Our current approach
If non-essential tracking is introduced later, this policy and the interface will be updated before it is enabled, and prior consent will be requested where required.
Cookies used
| Name | Provider and purpose | Typical duration | Party and attributes |
|---|---|---|---|
| postiva-session | Postiva. Authentication, security, CSRF protection, and session continuity. | 120 minutes of inactivity by default | First party, essential, HttpOnly, SameSite=Lax, Secure in production |
| remember_web_* | Postiva. Keeps you signed in when you actively choose the remember option. | 30 days or until sign-out | First party, requested authentication, HttpOnly, SameSite=Lax, Secure in production |
| appearance | Postiva. Remembers light, dark, or system appearance after you select it. | 180 days | First party, requested preference, SameSite=Lax, Secure in production |
| sidebar_state | Postiva. Remembers whether the application sidebar is open. | 7 days | First party, requested preference, SameSite=Lax, Secure in production |
Local storage used
| Name | Provider and purpose | Duration | Category |
|---|---|---|---|
| appearance and appearance_expires_at | Postiva. Stores a selected theme and its expiry. | 180 days, then deleted | Requested preference |
| postiva_pwa_prompt_dismissed_at | Postiva. Avoids repeating an install prompt after dismissal. | 30 days, then deleted | Requested interface preference |
Third-party flows
Google and Paddle may set their own cookies when you deliberately start Google sign-in, checkout, or billing management. Those cookies are controlled by those providers and are covered by their privacy information.
- Google is used only for optional account authentication.
- Paddle acts as Merchant of Record for checkout, payment, tax, invoicing, and subscription management.
Your controls
You can remove cookies and local storage through your browser settings. Blocking essential storage can prevent sign-in, security checks, saved preferences, and other core functions from working.
