Skip to content
EmbrolinkSign in

Embrolink Cookie Policy

Draft — lawyer review (needs user). Checked against the code on 2026-09-30: apps/api/src/core/auth.ts:13,145-150 (session cookie), apps/web/src/components/ui/sidebar.tsx:27-28,85 (sidebar cookie), apps/web/src/lib/api.ts:38-44 (el.factory), apps/web/src/components/providers.tsx:22 (next-themes, default key theme), apps/web/src/lib/session.tsx:74 (el.factory removed on sign-out), apps/web/next.config.ts:14-28 (Content-Security-Policy blocks every third-party script, font, image and connection). Re-check whenever a cookie or storage key is added; this page must list every one.

Version: 2026-10-01 · Applies to: the Embrolink website and web app ([WEBSITE URL]).

Short version

We use only what the website needs to work: one sign-in cookie, one layout cookie and two small settings saved in your browser. No analytics, no advertising, no tracking, no third-party scripts, so there is no cookie banner and nothing to opt out of.

What we use

NameTypeSet byWhat it doesHow longCategory
el_sessionCookie (HttpOnly, Secure, SameSite=Lax, first-party)Embrolink API, through our own domainKeeps you signed in. Holds a random token; we store only its hash30 days after your last visit, or until you sign outStrictly necessary
sidebar_stateCookie (first-party)Web appRemembers whether you opened or closed the side menu7 daysStrictly necessary (preference you set)
el.factoryBrowser local storageWeb appRemembers which factory you are working in, so lists show the right dataUntil you sign out or clear your browser dataStrictly necessary (preference you set)
themeBrowser local storageWeb app (next-themes)Remembers light, dark or system appearanceUntil you change it or clear your browser dataStrictly necessary (preference you set)

We do not use cookies or storage for advertising, analytics, profiling or cross-site tracking. Security against cross-site request forgery uses a request header, not a cookie.

Third parties

None. Every script, style, font and image is served from our own domain. Fonts (Public Sans and IBM Plex Mono) are downloaded once when we build the website and then served by us, so your browser never contacts Google Fonts or any other third party. Our Content-Security-Policy tells browsers to refuse any other source.

The mobile apps

The Android and iOS apps do not use cookies. They keep your session token in the phone's secure storage (Keychain or Keystore) and entries made offline in a local database until they are sent (Privacy Notice, A4).

Your choices

Because everything here is strictly necessary, there is nothing to switch off. You can delete cookies and site data in your browser settings at any time; you will then be signed out and the menu, factory and appearance choices return to their defaults.

Changes

If we ever want a non-essential cookie or third-party script, we will first ask for your consent with a banner where "Reject" is as easy as "Accept", nothing is pre-ticked, and your choice can be changed from the page footer. This page will list it before it is used.

Contact

[SUPPORT E-MAIL] · Grievance Officer: [GRIEVANCE OFFICER], [GRIEVANCE E-MAIL]