Legal
Cookie policy.
Last updated: September 4, 2026
Presently sets cookies to keep you signed in and to remember a couple of interface choices. That is the whole list. There is no advertising network here, no cross-site tracking, and no third party reading your activity.
Cookies we set
| Name | Purpose | Type | Expiry |
|---|---|---|---|
| authjs.session-token | Keeps you signed in. Without it every page load would ask you to log in again. | Strictly necessary | 30 days, or until you sign out |
| authjs.csrf-token | Protects sign-in and form submissions from cross-site request forgery. | Strictly necessary | Session |
| authjs.callback-url | Returns you to the page you were on after signing in. | Strictly necessary | Session |
All three are strictly necessary — the service cannot work without them — which is why there is no consent banner asking permission for them. Blocking them in your browser will stop you being able to sign in.
Local storage, not cookies
A few preferences live in your browser’s local storage rather than in a cookie. They never leave your device and are never sent to us: your light or dark theme choice, the last workspace you had open, which view you prefer per folder, and which folders you had expanded.
Payments
Checkout runs through Paddle, our merchant of record. When you open the checkout, Paddle sets its own cookies to process the transaction and detect fraud, under its own privacy policy. We never see your card details.
Client share links
A client opening a share link needs no account and gets no session cookie. The page remembers their chosen view in local storage on their own device, and nothing else.
Changes
If we add a cookie, this table is updated before it ships. See also the privacy policy.