Last updated: 2026-09-30

Cookie Policy

The few cookies we set, what they do, and how to control them.

The short version

We don't use advertising or cross-site tracking cookies. Our analytics are cookieless. The only cookies we set are the ones needed to run the service and to remember your own preferences.

Strictly necessary

These are required for the service to work and can't be switched off. They're set only after you sign in or interact with the app:

  • Session cookies (set by our authentication layer) — keep you signed in. These are HttpOnly, Secure, and SameSite. OAuth and two-factor flows set additional short-lived cookies that exist only for the duration of that flow.
  • Security cookies — protect against cross-site request forgery and similar attacks.

Functional

Set only when you make a choice, and used to remember it. These are functional cookies that remember a setting you explicitly chose, so they don't require consent — we simply disclose them here:

  • Theme preference — remembers your light/dark choice (`nuxt-color-mode` cookie). Set only when you pick a theme.

Analytics — cookieless

Our product analytics (self-hosted Umami) set no cookies at all. Guests can opt out, and optional session replays/heatmaps require a separate, explicit opt-in.

Managing cookies

You can review and change your choices any time via the cookie preferences control in the site footer, and you can clear cookies in your browser settings. Blocking strictly-necessary cookies will break sign-in.

Cookie questions?

Ask us anything about how we use cookies.