The hosted service uses exactly two cookies, both strictly necessary for signing in and staying signed in:
| Cookie | Purpose | Type | Lifetime |
|---|---|---|---|
dr_session | Keeps you signed in (opaque, signed session identifier) | Strictly necessary; HttpOnly, Secure, SameSite=Lax | 7 days, refreshed while you use the service, capped at 30 days total |
dr_oauth | Protects the sign-in handshake (holds the OAuth state/PKCE values between redirect and callback) | Strictly necessary; HttpOnly, Secure, SameSite=Lax | 10 minutes; deleted as soon as sign-in completes |
That’s it. We use no analytics, advertising, or cross-site tracking cookies, no third-party trackers, and no fingerprinting. Because both cookies are strictly necessary for the service to function, no cookie consent banner is required. If we ever add optional analytics, we will update this notice and ask for consent first.
If you top up credits, Stripe’s checkout pages (hosted by Stripe) set their own cookies for payment and fraud prevention, governed by Stripe’s privacy policy.