Legal
Cookie Policy
Last updated: Draft
Draft for review. A plain-language starting point, not legal advice. Have it reviewed by counsel and fill in your company/entity name, address, and governing-law jurisdiction before you go live.
Short version: Pragor sets one strictly-necessary cookie to keep you signed in, and uses cookieless, privacy-first analytics. We use no advertising, marketing or cross-site tracking cookies — so under the ePrivacy Directive no consent banner is required. If that ever changes, we'll ask for your consent first.
The only cookie we set
`pragor_session` — *strictly necessary*. Keeps you signed in and protects forms against CSRF. Flags: `HttpOnly`, `SameSite=Lax`, `Secure` (over HTTPS). Session-scoped — it expires when you sign out or after inactivity. No consent is required for it (ePrivacy Art. 5(3) exemption for cookies strictly necessary to deliver the service you asked for).
Analytics — cookieless by design
We run Plausible Analytics, self-hosted. It is cookieless and GDPR / ePrivacy / CCPA compliant: it sets no cookies, stores nothing on your device, collects no personal data, and never tracks you across sites or over time. Because it is cookieless and processes no personal data, it runs without a consent banner — that is deliberate and lawful.
What we do NOT use
No advertising cookies, no social-media pixels, no cross-site trackers, no device fingerprinting, no data brokers.
Local storage (not a cookie)
We remember your light/dark theme in your browser's local storage purely to honour your preference — it never leaves your device and is not a cookie.
Your controls
Sign out to clear the session cookie, or block/clear cookies in your browser (the app then can't keep you signed in). Nothing else to opt out of, because there is nothing non-essential to opt out of.
If this changes
Before introducing any non-essential cookie we will add a proper opt-in consent mechanism and update this page first.