Legal
Cookie policy
Cookie policy
Last updated: July 31, 2026
We use the minimum set of cookies to make sign-in work and to remember display preferences. No advertising cookies, no cross-site tracking, no behavioural-analytics SDK.
What we set
| Cookie | Purpose | Lifetime | Type |
|---|---|---|---|
better-auth.session-token |
Authentication — keeps you signed in across page loads. HttpOnly, Secure on HTTPS, SameSite=Lax. | 7 days, rolling | Strictly necessary |
Theme cookie — pl-theme (Placet), cv-theme (Cordon), sl-theme (Sluice), dh-theme (Duehatch), gw-theme (Gangway) |
Remembers your dark / light / auto theme choice. JS-readable so the bootstrap script in app.html can avoid a flash on page load. SameSite=Lax. |
1 year | Functional |
gw-ref (Gangway) |
Remembers which referral link brought you here, so the referrer can be credited if you sign up. Set only when you arrive via a ?ref= link; contains the referral code, nothing about you. HttpOnly, SameSite=Lax. |
60 days | Functional |
| Paddle checkout / customer portal cookies | Set by Paddle on its checkout overlay and customer-portal pages — our Merchant of Record — not by us. Governed by Paddle's cookie policy. | Per Paddle | Strictly necessary (only during checkout / portal) |
We do not set cookies for: advertising, retargeting, behavioural profiling, A/B testing, or analytics tied to individual users.
Other storage on your device
Cookies aren't the only thing a browser stores, so for completeness — we also
use localStorage in two places, and neither is shared with anyone:
| Key | Purpose | Where |
|---|---|---|
pl-theme, cv-theme, sl-theme, dh-theme, gw-theme |
The same theme choice as the cookie above, mirrored so the page can apply it before it renders | All products |
af:email:<board> |
The email you typed into an approval room, remembered per board so you don't retype it when you come back | Placet client portals |
Clearing site data in your browser removes both. Neither is readable by any other site, and nothing is sent to a third party.
Why no cookie banner
The session cookie is required to deliver the service you asked for, and the theme cookie is one you set yourself by using the theme switcher. Neither needs an opt-in banner, and we have no third-party, advertising or cross-site tracking cookies at all.
One cookie doesn't fit that description and we'd rather name it than round
it up: gw-ref. Following a referral link is what sets it — you didn't
ask for it, and crediting a referrer isn't necessary to deliver anything to
you. What it holds is the referral code from the link and nothing about
you; it is first-party and HttpOnly, is read once when a workspace is
created, and is never used to profile, target or track you across sites.
Refusing or clearing it costs you nothing — the product behaves identically,
and only the person who referred you loses the credit.
If we ever add analytics or advertising, this policy and a banner land together.
How to disable
Browser settings — every major browser supports rejecting cookies per site. If you disable the session cookie you can't sign in. The theme cookie is optional and the site falls back to your system preference.
Contact
privacy@porthatch.app for cookie-related questions.