cardcura_parent_sessionStrictly necessaryHttpOnlyKeeps an adult signed in to the Parent Hub. The cookie contains a random session secret; account details are resolved server-side from its hashed database record.
Expires after 30 days
Effective September 10, 2026
CardCura sets 2 cookies. Both are strictly necessary session cookies: one for an adult Parent Hub session and one for a paired Kid Portal session. That is the whole list.
Because there are no optional cookies, CardCura does not show a consent banner or set a separate cookie merely to remember that you dismissed one. If optional cookies are introduced later, they must be off until you choose otherwise.
cardcura_parent_sessionStrictly necessaryHttpOnlyKeeps an adult signed in to the Parent Hub. The cookie contains a random session secret; account details are resolved server-side from its hashed database record.
Expires after 30 days
kid_session_idStrictly necessaryHttpOnlyKeeps one paired device signed in to one child’s limited Kid Portal. It can view that child’s information and submit routine check-ins, but it cannot change balances or family settings.
Expires after 12 hours
You can delete or block cookies in your browser settings at any time. If you block the two session cookies, signing in to the Parent Hub and pairing a child's tablet will stop working — those cookies are how the app knows who you are.
A paired child device holds one cookie for a limited Kid Portal session. It can view that child's information and submit routine check-ins, but it cannot change balances or family settings. No analytics, advertising, or tracking script loads on a child-facing page.
Questions go to privacy@cardcura.com. See also our privacy policy.