← Back home

Cookie policy

Last updated: 2026-05-24

We use the minimum cookies needed to keep you signed in and remember your preferences. No advertising or cross-site tracking.

What are cookies

Cookies are small text files a website stores on your device. They let the site remember you between requests — for example, that you're signed in.

How we use them

Trumailo uses cookies for two things: keeping you signed in after you authenticate, and remembering UI preferences like whether you've dismissed the onboarding dialog. We don't use cookies for advertising or analytics tracking.

Cookies we set

  • next-auth.session-token — your signed-in session. HTTP-only, secure (in production), SameSite=Lax. Expires when your session does.
  • next-auth.csrf-token — cross-site request forgery defence. Set during sign-in.
  • next-auth.callback-url — remembers where to send you after sign-in.

We also use one localStorage entry (trumailo-onboarded) to remember that you've seen the API-setup walkthrough. Not technically a cookie, but worth mentioning here.

Third-party cookies

When you reach the checkout page, Paddle's embedded checkout sets its own cookies to process your payment. See Paddle's cookie policy for details. We don't embed analytics, social, or advertising trackers.

Your choices

You can clear or block cookies in your browser settings. Disabling our session cookie will sign you out and prevent you from using the app, but you'll still be able to read the marketing site.

Changes

If we ever add a tracking cookie we'll show a consent banner first. Until then, this page tells the whole story.

Questions about this policy? Email legal@trumailo.com or use the contact form.