Cookie policy
Last updated: 2026-08-20
We use exactly two categories of cookies. Both are documented below. We do not use advertising cookies, cross-site trackers, or social-sharing widgets that drop cookies.
Essential cookies
These are required for the portal to work. You can't turn them off — if you block them, sign-in stops working.
| Name | Purpose | Lifetime | Set by |
|---|---|---|---|
__Secure-authjs.session-token | Authenticated session for the portal | 30 days from issue, rolling | Auth.js (us) |
__Host-authjs.csrf-token | CSRF protection on form submissions | Session | Auth.js (us) |
__Secure-authjs.callback-url | Where to send you after sign-in | Session | Auth.js (us) |
(Names vary slightly between browsers. The __Host- and __Secure-
prefixes are Auth.js defaults; they're enforced over HTTPS only.)
Analytics cookies (opt-in)
Off by default. Loaded only after you click "Accept" on the cookie banner. Until then, no analytics scripts run and no analytics cookies are written.
When enabled, we track which marketing pages you visit so we can see where to invest in docs and improvements. We do not:
- Track you across other websites.
- Build user profiles for advertising.
- Share analytics data with third parties for marketing purposes.
You can change this decision at any time from the cookie banner (it's re-shown if you clear browser storage).
Desktop-app telemetry
The desktop app does not use cookies. It can collect anonymous usage events only if you explicitly opt in via Settings → Privacy in the app. Off by default; turning it off drops any queued events immediately.
Questions
Email legal@lunamic.co.