Skip to main content

Legal

Cookie Policy

What we store in your browser, and why.

The Simple Truth

We use cookies and local storage for sign-in, security and remembering privacy choices. The inventory below identifies their purposes and lifetimes.

We do not collect visitor analytics. Optional browser error monitoring stays off unless you consent. We do not use advertising pixels, retargeting cookies, or cross-site behavioral profiling.

Operational signals beyond cookies

Your choice, notice version, timestamp and consent identifier are saved in this browser. Professional does not synchronize this preference to the organization consent register. Separate security and request logs can contain network information. Optional browser error monitoring remains off unless you allow it; visitor analytics, advertising, and cross-site profiling are not used.

Authentication, security, and device-trust data

IP address or minimized network summary, user-agent, browser and operating-system summary, device name, cryptographic device-fingerprint or proof hashes, session state, login events, and security-risk signals.

Purpose: Deliver magic-link authentication, authorize trusted devices, prevent abuse, investigate security events, and protect accounts and organizations.

Consent and privacy-preference evidence

Consent choice, purpose, notice version, timestamp, withdrawal state and consent identifier stored in this browser. The separately tier-gated server capture paths store pseudonymized subject references and record IP address and user-agent as null.

Purpose: Remember privacy choices and record local choice or withdrawal events. Where the separate organization consent register is enabled, support its audit evidence.

Privacy-filtered error and reliability data

Error type, scrubbed message and stack context, bounded request context, internal account identifier where set, release and environment identifiers, and privacy-filtered browser or server diagnostics. Filtered diagnostics are not necessarily anonymous.

Purpose: Detect, diagnose, and resolve security, availability, and software reliability failures.

The register records current technical purposes, categories, minimization, retention criteria, and provider paths. Owner and privacy or legal review must confirm the final controller-processor roles, lawful basis, retention periods, transfer safeguards, and notice approval. This register does not determine legal compliance.

What Are Cookies?

Cookies are small text files stored on your device when you visit a website. They're used for various purposes: remembering your login, tracking your behavior, showing targeted ads, etc.

Under EU cookie rules, websites must get consent before setting non-essential cookies or using similar storage technologies. Strictly necessary storage for security and service delivery is treated separately.

What Cookies We Use

Essential Cookies (Strictly Necessary)

Necessary sign-in and security storage is separate from the optional-monitoring choice. Your browser can block it, but that may prevent the functions you request.

Sign-in and privacy-control storage used by ScrubMetadata. Cookies are sent to the relevant site endpoint. Local privacy choices may also be synchronized to our server as described below. Other providers are described separately.
NamePurposeLifetimeStorage
next-auth.session-token / __Secure-next-auth.session-tokenSign-in sessionUp to 30 days; renewed during continued authenticated useCookie
next-auth.csrf-token / __Host-next-auth.csrf-tokenAuthentication request protection where the authentication library sets itBrowser sessionCookie
csrf-tokenProtect application requests against cross-site request forgeryOne hour from issue or refreshCookie
device-authorizedRemember authorized-device stateUp to 24 hoursCookie
gdpr-consentPrivacy choices, notice version, timestamp and consent session identifierNo automatic time expiry in the current implementation; replaced on a new choice or removed when site data is clearedLocal storage
gdpr-consent-log / soc2-processing-logLocal consent and privacy-setting activity history; the storage name does not claim SOC 2 certificationLatest 50 entries in each log; no automatic time expiry. Removed when site data is clearedLocal storage

Security and authentication are purposes, not a blanket consent exemption or GDPR lawful basis for every stored item. Optional browser error monitoring relies on your consent. Server record retention is separate from these browser lifetimes.

Visitor Analytics

Not used.

We do not load visitor analytics scripts. Core metadata detection, removal, verification, reporting, and compliance workflows do not depend on analytics tracking.

Marketing Cookies

We don't use marketing cookies.

No advertising pixels, retargeting or ad networks.

Consent and Global Privacy Control

Visitor analytics, marketing cookies, and advertising pixels are not used. Optional browser error monitoring is disabled by default and can be allowed or rejected in the privacy banner.

If your browser sends a Global Privacy Control signal, we treat it as an opt-out from optional browser error monitoring in that browser. This description does not assert a verified control over every third-party storage mechanism.

This is designed around:

  • GDPR consent principles and EU cookie consent rules for non-essential storage
  • UK ICO guidance for strictly necessary cookies and consent-based analytics
  • US state privacy opt-out preference signal requirements, including CPRA/GPC-style controls

Third-Party Services

We use the following third-party services that may set their own cookies:

Error Monitoring (Sentry)

Optional browser error reports are sent to Sentry only after your consent and may include an internal account identifier and filtered technical diagnostics. Session replay and browser performance tracing are disabled in the current configuration. Server-side operational monitoring is separate from browser consent.

Purpose: Reliability and incident response
Your Control: Optional browser telemetry can be disabled from Cookie preferences in the footer

Payment Processing (Paddle)

When you purchase a subscription, payment is processed by Paddle.com. Paddle may set cookies for fraud prevention and payment processing.

Purpose: Payment processing, fraud prevention
Cookies: Determined by Paddle's privacy policy
Your Control: Required for payment functionality

Infrastructure (Vercel)

Vercel hosts our website and processes technical requests. Hosting does not itself establish that a particular cookie exists or qualifies for a consent exemption.

Purpose: Website performance, security
Storage: Depends on the enabled service and request path
Your Control: Browser storage controls remain available

These third-party services are covered by their own privacy policies:

Your Rights

You have the following rights regarding cookies:

Delete Cookies: You can delete cookies through your browser settings at any time.
Block Cookies: You can configure your browser to block all cookies (note: this may affect website functionality).
Opt-Out: You can reject optional browser error monitoring from the banner or Cookie preferences in the footer. Visitor analytics and marketing cookies are not used.

How to manage cookies in your browser:

  • Chrome: Settings → Privacy and security → Cookies and other site data
  • Firefox: Settings → Privacy & Security → Cookies and Site Data
  • Safari: Preferences → Privacy → Manage Website Data
  • Edge: Settings → Privacy, search, and services → Cookies

Updates to This Policy

If we materially change our cookie or telemetry practices, we'll:

  1. Update this Cookie Policy
  2. Update the privacy banner where consent is required
  3. Give you the choice to accept, reject, or customize any non-essential storage we introduce
  4. Email existing users about the change

Current Status: Strictly necessary storage by default; no visitor analytics; optional browser error monitoring only after consent.

Questions about our cookie policy?

We believe in clear communication. If anything is unclear, reach out.

Contact Us

V1 controlled-trial policy — owner approved

Updated September 19, 2026

Version: cookie-2026-09-19-v1

Cookie Policy | ScrubMetadata