Cookies policy.
The full list of cookies we set in your browser, what each one is for, how long it lasts, and what we do not do.
Effective June 8, 2026
Effective date: June 8, 2026. Last reviewed: June 14, 2026.
What we use cookies for
CohortLedger uses cookies only for authentication, security, and UI preferences. We do not use behavioral advertising cookies, we do not allow third-party advertising networks to track you through CohortLedger, and we do not currently use a third-party analytics vendor. If we begin using analytics, we will name the vendor in this policy and in our subprocessor list before any data flows to it.
The cookies we set
| Name | Provider | Purpose | Duration | Type | Attributes |
|---|---|---|---|---|---|
| sb-access-token | CohortLedger (Supabase Auth) | Keeps the operator signed in to the dashboard. Contains a short-lived bearer token. | 1 hour, rotated on use | Strictly necessary | HttpOnly, Secure, SameSite=Lax |
| sb-refresh-token | CohortLedger (Supabase Auth) | Issues new access tokens so the operator does not have to sign in every hour. | 30 days | Strictly necessary | HttpOnly, Secure, SameSite=Lax |
| cl_csrf | CohortLedger | Cross-site request forgery protection on form submissions and Server Actions. | Browser session | Strictly necessary | HttpOnly, Secure, SameSite=Strict |
| cl_prefs | CohortLedger | Remembers small UI choices, such as the active dashboard view or the monthly versus annual pricing toggle. Optional and never tied to your identity. | 1 year | Functional | Secure, SameSite=Lax |
What we do not use
- No third-party advertising trackers.
- No retargeting pixels.
- No social-network share trackers loaded by default.
- No browser fingerprinting libraries.
- No cross-context behavioral advertising as defined by California law.
Global Privacy Control (GPC)
We honor valid Global Privacy Control (GPC) signals as an opt-out request under California Civil Code § 1798.135(b). Because CohortLedger does not sell or share personal information for advertising and does not run cross-context behavioral advertising, receipt of a GPC signal does not change our data practices: we already do not engage in the practices the signal asks businesses to suppress. The signal is recorded in our logs and acknowledged.
How to manage cookies
Most browsers let you block or clear cookies. Blocking the strictly necessary cookies above will sign you out and may prevent the dashboard from loading. You can clear the functional cookie at any time without losing access to the service; the dashboard will revert to default UI choices.
If we add an analytics cookie in the future, we will provide a self-service opt-out in the dashboard Settings → Privacy screen and update this policy on the same day the cookie ships.
EU and UK visitors
CohortLedger is a US-only service. We do not market the service to individuals outside the United States and do not target EU or UK residents. EU and UK visitors who reach this site receive only the strictly-necessary cookies listed above; we do not load analytics or marketing cookies regardless of consent state.
Contact
Questions about this policy go to privacy@cohortledger.com or Privacy & Data Protection, Ravencord Inc., 6688 Nolensville Rd, Ste 108 #2225, Brentwood, TN 37027, United States.
