Legal

Cookie Policy

Every cookie we set, what it does and how long it lasts. There are five, all of them needed to make the product work — no advertising or analytics trackers.

Last updated 29 July 2026. English is the authoritative version of this document.

2. Cookies we set

CookiePurposeTypeLifetime
__Secure-authjs.session-tokenKeeps you signed in. Scoped to our parent domain so one login also works on your workspace's public board subdomain. HttpOnly, so JavaScript cannot read it.Strictly necessary8 hours
authjs.csrf-tokenProtects sign-in and sign-out requests against cross-site request forgery.Strictly necessarySession
authjs.callback-urlRemembers which page to return you to after signing in.Strictly necessarySession
i18nextRemembers the language you picked so pages render in it on the server as well as the client.Functional1 year
fb_guest_idA random identifier for visitors without an account. Gives your posts and comments one consistent pseudonymous identity on a board, and limits votes to one per browser per post. Contains no personal data.Strictly necessary1 year

In development the session cookie is named authjs.session-token without the __Secure- prefix, because that prefix requires HTTPS.

3. Third-party cookies

  • Paddle— our payment provider and Merchant of Record. When you check out or open the billing portal, Paddle processes the payment and may set cookies for payment processing and fraud prevention. Those are governed by Paddle’s privacy notice, not ours.
  • Cloudflare — our domains are served through Cloudflare, which may set a bot-management cookie (for example __cf_bm) to distinguish humans from automated traffic. It is used for security, not tracking or advertising.

We embed no social widgets, advertising pixels or session-recording scripts, so no cookies are set by those.

4. Similar technologies

Alongside cookies we store a small amount of data in your browser’s localStorage — for example whether you have already voted on a post, so the button shows the right state immediately. It stays on your device, is not sent to us as a cookie, and clearing site data removes it.

5. Managing cookies

  • You can delete or block cookies in your browser settings, or clear site data for our domain.
  • Blocking the session cookie will sign you out and prevent you from signing in — it is the mechanism that keeps you authenticated.
  • Blocking the language cookie means pages fall back to English.
  • Blocking the visitor cookie means your submissions will not share one identity and vote limits will apply per visit rather than per browser.

6. More information

How we handle the personal data behind these cookies — including your rights and how long we keep session and log records — is set out in the Privacy Policy. Questions about this page can go to privacy@feedboardapp.com.

Questions

Email support@feedboardapp.com for general questions, or privacy@feedboardapp.com for anything about your personal data.