Cookies
Last updated September 24, 2026
CMD-OS uses only strictly necessary cookies and browser storage: the ones that keep you signed in, protect sign-in, and remember a setting you chose. There are no analytics, advertising or third-party tracking cookies — on this website or in the app.
Because every item below is strictly necessary to provide a service you asked for, the EU ePrivacy rules and the UK's PECR don't require consent for them, which is why you won't see a cookie banner. If we ever add anything that isn't strictly necessary, we will ask first.
What we set
| Name | Type | Purpose | Lasts |
|---|---|---|---|
cortex_session | Cookie (first-party, HttpOnly, Secure) | Keeps you signed in. Holds a signed session ID and nothing else. | 30 days, or until you sign out |
cortex_google_state | Cookie (first-party, HttpOnly) | Protects the Google connection flow against forgery. Only set when you connect Google. | 10 minutes |
cortex-theme | Local storage | Remembers whether you picked the light or dark appearance. | Until you clear it |
cortex-rail | Local storage | Remembers whether you collapsed the sidebar. | Until you clear it |
cortex-v1-assets | Service-worker cache | Stores the app's own static files so it loads fast and works offline. Never stores your data. | Until the next app update |
Third-party pages and embeds
- Checkout and billing happen on Stripe's own pages (checkout.stripe.com and billing.stripe.com), which set cookies Stripe needs for payments and fraud prevention under Stripe's cookie policy.
- Link pages that customers build can embed videos. YouTube videos use YouTube's privacy-enhanced mode (youtube-nocookie.com) and Vimeo videos are loaded with Do Not Track on; those services apply their own policies once a visitor plays a video.
Your control
You can block or delete cookies in your browser settings. If you block the session cookie you won't be able to sign in. Clearing local storage just resets your appearance and sidebar choices. More in our Privacy Policy.