Cookie policy
This is the whole inventory. There is no banner because nothing here needs consent.
- eu_session
- Set when you sign in. Identifies your session on our server. HttpOnly, Secure, SameSite=Lax. Expires after 30 days without activity, or when you sign out.
- eu_google_oauth
- Set only while you sign in with Google, to protect the flow against forgery. Expires after 10 minutes.
- eu_google_pending
- Set only between finishing Google sign-in and choosing a role on first login. Expires after 10 minutes.
- eu_view_as
- Set only for administrators using the read-only “view as” tool. Expires after 30 minutes.
What we do not do
No advertising cookies, no cross-site tracking, no third-party cookies. Public-page analytics run through Tusua without cookies or fingerprinting: the only identifier is a hash of your IP address and browser with a salt that rotates, which cannot be reversed. Stripe's checkout and onboarding pages are Stripe's own sites and follow their cookie policy.
Browser storage
We do not use local storage for tracking. Draft reports are saved on our server, not in your browser.