← All legal documents

Cookie Policy

Effective date: 28 April 2026 · Last updated: 1 August 2026

This Cookie Policy explains how PostThing uses cookies and similar technologies on post-thing.com. It complements the Privacy Policy.

1. What cookies are

A cookie is a small text file that a website asks your browser to store. Cookies let a site recognize your browser between requests — for example, to keep you signed in. Some related technologies (local storage, session storage, IndexedDB) work the same way conceptually; we treat them as "cookies" for the purpose of this policy.

2. The cookies PostThing sets

PostThing currently sets only strictly necessary cookies — the ones we need to sign you in and keep your session safe. We do not use analytics, advertising, or tracking cookies.

| Name | Set by | Purpose | Type | Lifetime | |---|---|---|---|---| | authjs.session-token (or __Secure-authjs.session-token over HTTPS) | PostThing (Auth.js) | Identifies your signed-in session | Strictly necessary | Until you sign out or the session expires (≈ 30 days of inactivity) | | authjs.csrf-token (or __Host-authjs.csrf-token) | PostThing (Auth.js) | Protects sign-in and OAuth flows from cross-site request forgery | Strictly necessary | Session | | authjs.callback-url (or __Secure-authjs.callback-url over HTTPS) | PostThing (Auth.js) | Remembers where to send you after sign-in | Strictly necessary | Session |

We do not currently use browser local storage. Your active-workspace selection is stored in your account record on our servers and is covered by the Privacy Policy.

If we ever introduce non-essential cookies (for example, product analytics) we will first show a consent banner and we will not set those cookies until you opt in.

3. Third-party cookies

We do not set third-party advertising or analytics cookies. The third parties we use to deliver the Service (such as Resend for sign-in emails, or Cloudflare for object storage) may set their own cookies on their own domains when you interact with them — those cookies are governed by those companies' policies, not by us.

4. How to control cookies

Because the cookies above are strictly necessary for sign-in, blocking them will sign you out and stop the Service from working for you. Beyond that, you can:

  • delete cookies in your browser's settings ("Clear browsing data" or equivalent);
  • block cookies for specific sites in your browser's privacy settings;
  • use private / incognito mode, which discards cookies when the window closes.

Help pages for the major browsers:

5. Changes

If we add or change cookies in a way that affects your privacy choices, we will update this page and — for non-essential cookies — show you a consent prompt before they are set.


Questions: privacy@post-thing.com.