Skip to content

Cookies

Only what is needed to sign you in, and a short list of conveniences kept in your own browser. Nothing that follows you around, and no banner asking permission for cookies that do not exist.

Version 2.0Last updated 26 September 2026

01What this policy covers

This policy lists every cookie and piece of browser storage that veilux.io and the Veilux product actually set, what each one is for, how long it lasts, and how to control it. It is deliberately specific rather than a generic list of cookie categories that might apply to a website in general — if something is not listed here, we do not set it.

This is a policy about the mechanism, not about who controls the data inside it: the session cookie identifies your sign-in the same way whether you are staff at a subscribing firm or one of that firm’s own customers using the client portal.

02Strictly necessary cookies

These two cookies are set only when you sign in, and only they. Both are strictly necessary for the "PECR exemption" that applies to cookies without which the service you asked for — being signed in — cannot be provided; no consent banner is required for them, and none is shown.

Strictly necessary cookies
NamePurposeDurationType
next-auth.session-token (__Secure- prefixed on https)Keeps you signed in between requests. Contains an encrypted, signed token identifying your session; carries no readable personal data.Up to 7 days, or until you sign outHTTP-only, first-party
next-auth.csrf-token (__Host- prefixed on https)Set by our sign-in framework to prove a sign-in request came from our own form, not another site. Never read by page scripts.Session (deleted when you close your browser)HTTP-only, first-party

03What we keep in your browser’s own storage

A handful of conveniences are kept in your browser’s local storage rather than a cookie — they are never sent to our servers, never leave your device, and are not used to identify you across sessions or sites. Clearing your browser’s site data removes them, and the product works normally without them; you just lose the convenience each one provides.

Local storage keys
What it remembersWhyScope
themeRemembers whether you chose light or dark mode, so the right one shows before your account preferences load.This browser only
A per-firm "pinned navigation" flagRemembers whether you pinned the side menu open in the staff workspace.This browser only
A calendar view preferenceRemembers which calendar view (day, week, month) you last used.This browser only
A short list of recent searchesSpeeds up the global search box by showing what you searched for recently.This browser only

04What we do not use

No analytics cookies, no advertising or retargeting cookies, no tracking pixels, no session-replay scripts, and no third-party cookies of any kind, on this site or inside the product. That is the entire reason there is no cookie-consent banner: under PECR, a banner is only required when a website sets a non-essential cookie, and this one does not.

If that ever changes — for example if we add analytics to understand how the product is used — this page and a proper consent mechanism (nothing loads until you say yes) will change in the same release, not afterwards.

05How to control cookies

Because the only cookies we set are the ones that keep you signed in, the practical control is simple: sign out, or clear your browser’s cookies for this site, and the session cookie is gone. Every modern browser also lets you block or delete cookies generally in its settings; doing so for this site will sign you out and, on your next visit, ask you to sign in again — there is nothing else for it to affect.

06Changes to this policy

We will update this page the moment what the product actually sets changes, whether that means adding something or removing it. The version number and "last updated" date above always reflect the current state of the code, not an aspiration.

Questions about this document: [email protected].

Cookies · Veilux