising or tracking cookies, or any cookie-based analytics. Our launch film plays from a video file hosted on our own site, not an embedded third-party player, so it doesn't set a cookie either. Signing up to our newsletter does not set a cookie: the signup form sends your email straight to our newsletter provider from our own server, not from a script running in your browser.

If This Changes

If we ever add a cookie-based analytics, advertising, or other non-essential cookie, we'll update this page and add a consent banner asking for your permission first, as UK law requires.