Cookie Info
The cookies Affensus sets in your browser.
Last updated September 28, 2026
What we set
auth-token — HttpOnly session cookie after you sign in. Lasts 7 days. Required to use the dashboard and billed extract.
oauth_state — short-lived cookie during Google or GitHub sign-in. Used to stop CSRF. It goes away after the login finishes.
affensus-theme — light or dark. Lasts 1 year. Set when you pick Appearance.
affensus-demo-extracts — counts homepage demo extracts. Lasts 1 year. Not used after you sign in with a key.
Local storage
The browser may also keep theme and demo-extract counts in local storage so the UI stays consistent.
Third parties
Stripe may set cookies when you pay. Those cookies are Stripe's, not ours. See Stripe's privacy documentation.
How to control them
You can block or delete cookies in your browser. If you block auth-token, you cannot stay signed in. Theme will fall back to the default.