Legal
Cookie Policy
Last updated 15 August 2026
We set three cookies, and all three exist to sign you in and keep you signed in.
There is no analytics, no advertising and no third-party tracking on this site — which is why you have not been asked to accept anything.
What a cookie is here
A small piece of text your browser stores for a site and sends back on the next request. Ours are used only to know that the browser asking for your dashboard is the one that signed in.
The cookies we set
pkce_verifier
Written when you start signing in and deleted the moment you finish. It is what stops someone intercepting your sign-in from completing it themselves. Lives for a few minutes at most.
access_token
Proves to the site that you are signed in. Expires when the session does, typically within the hour.
refresh_token
Lets your session continue without signing in again. Expires after 30 days.
All three are marked HttpOnly, so no script on the page can read them; Secure, so they are only ever sent over HTTPS; and SameSite=Lax, so another site cannot cause your browser to send them.
What we do not set
No analytics cookies. No advertising or retargeting pixels. No social media trackers. No third-party scripts of any kind — the marketing site ships no client-side JavaScript at all.
This is also why there is no cookie banner. Cookies that are strictly necessary to provide a service you asked for do not require consent, and we do not set any others. If that ever changes, we will ask.
Turning them off
You can block or delete cookies in your browser settings. Blocking these three means you cannot sign in, because there is no other way for the site to know the request is yours. The rest of the site — this page included — works without them.
The mobile app
The Notiza app does not use cookies. It stores your session securely on the device instead, and clears it when you sign out.
