Last updated: 26 June 2026
Spluur uses cookies only to keep you signed in and to protect the account-connection flows in the dashboard. We don't use cookies for advertising, and we don't load third-party tracking or analytics scripts that set cookies of their own.
access_token
Strictly necessaryAuthenticates your requests while you're signed in.
Expires after: 15 minutes
refresh_token
Strictly necessaryIssues a new access token without making you log in again.
Expires after: 7 days
github_oauth_state
Strictly necessaryPrevents cross-site request forgery during the GitHub connection flow. Only set while you're actively connecting a GitHub account.
Expires after: 10 minutes
All cookies we set are HttpOnly (inaccessible to JavaScript, including our own frontend code), transmitted only over HTTPS in production, and use the SameSite=Lax attribute to limit cross-site sending. None of them are readable or usable by any other website.
Every cookie we set is "strictly necessary" under data protection law — the site cannot function without them, since they're how you stay logged in. We don't set any cookie that requires opt-in consent, which is why you won't see a cookie banner on Spluur.
The dashboard also stores some non-sensitive UI state in your browser's local storage (such as your cart contents and a copy of your basic profile info for fast page loads). This isn't a cookie and isn't sent to our servers automatically — it stays on your device until you clear it or sign out.
If the cookies we use change, we'll update this page. Material changes will be communicated by email or an in-app notice.
See our full Privacy Policy for how we handle data more broadly, or email privacy@spluur.app.