Cookie policy
The few cookies Typestream sets, what each is for, and why there's no cookie banner.
Typestream sets only the cookies it needs to sign you in and keep you signed in. It sets no advertising or tracking cookies, and neither of our analytics tools uses cookies. That's why there's no cookie banner.
Cookies Typestream sets
These are set by our sign-in service when you sign in to the app, for the app and its services on our domain. They're strictly necessary: without them, you can't stay signed in.
- The session cookie (
better-auth.session_token, with a__Secure-prefix on our live sites) says who you're signed in as. It can't be read by the page's scripts, is sent only over HTTPS, isn't sent with other sites' requests, and lasts seven days, or until you sign out. - Short-lived sign-in cookies hold state while you sign in with Microsoft or your organisation's SSO, and are removed when you finish.
Our marketing website sets no cookies of its own.
Things that aren't cookies
- Your theme (light, dark or matching your system), the getting-started checklist, and which tips you've already seen are kept in your browser's local storage. They never leave your browser.
- Vercel Web Analytics counts visits to our marketing website, and Vercel Speed Insights measures how fast pages load. Neither uses cookies or identifies you.
Other sites' cookies
When you pay through Stripe, or sign in with Microsoft or your organisation's identity provider, you're on their site, and their cookie policies apply.
Turning cookies off
You can block cookies in your browser's settings, but you won't be able to sign in to Typestream.
Questions? Write to privacy@typestream.nz.