Cookies

Every cookie we set, what it does, and how long it lasts. If a cookie is not on this page, we do not set it.

Before you sign in, there are none

The public pages — everything you can read without an account, including this one and every status page — set no cookies at all unless you have allowed analytics. Not a session cookie, not a preference, nothing. Reject analytics and nothing is stored on your device by us.

That is unusual enough to be worth saying plainly, because most sites showing you a cookie banner have already set several before you answer it.

Strictly necessary

These are set only once you sign in or unlock a protected status page, and only because the thing you asked for cannot work without them. Under the ePrivacy rules they do not require consent, and there is no way to refuse them and still sign in.

NamePurposeLasts
better-auth.session_tokenKeeps you signed in. Without it every page would ask for your password again.30 days, or until you sign out
better-auth.session_dataA short-lived signed copy of your session, so each dashboard page does not need a database round trip to know who you are.5 minutes
better-auth.dont_rememberRecords that you asked not to be kept signed in.Until you close the browser
vsp_…Remembers that you entered the password for one specific status page. One cookie per page, so unlocking one does not unlock another.7 days

In production all of these are Secure and HttpOnly, which means they are sent only over HTTPS and cannot be read by scripts on the page.

Analytics — only if you say yes

On the public website we use Google Analytics to see which pages people find useful. It sets _ga and _ga_…, which last up to two years and distinguish one browser from another.

It does not run unless you allow it. Declining does not hide the data afterwards — the code is never loaded and the cookies are never set. It is absent from the dashboard entirely, and absent from status pages, so a status page you publish carries no tag of ours and your visitors are not measured by us.

at any time. Declining changes nothing about how the site works.

What we do not use

No advertising cookies, no retargeting pixels, no social plugins, no session recording or heat-mapping, and no cross-site tracking of any kind. We do not sell or share anything for advertising, and there is no third party building a profile of you through us.

One thing that is not a cookie

Your analytics choice is kept in your browser’s local storage, not in a cookie, under vitrina.consent.analytics. It is stored so we can stop asking, it never leaves your device, and remembering a refusal is the one thing we would still need to do even if you refuse everything else.

Managing them yourself

Every browser can show, block and delete cookies for a site, and blocking ours will sign you out rather than break anything permanently. If you would rather ask us something first, write to privacy@vitrinaengine.com.

The privacy policy covers what we do with personal data more broadly, and the sub-processor list names every company involved.

Last updated 31 August 2026.