Cookie Policy
Last updated: September 17, 2026
This page explains the small number of cookies VIRTUX uses on its web pages. We currently use only cookies that are necessary for security and requested functionality.
Cookies used by VIRTUX
VIRTUX currently uses two first-party technical cookies on ordinary web pages. When you choose “Remember me” at sign-in, a third first-party technical cookie is added to restore your sign-in after the short idle session expires. None of these cookies is used to identify you for advertising, measure visits, build profiles, or track you across websites.
| Cookie | Purpose | Duration |
|---|---|---|
virtux_session |
Keeps the Laravel web session available between requests. It is used for authentication, redirects, security state, and temporary messages. The session data itself is stored server-side; the browser cookie carries only a protected session value. | 120 minutes after the last activity. |
XSRF-TOKEN |
Helps the browser include a CSRF token with state-changing requests so VIRTUX can reject forged requests. It is not an authentication cookie and is not used for analytics or advertising. | 120 minutes from issue, and refreshed as needed by the application. |
remember_web_59ba36addc2b2f9401580f014c7f58ea4e30989d |
Optional technical cookie created when you select “Remember me”. It lets VIRTUX restore your web sign-in after the idle session expires. It contains a protected value, is not used for analytics or advertising, and is removed when you log out. | Up to 86400 minutes (60 days), unless you remove it or log out sooner. |
Cookie security and storage
The session and remember-me cookies are currently configured as Secure, HttpOnly, and SameSite=lax. The XSRF-TOKEN value is intentionally readable by the browser because the CSRF protection mechanism needs to copy it into a request header; it does not grant account access. Cookie scope follows the application session configuration. The session data itself is stored server-side, and the remember-me cookie carries only a protected value used to restore the sign-in.
No tracking or third-party cookies
VIRTUX does not currently load analytics, advertising, social-media, personalization, or third-party font cookies on these pages. The optional remember-me cookie is a technical convenience selected by you, not a tracking cookie. We do not operate a cookie consent banner while this remains the complete cookie set. If we introduce a non-essential tracking cookie or a third-party service that places one, we will update this policy and review the appropriate consent and controls before enabling it.
Managing cookies
You can block or delete cookies through your browser settings. Because the cookies described above are necessary, blocking them may prevent sign-in, form submission, CSRF-protected actions, or other parts of the web service from working correctly.
Related policies
For information about personal data and your rights, see our Privacy Policy. The general rules for using VIRTUX are in our Terms of Service.
Contact us
Questions about this Cookie Policy? Contact us via the in-app support channel or at [email protected].