Cookie Policy

Last updated: September 2026

Strictly necessary cookies

These are required for the app to function and cannot be switched off:

  • Session cookie (authjs.session-token / host-prefixed variants): keeps you signed in. Http-only, secure, SameSite=Lax.
  • CSRF token (authjs.csrf-token): protects authentication requests against cross-site forgery.
  • Callback URL (authjs.callback-url): returns you to the right page after signing in.

Local storage

We use your browser's local storage to remember your theme preference (light/dark/system). This never leaves your device.

What we don't use

No advertising cookies, no cross-site tracking, no third-party analytics in the MVP. If that changes we will update this policy and ask for consent where required.


This document is a plain-language template provided for transparency about how the product works. It is not legal advice. Consult a qualified professional before relying on it for compliance purposes.