Legal
Cookie Policy
What we store in your browser, and why.
The Simple Truth
We use cookies and local storage for sign-in, security and remembering privacy choices. The inventory below identifies their purposes and lifetimes.
We do not collect visitor analytics. Optional browser error monitoring stays off unless you consent. We do not use advertising pixels, retargeting cookies, or cross-site behavioral profiling.
Operational signals beyond cookies
Your choice, notice version, timestamp and consent identifier are saved in this browser. Professional does not synchronize this preference to the organization consent register. Separate security and request logs can contain network information. Optional browser error monitoring remains off unless you allow it; visitor analytics, advertising, and cross-site profiling are not used.
Authentication, security, and device-trust data
IP address or minimized network summary, user-agent, browser and operating-system summary, device name, cryptographic device-fingerprint or proof hashes, session state, login events, and security-risk signals.
Purpose: Deliver magic-link authentication, authorize trusted devices, prevent abuse, investigate security events, and protect accounts and organizations.
Consent and privacy-preference evidence
Consent choice, purpose, notice version, timestamp, withdrawal state and consent identifier stored in this browser. The separately tier-gated server capture paths store pseudonymized subject references and record IP address and user-agent as null.
Purpose: Remember privacy choices and record local choice or withdrawal events. Where the separate organization consent register is enabled, support its audit evidence.
Privacy-filtered error and reliability data
Error type, scrubbed message and stack context, bounded request context, internal account identifier where set, release and environment identifiers, and privacy-filtered browser or server diagnostics. Filtered diagnostics are not necessarily anonymous.
Purpose: Detect, diagnose, and resolve security, availability, and software reliability failures.
The register records current technical purposes, categories, minimization, retention criteria, and provider paths. Owner and privacy or legal review must confirm the final controller-processor roles, lawful basis, retention periods, transfer safeguards, and notice approval. This register does not determine legal compliance.
What Are Cookies?
Cookies are small text files stored on your device when you visit a website. They're used for various purposes: remembering your login, tracking your behavior, showing targeted ads, etc.
Under EU cookie rules, websites must get consent before setting non-essential cookies or using similar storage technologies. Strictly necessary storage for security and service delivery is treated separately.
What Cookies We Use
Essential Cookies (Strictly Necessary)
Necessary sign-in and security storage is separate from the optional-monitoring choice. Your browser can block it, but that may prevent the functions you request.
| Name | Purpose | Lifetime | Storage |
|---|---|---|---|
| next-auth.session-token / __Secure-next-auth.session-token | Sign-in session | Up to 30 days; renewed during continued authenticated use | Cookie |
| next-auth.csrf-token / __Host-next-auth.csrf-token | Authentication request protection where the authentication library sets it | Browser session | Cookie |
| csrf-token | Protect application requests against cross-site request forgery | One hour from issue or refresh | Cookie |
| device-authorized | Remember authorized-device state | Up to 24 hours | Cookie |
| gdpr-consent | Privacy choices, notice version, timestamp and consent session identifier | No automatic time expiry in the current implementation; replaced on a new choice or removed when site data is cleared | Local storage |
| gdpr-consent-log / soc2-processing-log | Local consent and privacy-setting activity history; the storage name does not claim SOC 2 certification | Latest 50 entries in each log; no automatic time expiry. Removed when site data is cleared | Local storage |
Security and authentication are purposes, not a blanket consent exemption or GDPR lawful basis for every stored item. Optional browser error monitoring relies on your consent. Server record retention is separate from these browser lifetimes.
Visitor Analytics
Not used.
We do not load visitor analytics scripts. Core metadata detection, removal, verification, reporting, and compliance workflows do not depend on analytics tracking.
Marketing Cookies
We don't use marketing cookies.
No advertising pixels, retargeting or ad networks.
Consent and Global Privacy Control
Visitor analytics, marketing cookies, and advertising pixels are not used. Optional browser error monitoring is disabled by default and can be allowed or rejected in the privacy banner.
If your browser sends a Global Privacy Control signal, we treat it as an opt-out from optional browser error monitoring in that browser. This description does not assert a verified control over every third-party storage mechanism.
This is designed around:
- GDPR consent principles and EU cookie consent rules for non-essential storage
- UK ICO guidance for strictly necessary cookies and consent-based analytics
- US state privacy opt-out preference signal requirements, including CPRA/GPC-style controls
Third-Party Services
We use the following third-party services that may set their own cookies:
Error Monitoring (Sentry)
Optional browser error reports are sent to Sentry only after your consent and may include an internal account identifier and filtered technical diagnostics. Session replay and browser performance tracing are disabled in the current configuration. Server-side operational monitoring is separate from browser consent.
Purpose: Reliability and incident response
Your Control: Optional browser telemetry can be disabled from Cookie preferences in the footer
Payment Processing (Paddle)
When you purchase a subscription, payment is processed by Paddle.com. Paddle may set cookies for fraud prevention and payment processing.
Purpose: Payment processing, fraud prevention
Cookies: Determined by Paddle's privacy policy
Your Control: Required for payment functionality
Infrastructure (Vercel)
Vercel hosts our website and processes technical requests. Hosting does not itself establish that a particular cookie exists or qualifies for a consent exemption.
Purpose: Website performance, security
Storage: Depends on the enabled service and request path
Your Control: Browser storage controls remain available
These third-party services are covered by their own privacy policies:
- Cloudflare Turnstile uses network and device signals for bot protection and separately to improve its bot detection. See its Turnstile privacy notice.
- Paddle Privacy Policy: paddle.com/legal/privacy
- Sentry Privacy Policy: sentry.io/privacy
- Vercel Privacy Policy: vercel.com/legal/privacy-policy
Your Rights
You have the following rights regarding cookies:
How to manage cookies in your browser:
- Chrome: Settings → Privacy and security → Cookies and other site data
- Firefox: Settings → Privacy & Security → Cookies and Site Data
- Safari: Preferences → Privacy → Manage Website Data
- Edge: Settings → Privacy, search, and services → Cookies
Updates to This Policy
If we materially change our cookie or telemetry practices, we'll:
- Update this Cookie Policy
- Update the privacy banner where consent is required
- Give you the choice to accept, reject, or customize any non-essential storage we introduce
- Email existing users about the change
Current Status: Strictly necessary storage by default; no visitor analytics; optional browser error monitoring only after consent.
Questions about our cookie policy?
We believe in clear communication. If anything is unclear, reach out.
Contact UsV1 controlled-trial policy — owner approved
Updated September 19, 2026
Version: cookie-2026-09-19-v1