Embrolink Cookie Policy
Draft — lawyer review (needs user). Checked against the code on 2026-09-30:
apps/api/src/core/auth.ts:13,145-150(session cookie),apps/web/src/components/ui/sidebar.tsx:27-28,85(sidebar cookie),apps/web/src/lib/api.ts:38-44(el.factory),apps/web/src/components/providers.tsx:22(next-themes, default keytheme),apps/web/src/lib/session.tsx:74(el.factoryremoved on sign-out),apps/web/next.config.ts:14-28(Content-Security-Policy blocks every third-party script, font, image and connection). Re-check whenever a cookie or storage key is added; this page must list every one.
Version: 2026-10-01 · Applies to: the Embrolink website and web app ([WEBSITE URL]).
Short version
We use only what the website needs to work: one sign-in cookie, one layout cookie and two small settings saved in your browser. No analytics, no advertising, no tracking, no third-party scripts, so there is no cookie banner and nothing to opt out of.
What we use
| Name | Type | Set by | What it does | How long | Category |
|---|---|---|---|---|---|
el_session | Cookie (HttpOnly, Secure, SameSite=Lax, first-party) | Embrolink API, through our own domain | Keeps you signed in. Holds a random token; we store only its hash | 30 days after your last visit, or until you sign out | Strictly necessary |
sidebar_state | Cookie (first-party) | Web app | Remembers whether you opened or closed the side menu | 7 days | Strictly necessary (preference you set) |
el.factory | Browser local storage | Web app | Remembers which factory you are working in, so lists show the right data | Until you sign out or clear your browser data | Strictly necessary (preference you set) |
theme | Browser local storage | Web app (next-themes) | Remembers light, dark or system appearance | Until you change it or clear your browser data | Strictly necessary (preference you set) |
We do not use cookies or storage for advertising, analytics, profiling or cross-site tracking. Security against cross-site request forgery uses a request header, not a cookie.
Third parties
None. Every script, style, font and image is served from our own domain. Fonts (Public Sans and IBM Plex Mono) are downloaded once when we build the website and then served by us, so your browser never contacts Google Fonts or any other third party. Our Content-Security-Policy tells browsers to refuse any other source.
The mobile apps
The Android and iOS apps do not use cookies. They keep your session token in the phone's secure storage (Keychain or Keystore) and entries made offline in a local database until they are sent (Privacy Notice, A4).
Your choices
Because everything here is strictly necessary, there is nothing to switch off. You can delete cookies and site data in your browser settings at any time; you will then be signed out and the menu, factory and appearance choices return to their defaults.
Changes
If we ever want a non-essential cookie or third-party script, we will first ask for your consent with a banner where "Reject" is as easy as "Accept", nothing is pre-ticked, and your choice can be changed from the page footer. This page will list it before it is used.
Contact
[SUPPORT E-MAIL] · Grievance Officer: [GRIEVANCE OFFICER], [GRIEVANCE E-MAIL]