Cookie Policy
Harry The Marketer · Last updated 6 August 2026
What we set
| Name | Purpose | Type | Lifetime |
|---|---|---|---|
htm_session |
Keeps you signed in to your workspace. Contains a signed reference to your user record — no personal data in the value itself. | Strictly necessary, first-party, HTTP-only, SameSite=Lax, Secure in production |
7 days, or until you sign out |
What we do not set
- No advertising or retargeting cookies
- No third-party analytics, heatmap, or session-recording cookies
- No cross-site tracking of any kind
Because the only cookie is strictly necessary for a service you asked for, no consent banner is required under the ePrivacy rules — so we do not show one.
Third parties during sign-in
If your deployment uses Auth0, signing in redirects you to Auth0, which sets its own cookies on its own domain under its own policy. Connecting Gmail redirects you to Google, likewise. Neither sets cookies on our domain.
Email tracking
Emails sent by campaigns can include an open pixel and signed click-through links. These do not use cookies; they record that a specific message was opened or clicked so the sending workspace can measure its campaign. Recipients can stop all of it with the unsubscribe link in any message.
Controlling cookies
You can clear or block cookies in your browser, but blocking htm_session will prevent you from
staying signed in.