Cookies for sign-in
| Cookie | Purpose | Duration |
|---|---|---|
veyra_oauth_state | Bind the Discord return to the login request. | Up to 10 minutes. |
veyra_oauth_return | Return you to the requested dashboard page. | Up to 10 minutes. |
The authentication backend sets these cookies when you start Discord sign-in and clears them after a successful callback. They use HttpOnly, Secure and SameSite=Lax. Blocking them can prevent login from completing.
Local storage
| Entry | Purpose | Duration |
|---|---|---|
veyra.auth.session | Authorize your signed-in dashboard requests. This is sensitive: never share its value. | The server session lasts up to 30 days. The browser entry has no automatic storage expiry; logout or rejected/expired login clears its value. |
veyra.runtime.apiBase and selected-account entry | Remember the connection address and which linked Roblox account you selected. | Until replaced or cleared. |
veyra.theme.*, veyra.sidebar.*, veyra.logs.* | Remember appearance, navigation and log-view choices. | Until replaced or cleared. |
veyra.runtime.config | Remember settings saved through Configuration. | Until reset or cleared. |
Local storage belongs to this browser and site origin. Its presence does not extend server-side retention. Technical entry names still use the earlier Veyra prefix.
Session storage
veyra.fromHome temporarily controls the transition from the homepage. veyra.accountDeletionNotice can show the result after account deletion. These entries are consumed by the next relevant page and otherwise end with the browser’s tab session, subject to its restore behaviour.
Tracking and external services
The reviewed test version includes no advertising or marketing tracker. It does record runtime activity on the backend as described in Privacy. External avatar requests, Discord login and hosting can expose connection metadata to the provider.
This notice describes storage; it is not a consent banner. Sign-in is not permission for unrelated tracking. If optional tracking is introduced, applicable consent requirements and controls need to be resolved before it loads. Current preference-storage purposes also need review before an open release.
Your choices
- Sign out to revoke the current Aroyn web session. Other sessions and server data are not deleted by ordinary logout.
- Change interface settings in the dashboard or reset saved configuration in Configuration.
- Use your browser’s site-data controls to remove cookies and local/session storage for the dashboard and its authentication origin. This signs you out and resets local choices; it does not delete your server account.
- Use Account data to export/delete server-side Aroyn account data. Account deletion clears Aroyn storage in the current browser; other devices’ copies are outside its control.
Questions
Aroyn is a free independent project maintained by vmsize from Ukraine. Contact: septave on Discord. Find the username through Discord’s Add Friend screen and send a private message. Do not include passwords, dashboard keys, access tokens or identity documents.
Preview updated 1 October 2026. Read Privacy and Terms for account data and service rules.