Cookie Policy

Version 1.1.0 · Effective 2026-07-06

What is a cookie?

A cookie is a small text file your browser stores at our request. We use them for three reasons: keeping you logged in, recording your preferences, and (with your consent) measuring how the app is used.

What we set today

Below is the complete list. If we add a cookie not on this list, we’ll update this page and, where required, ask for your consent.

Essential cookies

CookiePurposeDuration
a_session_abesoft-suiteAuthenticated session. Identifies the logged-in user across requests so the dashboard doesn't ask you to log in on every page load. HttpOnly + Secure + SameSite=Lax.30 days (or until logout)
oauth_stateCSRF token for the Google OAuth round-trip. The /api/auth/oauth/google/start route stores a random 32-char state here; the callback reads and compares it. HttpOnly + SameSite=Lax, 10-minute TTL, cleared on success or failure.10 minutes

Functional cookies

CookiePurposeDuration
signfile_consentRecords your cookie-consent choices (Accept all / Reject all / Manage preferences). Persists for 365 days. Strictly-necessary for storing your consent under ePrivacy Art. 5(5) — we do not ask for consent to set this cookie.365 days

Analytics cookies

CookiePurposeDuration
(gated by signfile_consent)When you grant 'Analytics & Error reporting' consent, our error reporter (Sentry) initializes in your browser and sends error envelopes (page URL, browser type, stack trace) to ingest.de.sentry.io. We do not set first-party analytics cookies today; future analytics tools (e.g. Plausible, PostHog) would land here and inherit the same gate.Until you withdraw consent

Marketing cookies

CookiePurposeDuration
(none today)We don't currently use marketing pixels or retargeting cookies. The 'Marketing' toggle in the preferences modal is a forward-looking gate: turning it on today doesn't change anything, but it will automatically activate any future marketing cookies we add (we'll update this policy first).

Browser storage (localStorage)

We also store a small amount of non-cookie client-side state in your browser’s localStorage. None of these items are sent off your device and they are not subject to GDPR cookie consent — but we disclose them for transparency.

KeyPurposeDuration
signfile-active-workspaceThe id of the workspace you're currently viewing. Read on every /api/* call by apiFetch() and attached as the X-Workspace-Id header. Without this, every page load would force a workspace picker.Persistent until logout
abesoft-active-workspaceLegacy key from the pre-rebrand app. No longer written — we clear it on logout and on a 403 from /api/me/dashboard — but older browsers may still have a residual value.Read-only / cleared on logout
signfile-welcome-banner-dismissedWhether you've dismissed the dashboard 'Welcome' banner. '1' = dismissed.Persistent
themeLight / dark / system preference (set by next-themes). Doesn't affect first-party cookies.1 year

What we don't set

We don’t set advertising cookies, third-party tracking pixels, or social-media retargeting cookies. We don’t sell or share cookie data with data brokers. Server-side error reporting (Sentry on our servers and edge functions) keeps running regardless of your cookie preference — only the browser-side SDK is gated.

Your choices

You can block non-essential cookies in your browser settings. The Essential cookies above are required for the app to function (you can’t log in without the session cookie), so blocking them will break the app.

For finer control, the cookie banner that appears on your first visit lets you Accept all, Reject all, or pick per-category. You can change your choice at any time using the “Manage cookie preferences” link in any page footer.

Questions

Cookie Policy — SignFile · SignFile