Skip to content
PeptideProof
Draft — this document has not yet been reviewed by qualified legal counsel and must not be relied upon. See docs/LEGAL_REVIEW_REQUIRED.md.

Cookies and local storage

Last updated 8 October 2026 · Effective [effective date] · All legal documents

PeptideProof uses only the cookies it needs to work. We do not use advertising, tracking or analytics cookies, and we store no identifier on your device for analytics. Because of that we do not show a cookie-consent banner; if that ever changes, we will ask for your consent first.

What we set

CookiePurposeLifetime
__Secure-authjs.session-tokenKeeps you signed in (strictly necessary)Up to 30 days
__Host-authjs.csrf-tokenProtects sign-in forms against forgery (strictly necessary)Session
__Secure-authjs.callback-urlReturns you to the page you were on after signing in (strictly necessary)Session

The __Secure- and __Host- prefixes mean the browser only accepts them over HTTPS.

What we do not do

  • No analytics or advertising cookies, and no third-party trackers or pixels.
  • Page views are counted on our server without storing anything on your device: we derive an anonymous hash from your IP address and browser, salted with a secret that changes every day, so it cannot be linked across days or reversed.

Third parties

If you subscribe or buy credits you are sent to Stripe’s checkout, which sets its own cookies under Stripe’s policy. The embeddable report widget sets no cookies and stores nothing on the page it is shown on.

See also the Privacy Policy.