Last updated: 17 August 2026
| Name / type | Purpose | Duration | Category |
|---|---|---|---|
| Authentication token (local storage, set by Supabase) | Keeps you signed in and authorizes API requests | Until sign-out / expiry | Strictly necessary |
| UI preferences (local storage) | Remembers table column layout and similar settings | Persistent until cleared | Functional (essential to the feature you chose) |
| Cookie choice (local storage) | Remembers whether you accepted or rejected analytics, so we do not ask again on every page | Persistent until cleared | Strictly necessary (records your choice) |
| Analytics cookie and local storage (first-party, set by HeyCatch) | Measures which pages and features are used, and — once you are signed in — ties that to your account | Up to 12 months | Optional — set only after you click Accept |
Use the Cookie settings link in the footer of any page to accept or reject analytics at any time. Withdrawing consent deletes the analytics cookie and stops all further collection — in your browser and on our servers, including account events such as a subscription change or a credit purchase. It does not affect your account or any data you have already saved.
You can also clear cookies and local storage through your browser settings. Note that removing the authentication token will sign you out, and the app will not function while signed out. Clearing storage also clears your recorded cookie choice, so you will be asked again on your next visit.
Some subprocessors (e.g. Stripe for checkout) may set their own strictly necessary cookies on their own pages when you interact with them. Their cookie practices are governed by their policies. Our full subprocessor list, including HeyCatch, is in the DPA.