Cookie Policy

Last updated: [EFFECTIVE DATE]
Template only, not legal advice. Confirm this list matches the cookies your backend actually sets before publishing, and have it reviewed by a lawyer.

1. What cookies are

Cookies are small text files stored on your device. We use them strictly to operate the Service - primarily to keep you signed in securely.

2. Cookies we use

We use essential cookies only. We do not use advertising or third-party tracking cookies.

CookiePurposeType
founder_access_tokenAuthenticates your dashboard sessionEssential, HttpOnly, session/short-lived
founder_refresh_tokenRenews your session securely (token rotation)Essential, HttpOnly, longer-lived
user refresh tokenMaintains end-user sessions in your app via billtEssential, HttpOnly

These cookies are HttpOnly (not readable by JavaScript) and, in production, sent only over HTTPS (Secure). They are necessary for the Service to function.

3. Why we don't ask for consent banners

Strictly necessary cookies generally do not require prior consent under laws such as the ePrivacy Directive. Because we use only essential authentication cookies, no advertising or analytics consent banner is required. (If you later add analytics, update this section and add consent.)

4. Managing cookies

You can block or delete cookies in your browser settings, but the Service will not work correctly without the essential cookies above - you will not be able to stay signed in.

5. Third-party cookies

Sign-in via Google and payment via Stripe may set their own cookies on their domains during those flows, governed by their respective policies.

6. Contact

Questions about cookies: [CONTACT EMAIL].