Cookie Policy
Version 2026-07-cookies-1 · Effective 2026-07-26
The cookies Clause50 sets today (strictly necessary only), and when this changes.
What we set today
Clause50 sets only strictly necessary cookies — the ones needed to keep you signed in and to protect the sign-in flow. We do not set any analytics, tracking, or advertising cookie.
| Cookie | Purpose | Type | Duration |
|---|---|---|---|
| Auth.js session cookie | Keeps you signed in between requests | Strictly necessary | Until sign-out or expiry |
| Auth.js CSRF cookie | Protects sign-in and account actions against cross-site request forgery | Strictly necessary | Session |
| cc_consent | Remembers your cookie-banner choice (accepted/rejected) so you aren't asked again | Strictly necessary | 1 year |
Not a cookie: theme preference
Whether you see a light or dark interface is remembered in your browser's localStorage, not a cookie. It is never sent to our servers and involves no tracking.
A consent banner, and why it ships even though nothing non-essential loads yet
Under the ePrivacy rules, a consent banner is required for non-essential cookies, not for cookies that are strictly necessary to provide a service you requested. Every row above is strictly necessary — we still don't set an analytics, marketing, or third-party tracking cookie.
Paid checkout takes you to Polar, our payment processor, on Polar's own domain — it does not embed a script or set a cookie on clause50.com. So, strictly, nothing non-essential currently loads here. We ship the consent banner anyway, now, rather than waiting: it gives you the choice up front and means that if we ever do add something non-essential (an embedded widget, analytics), rejecting means nothing loads — the gate already exists rather than being promised for later. Your choice is recorded so we can show we asked.