Effective date: 14 August 2026
We use only strictly-necessary cookies — the small set required to run the Service and keep you signed in. Because we set no non-essential or advertising cookies, no cookie consent banner is needed.
Strictly necessary (set without consent — required to run the Service)
| Cookie | Purpose | Type | Retention |
|---|---|---|---|
auth_token | Keeps you logged in (signed session JWT) | httpOnly, SameSite=Lax | 7 days |
refresh_token | Silently renews your session | httpOnly, SameSite=Lax | 7 days |
session_id | Correlates your session | httpOnly | 7 days |
x-tier | Your plan tier, read at the edge for rate limiting | JS-readable | 7 days |
We also use localStorage for UI preferences (theme, tab state, draft inputs). These stay in your
browser and are not transmitted as cookies.
Diagnostics (no cookies)
We use Sentry for error and performance diagnostics. It does not set cookies, does not
record your session, and personal data is stripped before reports are sent (sendDefaultPii: false).
We do not use advertising cookies, Google Analytics, Meta Pixel, session replay, or similar
third-party trackers.
Note: Stripe Checkout may set its own cookies on Stripe's own pages during payment — those are governed by Stripe's own cookie and privacy notices, not by this policy.
Your choices
- Browser controls: you can block/delete cookies, but blocking strictly-necessary ones will break login.
- "Do Not Sell/Share" (US): we do not sell or share personal data via cookies; we honour Global Privacy Control signals where applicable.
Questions: privacy@opafex.com.