Legal

Cookie Policy

A current inventory of Monocrawl cookies and browser storage — no hypothetical trackers.

Effective

1 September 2026

Version

2026-09-01

Non-essential analytics

Not enabled
01

What this covers

Cookies are small values stored by a browser. Local storage and session storage are similar browser technologies. UK privacy rules apply to storing or reading them even when the value is not personal information.

Monocrawl currently uses storage needed to authenticate and secure accounts, retain a requested interface preference, complete a referral workflow and keep browser-local working history. We do not currently use advertising, cross-site tracking or product-analytics cookies.

02

Current inventory

  • `better-auth.session_token` (or the secure production-prefixed equivalent): signed, HTTP-only authentication cookie used to maintain the account session. The configured session lifetime is seven days and revocation can end it earlier.
  • `better-auth.two_factor` / secure-prefixed equivalent: short-lived authentication state used only while completing a two-factor challenge.
  • `sidebar_state`: first-party interface preference recording whether the dashboard sidebar is open. Maximum age seven days.
  • `mn_ref` in local storage: referral code captured when a visitor follows a referral link. It is removed after a successful account flow uses it; a visitor can clear it sooner.
  • `mn_explorer_recent` in local storage: a browser-local ring buffer of recent Explorer runs. It remains until cleared in Explorer or browser settings and is not a server account history.
  • `sf_new_key` in session storage: temporarily carries a newly issued plaintext API key between dashboard screens so it can be shown once. It is removed after display and normally disappears when the tab session ends.

Authentication and two-factor storage is strictly necessary for the signed-in service. The sidebar value implements the preference requested by the user. Referral and Explorer storage support the workflow described above; they are not used for behavioural advertising.

03

Stripe and sign-in providers

Stripe-hosted Checkout and billing pages may set Stripe cookies or similar storage for payment security, fraud prevention, session continuity and regulatory requirements. Those values are controlled by Stripe on its domain; see Stripe’s own privacy and cookie information.

If you choose Google or GitHub sign-in, that provider may use its own cookies on its domain to authenticate you and return the authorised result. Monocrawl does not make those optional providers load merely because you visit a public page.

04

Your choices

You can clear local or session storage and block cookies in browser settings. Blocking authentication cookies prevents sign-in; clearing Explorer or referral storage removes that local history or attribution. The dashboard provides a direct control to clear recent Explorer history.

Because Monocrawl does not currently set non-essential analytics or advertising cookies, there is no cosmetic consent banner. If we introduce storage that needs consent, it will not be set until an appropriate affirmative choice is obtained.

05

Changes and contact

We audit this inventory when authentication, analytics, checkout or browser workflows change. The version and effective date above identify the current inventory.

Questions or objections can be recorded using the privacy category at Contact. See the Privacy Notice for personal-information rights.

Cookie names may gain a standard __Secure- prefix in production without changing their function.