Cookie policy
Last updated: 27 September 2026. Policy version 2.
Cookies are small files a site stores in your browser so it can remember something between page loads. Whaily uses as few as it can. This page lists every one, what it does and how long it lasts. If a row is unclear, write to hello@whaily.com and we will fix the wording.
The short version
We set no analytics cookie, no advertising cookie and no third-party tracker. The cookies below sign you in, keep you signed in, keep bots out, or remember something you told us, and they stay whatever you choose. One thing is optional: error reporting through Sentry. It starts only if you accept, and it stops as soon as you withdraw. If you reject, or have not chosen yet, your browser does not even download it.
Your choice
Record or change it here. The cookies below stay either way, because Whaily cannot sign you in without them.
You have not recorded a choice yet.
Strictly necessary
Signing in, staying signed in, protecting the forms against cross-site attacks and keeping automated sign-ups out all depend on these. There is no toggle for them and they are exempt from consent under ePrivacy Article 5(3).
| Name | Set by | What it does | How long |
|---|---|---|---|
| whaily-console.session-token (__Secure-whaily-console.session-token on our live site) | Whaily (Auth.js) | Keeps you signed in. A signed token holding your user id, your brand memberships and the id of this session, so signing out of one device can end that one alone. | 180 days, extended while you keep using Whaily |
| authjs.csrf-token (__Host-authjs.csrf-token on our live site) | Whaily (Auth.js) | Stops another site posting the sign-in and sign-out forms on your behalf. | Until you close the browser |
| authjs.callback-url (__Secure-authjs.callback-url on our live site) | Whaily (Auth.js) | Where to send you after a successful sign-in. | Until you close the browser |
| authjs.pkce.code_verifier, authjs.state | Whaily (Auth.js) | Only if you sign in with Google. They tie the trip out to Google and back to the browser that started it, so a reply meant for someone else cannot be replayed here. | 15 minutes |
| __cf_bm, cf_clearance, cf_chl_rc_* | Cloudflare (Turnstile) | The bot check on the sign-up, sign-in and invitation forms. It is what keeps automated sign-ups out. | From one page load up to 30 minutes |
| console-claims-refresh | Whaily | Set for a few minutes after you create a brand, so the next page reads your access from the database instead of from a token issued a moment before the brand existed. | 5 minutes |
| whaily-console.impersonate | Whaily | Whaily staff only, and signed so it cannot be forged. It pins a support session to the one brand being looked at. A customer browser never receives it. | 8 hours |
| whaily_cookie_consent | Whaily | Remembers the choice you make on this page, so we stop asking. | 395 days |
| whaily_onboarding_v1 (browser storage, not a cookie) | Whaily | While you set up a brand, keeps what you typed so a reload does not lose it. Stored in this tab only and removed when you finish. | Until you close the tab |
Remembering what you chose
These are set because you did the thing they remember, and only then. None of them identifies you, none is read by anyone else, and none leaves your browser except to answer the page that set it. Clearing site data removes them.
| Name | Set by | What it does | How long |
|---|---|---|---|
| console-last-sign-in | Whaily | Which of the three sign-in methods you last used, so the sign-in page can point at it. One of three fixed words. Never your address. | 1 year |
| whaily_nudge_overview_<brand id> | Whaily | Set when you dismiss the coverage tip on a brand overview, so it stays dismissed for that brand. | 7 days |
| theme (browser storage, not a cookie) | Whaily | Whether you chose light, dark, or to follow your device. Stored in your browser and never sent to us. Listed because ePrivacy treats browser storage the same way it treats a cookie. | Until you clear site data |
Optional: error reporting
If you accept, Whaily loads Sentry in your browser. When a page breaks, it sends Sentry the error message, the stack trace, the address of the page, your browser and operating system, and a short trail of what the page did just before (the requests it made and the controls pressed), so we can find and fix the fault. Sentry sees your IP address when your browser connects to it, as any server does. We do not send your name, your email address or your cookies with a report. Sentry sets no cookie of its own. Reports go to Sentry's EU region (ingest.de.sentry.io, Germany).
It never loads before you accept. If you reject, or withdraw later, it stops at once, without a reload. This is policy version 2: an answer given under version 1, before Sentry was added, is not carried forward, so the banner asks again.
Other services we use
- Cloudflare Turnstile, the bot check on the sign-up, sign-in and invitation forms. It loads only on those forms, sets the cookies named above and is strictly necessary.
- Sentry, for error reporting, only if you accept. See the optional section above.
- Stripe, only when you choose a plan. You leave Whaily for Stripe's checkout page, which sets its own cookies under its own policy. No Stripe script runs on our pages.
- Vercel, which hosts and serves these pages. It sets no cookie of its own in your browser.
- Neon, which hosts the database. Your browser never talks to it and it sets nothing.
- Resend, which sends sign-in links and notification email. No browser cookie. Listed so the list is complete.
- Google, only if you choose to sign in with a Google account. Google sets its own cookies on its own sign-in page, under its own policy, not on ours.
Changing your mind
Use the buttons above, or the control in the footer of any page, which reopens the banner. Clearing cookies in your browser resets everything and the banner returns on your next visit.
Related
Our Privacy Policy covers personal data more broadly, and the Terms of Use set out the legal framing of the service. Questions go to hello@whaily.com.
