Cookie Policy
Every cookie we set is listed below. There are 6, all of them either strictly necessary or functional. We set no advertising or tracking cookies at all.
Last updated 16 August 2026
Your choice
Under the ePrivacy rules, consent is required for anything stored on your device that isn't strictly necessary for a service you asked for. Strictly necessary is a narrow test, and the two functional cookies below don't meet it (the service works fine without them) so we ask.
Nothing in the functional category is written before you say yes. Refusing is one click, exactly like accepting, and if you later withdraw consent we delete those cookies and the matching browser storage rather than just noting your preference.
to change your answer at any time. We re-ask every six months, and immediately if we ever add a new category.
In plain English: We ask permission for two things: your timezone and interface preferences, and anonymous visit counts. There is no advertising here to consent to, and nothing goes to a third party.
Strictly necessary cookies
These make signing in work. Without them you cannot use the dashboard. They are all HttpOnly, so JavaScript cannot read them, and they are marked Secure over HTTPS.
| Cookie | Purpose | Expires |
|---|---|---|
| authjs.session-token__Secure-authjs.session-token over HTTPS | Keeps you signed in to the dashboard | 30 days |
| authjs.csrf-token | Protects sign-in and form submissions against cross-site request forgery | Session |
| authjs.callback-url | Remembers where to send you back to after signing in | Session |
| ff_consent | Remembers your cookie choice, so we do not ask again. Storing a consent decision is itself exempt from consent | 6 months |
Functional cookies
These remember a preference so the interface behaves the way you asked. They hold no identifier and are not shared with anyone.
| Cookie | Purpose | Expires |
|---|---|---|
| ff_tz | Your IANA timezone, so dates render in your local time on the server without a flash of the wrong time | 1 year |
| ff_tzmode | On a public project page, whether you chose to see times in your own timezone or the project's | 1 year |
The timezone cookie exists so a date can be rendered on the server in your own timezone. Without it you would briefly see the wrong time before the page corrected itself.
Browser storage
Not a cookie, but worth listing: we keep a few values in your browser's local storage. They never leave your device and are not sent with requests.
| Key | Purpose | Where |
|---|---|---|
| _beacon_vid | A random visitor id for Repora, our self-hosted analytics, so repeat visits count as one person. Written only if you accept analytics, and deleted the moment you withdraw it | Analytics software |
| feedfast:sidebar-collapsed | Whether you collapsed the dashboard sidebar | Dashboard |
| feedfast:voter-email | An email address you typed on a public feedback board, so your votes follow you and you don't retype it | Public project pages and the embedded widget |
| feedfast:seen:{project} | The last changelog entry you opened in the embedded widget, so the unread dot can clear | Embedded widget on a customer's site |
The embedded widget
When a customer embeds our widget on their own site, it sets no cookies. It loads one script and fetches one public JSON document, and uses local storage only to remember which changelog entry you last opened, so the unread dot can clear.
Requests from the widget carry no cookies at all. They are sent with credentials omitted, so nothing identifying travels with them unless you submit feedback.
Third-party cookies
We set none. The only script loaded from another domain is our own analytics on repora.ro: a different hostname, but our server and our data, with no third party involved. Two further exceptions, both of which only happen because you chose them by clicking something:
- Signing in with Google or GitHub sends you to their domain, where their own cookies and privacy policy apply. When you return, only our session cookie is set.
- Upgrading to Pro sends you to Creem.io's hosted checkout, where their cookies apply. Your card details never touch our servers.
Managing cookies
You can clear or block cookies in your browser settings. Blocking the strictly necessary ones will stop you signing in. Blocking or clearing the functional ones simply resets the preference: times fall back to the project's timezone, and the widget forgets what you have read.
Because we set no tracking cookies, browser “do not track” and global privacy control signals do not change what we do. There is nothing to turn off.
Withdrawing consent removes the functional cookies and the browser storage listed above straight away, in the same click.
Analytics
We count visits with Repora, which we host ourselves at repora.ro. It sets no cookies. It does keep one value in your browser's localStorage: _beacon_vid, a random id so that three visits from you are not counted as three people.
Analytics is the one thing here that runs before you answer the banner. The script loads on your first page, and keeps loading until you decline. Everything else (remembering your timezone, your sidebar, the email you voted with) waits for you to say yes.
Declining is absolute rather than cosmetic. The script stops loading, and _beacon_vid is deleted from your browser, so a later change of mind starts a new identity instead of resuming the old one. You can decline at any time from , and nothing gathered before then is tied to you by name.
It records which pages are viewed, where you arrived from, coarse browser and device information, and a small set of product events such as creating a project or publishing an entry. If you are signed in it also records your account's internal id, so a payment can be credited to the visit that led to it. That id is an opaque database key. Never your email or your name.
Public project pages carry no analytics at all. Those pages belong to our customers, and their visitors are not ours to measure.
Changes
If we add a cookie, it will appear in the tables above before it ships, and the date at the top will change. Adding a new category resets everyone's answer so you are asked again, rather than an old yes being stretched to cover something you never agreed to. That has happened once: analytics was added in August 2026, and every previous answer was discarded and re-asked rather than assumed.
Questions: [email protected]. See also the Privacy Policy.