Cookie policy
The cookies we set — all strictly necessary — and why there is no banner.
Last updated: August 10, 2026
Why you see no consent banner
We set no analytics, advertising or cross-site tracking cookies. Every cookie we use is strictly necessary to deliver the service you asked for, and those are exempt from prior consent.
If we ever add audience measurement, a banner will appear before it stores anything, and this page will change accordingly.
What we set
The complete list, as it appears in the code.
- Session cookie — keeps you signed in. Necessary. Expires at the end of the session or at its maximum age.
- CSRF token — protects forms against forged requests. Necessary. Session duration.
- locale — remembers your language so we need not read the database on every render. Necessary. One year.
- Display theme — remembers light or dark mode. Stored locally in your browser, never sent to the server.
- Payment provider cookies — set by Stripe or Paddle on the payment page, for transaction security and fraud prevention. Governed by their own policies.
Refusing them
Your browser can block or clear cookies. Blocking the necessary ones will prevent you from staying signed in, and therefore from using the service.