Cookie Policy
Last updated: 2026-07-14
What cookies we set
We set two cookies. Both are strictly necessary to provide a service you have asked for: one keeps you signed in, the other remembers your language. They are listed in the table below.
Over HTTPS the session cookie carries the __Secure- prefix and is HttpOnly and SameSite=Lax — it cannot be read by JavaScript and is not sent on cross-site requests. The language cookie is readable by JavaScript because the page needs it to render in your language.
Analytics and consent
Under the ePrivacy Directive and the GDPR, the two strictly-necessary cookies above do not require consent.
If analytics is enabled, we use PostHog to understand how the product is used. It loads — and sets its cookies — only after you accept the consent banner; decline and nothing analytics-related runs. Clear the consent cookie to be asked again.
Controlling cookies
You can delete or block cookies in your browser settings. Blocking the session cookie will prevent you from signing in — the Service cannot work without it.
Contact
Questions about this page: [privacy@yourdomain].
Cookie table
| Name | Purpose | Duration | Category |
|---|---|---|---|
| __Secure-better-auth.session_token | Keeps you signed in. Without it, every page load would sign you out. | 7 days | Strictly necessary |
| PARAGLIDE_LOCALE | Remembers the language you chose, so the site stays in it. | 400 days | Strictly necessary (functional) |