Skip to content
C50 Clause50EU AI Act transparency — made auditable.EU AI Act evidence, made auditable
Legal

Cookie Policy

Version 2026-07-cookies-1 · Effective 2026-07-26

The cookies Clause50 sets today (strictly necessary only), and when this changes.

What we set today

Clause50 sets only strictly necessary cookies — the ones needed to keep you signed in and to protect the sign-in flow. We do not set any analytics, tracking, or advertising cookie.

CookiePurposeTypeDuration
Auth.js session cookieKeeps you signed in between requestsStrictly necessaryUntil sign-out or expiry
Auth.js CSRF cookieProtects sign-in and account actions against cross-site request forgeryStrictly necessarySession
cc_consentRemembers your cookie-banner choice (accepted/rejected) so you aren't asked againStrictly necessary1 year

Not a cookie: theme preference

Whether you see a light or dark interface is remembered in your browser's localStorage, not a cookie. It is never sent to our servers and involves no tracking.

A consent banner, and why it ships even though nothing non-essential loads yet

Under the ePrivacy rules, a consent banner is required for non-essential cookies, not for cookies that are strictly necessary to provide a service you requested. Every row above is strictly necessary — we still don't set an analytics, marketing, or third-party tracking cookie.

Paid checkout takes you to Polar, our payment processor, on Polar's own domain — it does not embed a script or set a cookie on clause50.com. So, strictly, nothing non-essential currently loads here. We ship the consent banner anyway, now, rather than waiting: it gives you the choice up front and means that if we ever do add something non-essential (an embedded widget, analytics), rejecting means nothing loads — the gate already exists rather than being promised for later. Your choice is recorded so we can show we asked.