Legal

Cookies

What the Student Portal stores in your browser, and why.

Updated 17 September 2026

ComUni uses only strictly necessary cookies and browser storage. There are no analytics, advertising, social-media, or other third-party cookies or trackers. Because these items are required for signing in, for security, or to keep a choice you made, they cannot be switched off inside ComUni, and no consent choice is needed.

Cookies

NamePurposeLifetime
__Host-comuni_portal_sessionKeeps you signed in to the Student Portal. Holds a random session token; your account details stay on the server.Up to 7 days. The session stops working after 12 hours without activity, and the cookie is deleted when you sign out.
__Host-comuni_portal_csrfProtects forms and actions from cross-site request forgery. Set before sign-in so the sign-in form is protected too.12 hours. A new one is issued when needed.
comuni_localeRemembers the interface language you chose (English or Română) on this site. It holds only the language code.1 year. It holds only your language choice.

The session and security cookies are HttpOnly (page scripts cannot read them), Secure (sent only over HTTPS), SameSite=Strict (not sent with requests from other sites), and use the __Host- prefix, which ties them to this exact host. On a local development server without HTTPS the prefix is omitted.

The language cookie comuni_locale is readable by the page, because the page sets it when you choose a language. It is tied to this host, holds only “en” or “ro”, and is never used to identify you.

Older ComUni versions used cookies named comuni_session and comuni_csrf. They are no longer set; if your browser still holds one, ComUni deletes it.

Other browser storage

NamePurposeLifetime
comuni.cookieNoticeLocal storageRemembers that you closed the cookie notice in this browser. It holds only the notice version, never who you are.Until you clear this site’s data in your browser.
comuni.localePendingSession storageHolds a language you just chose until it is saved to your account, so your other ComUni site can use it too.Removed once saved to your account, or when the tab closes.

Student Portal and BackOffice are separate

The Student Portal and the BackOffice run on different host names and never share cookies. Signing in to one does not sign you in to the other, and a cookie from one is not accepted by the other. The BackOffice uses its own cookies: __Host-comuni_backoffice_session and __Host-comuni_backoffice_csrf. When you are signed in, your language choice is saved to your account instead, so both sites can show the same language without sharing a cookie.

Your choices

You can delete cookies and site data in your browser settings at any time. Deleting the session cookie signs you out, and blocking these cookies prevents sign-in. This page stays available from the sign-in page and the Portal footer.

The institution that issued your account is responsible for how your personal data is processed. See Personal data and privacy in the Terms, or contact the institution or its data-protection officer with questions.