Cookie policy
Last updated: 22 August 2026
This page describes cookies and similar storage used by FlyCal at app.flycal.it. It sits next to the privacy policy, which covers personal data more broadly.
Controller: Antonio Molinari, Via Caselle 6, 26032 Ostiano (CR), Italy — support@m6i.it.
What a cookie is
A cookie is a small piece of data a site can store on your device. Similar jobs can be done with local storage or with cookies set by other domains when the page loads their scripts. They can be strictly necessary for the service you asked for, or optional (statistics, advertising, extra features).
What FlyCal uses today
FlyCal currently uses technical storage only. There is no consent banner because there are no optional analytics, advertising, or profiling cookies. If that changes, this page will be updated and, where the law requires it, a choice will be offered before those tools run.
Session cookie
The application sets an encrypted session cookie (name in the form _flycal_app_session).
It keeps you signed in, stores the CSRF token that protects forms, and remembers the interface language
you selected. It is a first-party cookie, typically for the duration of the browser session, and is
marked Secure in production.
Legal basis: it is needed to provide the service you request (login and a working site). Under the Italian ePrivacy rules, strictly necessary cookies of this kind do not require prior consent.
Invitation cookie
If you arrive with an invitation code, FlyCal may set flycal_invitation so the code
survives until you finish signing up. It is first-party and technical. You can drop it by clearing
this site’s cookies.
What is not used today
At the date on this page FlyCal does not use:
- audience measurement or product analytics cookies;
- advertising, remarketing, or social pixels;
- session replay or heatmaps;
- a third-party consent platform;
- chat widgets that drop their own tracking cookies.
Sentry is used for crash reports from the server. It is not loaded as a marketing tag. Diagnostic events can include technical data described in the privacy policy. Session replay in the browser is not enabled.
Third-party requests that are not FlyCal cookies
Some pages ask your browser to fetch resources from other hosts so the interface can render:
- Google Fonts — the Lato typeface. Google may see your IP address and user agent.
- jsDelivr — the FullCalendar script on calendar screens. The CDN may see IP and user agent.
- Google Sign-In / Calendar — if you connect Google, Google’s own cookies and storage apply on Google’s domains during that flow. FlyCal does not control them.
Those requests are there to show fonts, the calendar grid, or to complete login. They are not FlyCal advertising tools. Details and transfer information are in the privacy policy.
How to control cookies
You can delete or block cookies in your browser settings. Blocking the session cookie will prevent sign-in and some forms from working. Clearing site data also removes the invitation cookie and any local preferences.
Browser help pages (Chrome, Firefox, Safari, Edge) explain how to see which cookies a site has stored.
Updates
If optional cookies are introduced — for example to understand how the public landing is used, or because a paid checkout needs a payment provider’s script — this policy will list them, say whether they are first- or third-party, and wait for consent where required.