Draft — to be reviewed by counsel before publication
Cookie policy
Draft for the marketing site and the dashboard of MB Tobuli. Contact [Contact email]. Company code [Company code]. Address [Registered address]. VAT [VAT number].
The API does not use a browser cookie. Callers send Authorization: Bearer. Do not describe the API key as a cookie.
Strictly necessary
These cookies run without a consent banner. They are required to serve a page or to keep a signed-in session.
- A load balancer or site proxy may set a cookie that only routes or secures the connection. The name is to confirm. Publish it only after counsel sees the live response headers.
Dashboard sign-in is implemented. These are the cookies that code sets.
st-sessionends the local session stand-in. The value0ishttpOnly,SameSite=Lax, andPath=/.Max-Ageis 400 days (60 * 60 * 24 * 400seconds). Starting the stand-in deletes the cookie. Production API authorization does not read it. It is not the sign-in session.st-envstores the Live or Test choice. It isPath=/,SameSite=Lax, andMax-Ageis 365 days (365 * 24 * 60 * 60seconds).st-themestores light or dark, and only after a theme is chosen. It uses the same path,SameSite, and lifetime asst-env. It is not measurement. The marketing site sets this same cookie.better-auth.session_tokenis the signed-in session. On HTTPS the name is__Secure-better-auth.session_tokenand the cookie isSecure. It ishttpOnly,SameSite=Lax, andPath=/.Max-Ageis 30 days (60 * 60 * 24 * 30seconds).better-auth.two_factorholds a signed identifier for a pending second-factor check. It uses the same attributes as the session cookie, including the__Secure-prefix on HTTPS.Max-Ageis 600 seconds. The check clears it.better-auth.stateholds signed OAuth state during GitHub or Google sign-in, when that provider is configured. It uses the same attributes as the session cookie.Max-Ageis 300 seconds.better-auth.better-auth-passkeyholds a signed token for a pending passkey registration or sign-in. The passkey plugin names itbetter-auth-passkey, and thebetter-auth.prefix is added in front. It uses the same attributes as the session cookie, including the__Secure-prefix on HTTPS.Max-Ageis 300 seconds. Verification does not delete it.
The sign-in bot check, when configured, loads a Cloudflare Turnstile challenge from challenges.cloudflare.com. The Turnstile Privacy Addendum (accessed 2026-10-07) does not name a cookie for that challenge. It directs readers to Cloudflare's cookie policy and the Turnstile developer docs. This draft does not claim that the challenge sets or omits a cookie.
This list does not include better-auth.session_data, better-auth.account_data, or better-auth.dont_remember. Cookie cache and account-cookie storage are off, and sign-in does not ask to skip remembering the session. better-auth.trust_device has a max age of 0, so it does not persist. st-invite and st-return are not set on main. The dashboard reads st-tenant and does not set it. st-mock and st-live-script are not set by the dashboard. st-mock-session is set only while the API mock is on, with no Max-Age, Path=/, and SameSite=Lax.
- The consent choice is a strictly necessary cookie. It records version, the
analyticschoice, theadschoice, and an ISO UTC timestamp. It usesPath=/,SameSite=Lax, andSecureon HTTPS. It lasts six calendar months. When a parent cookie domain is configured, the dashboard can read it. Do not reuse that cookie as an analytics identifier. The implemented name is in Current site storage below.
Do not place analytics or advertising in this category.
Consent categories
The banner offers two optional categories. Use these ids in the product and in this policy:
analyticsadvertising
Both stay off until the visitor opts in. The first layer has equally sized Reject all and Accept all actions. Customize opens the category choices, unchecked on the first visit. The primary button then reads Save choices. A reject control is as available as an accept control. Counsel reviews whether those labels are sufficient. Do not load the tags for a category the visitor has not accepted. Do not treat a closed banner as a yes. Escape on a reopened panel closes it and does not record a choice.
What each category does
analytics loads Google Analytics on the public marketing and documentation pages, and only when a measurement id is configured and the visitor has opted in. It grants analytics_storage. It does not grant advertising storage. Cloudflare Web Analytics, when a beacon token is configured, is cookieless and does not use this grant. See Subprocessors and ADR-0021 (docs/adr/0021-analytics-and-consent.md).
advertising loads Google advertising measurement on the public marketing and documentation pages, and only when an ads id is configured and the visitor has opted in. It grants ad_storage, ad_user_data, and ad_personalization. The site does not serve ads. The measured action is the start of signup, and only when a signup label is also configured. Do not use this category on the dashboard or on the API host.
The dashboard and the API host do not load analytics or advertising.
How to change the choice
Cookie settings in the marketing footer or documentation sidebar reopens the banner. The visitor can turn analytics or advertising off. Turning a category off stops later loads, removes the cookies this site can access for that category, and reloads the page so a tag that already started stops. It does not delete data already sent to Google. That deletion path is to confirm by counsel.
How long
The consent cookie lasts six calendar months from the choice timestamp. The theme preference lasts one year and is stored only after the visitor chooses a theme. It is not measurement. The signed-in dashboard session lasts 30 days. Other dashboard cookie lifetimes are in the list above. Do not publish a Google cookie duration until it is read from the live Set-Cookie header. The implemented names are in Current site storage below.
Current site storage
This inventory describes the implemented site behavior. The draft policy above still needs counsel review.
We remember your cookie choices and theme. Google tags load only after you grant a category. Use Cookie settings in the footer to change or withdraw your choice.
Strictly necessary
st_consent: your Analytics and Advertising choices, version and timestamp. Expires after six months and can be shared with the dashboard on our configured cookie domain.
Preferences
st-themecookie: your marketing theme preference, stored only after you choose a theme so later pages can paint it. Expires after one year. It is not used for measurement.st-themein localStorage: your documentation theme preference, retained until you clear site storage. It is not used for measurement.
Analytics (optional)
_ga,_ga_*,_gid,_gatand_gat_*: Google Analytics visit measurement, only after Analytics consent.st_attributionin session storage: utm_source, utm_medium, utm_campaign, utm_term, utm_content and gclid, only after Analytics consent. App signup links carry these values after consent.
Advertising (optional)
_gcl_*and_gac_*(including_gac_gb_*): Google Ads conversion and linked campaign cookies, only after Advertising consent. The site measures the beginning of signup; account creation and email sending are separate future conversions.
When configured, Cloudflare Web Analytics measures visits without cookies. Google tags are omitted when their environment IDs are empty. Withdrawing Analytics consent removes the measurement cookies this site can access and clears attribution storage. Withdrawing Advertising consent removes the advertising cookies this site can access. Withdrawing either category reloads the page to stop its tags.