Cookie Policy

Last updated: 26 June 2026

1. Our approach to cookies

Spluur uses cookies only to keep you signed in and to protect the account-connection flows in the dashboard. We don't use cookies for advertising, and we don't load third-party tracking or analytics scripts that set cookies of their own.

2. Cookies we set

access_token

Strictly necessary

Authenticates your requests while you're signed in.

Expires after: 15 minutes

refresh_token

Strictly necessary

Issues a new access token without making you log in again.

Expires after: 7 days

github_oauth_state

Strictly necessary

Prevents cross-site request forgery during the GitHub connection flow. Only set while you're actively connecting a GitHub account.

Expires after: 10 minutes

3. How these cookies are protected

All cookies we set are HttpOnly (inaccessible to JavaScript, including our own frontend code), transmitted only over HTTPS in production, and use the SameSite=Lax attribute to limit cross-site sending. None of them are readable or usable by any other website.

4. Strictly necessary, no consent banner

Every cookie we set is "strictly necessary" under data protection law — the site cannot function without them, since they're how you stay logged in. We don't set any cookie that requires opt-in consent, which is why you won't see a cookie banner on Spluur.

5. Local storage

The dashboard also stores some non-sensitive UI state in your browser's local storage (such as your cart contents and a copy of your basic profile info for fast page loads). This isn't a cookie and isn't sent to our servers automatically — it stays on your device until you clear it or sign out.

6. Changes to this policy

If the cookies we use change, we'll update this page. Material changes will be communicated by email or an in-app notice.

7. Questions

See our full Privacy Policy for how we handle data more broadly, or email privacy@spluur.app.