Legal
Cookie policy
Last updated: 2026-09-01. Short version: we set almost no cookies, and none of them track you across other sites.
1. What we set
| Cookie | Purpose | Lifetime |
|---|---|---|
session | Authenticated session after sign-in (HttpOnly, Secure) | Rolling, 30 days |
csrf | Cross-site-request-forgery token for mutation endpoints | Session |
consent | Remembers your cookie choice so we don't ask again | 1 year |
We use local storage for UI preferences (e.g. collapsed sidebar). Those preferences never leave your device and are not advertising beacons.
2. What we don't set
- Third-party advertising cookies.
- Cross-site tracking beacons.
- Social login widgets that set their own cookies on this domain.
3. Consent
Strictly necessary cookies need no consent. Any future marketing or analytics cookie would appear the first time we set it, via a prompt shown to users in the EU/UK and California, and would be switchable any time from the consent banner.
4. Managing cookies
You can delete cookies through your browser settings. Clearing session signs you out; the platform works identically without every cookie — we'd prefer that too.
Questions: dpo@cidbee.example.