Speleo← Back to home

Cookie Policy

Last updated: 5 July 2026

This Cookie Policy explains how Speleo (“we”, “us”, “our”) uses cookies and similar technologies on speleo.app. Read it together with our Privacy Policy.

What are cookies?

Cookies are small text files that a site stores on your device so it can work, or work better. Similar technologies — such as your browser’s localStorage — store small amounts of data in the same way. We refer to all of these as “cookies” below.

Do we ask for consent?

No cookie banner is shown, and none is required. We use only strictly necessary cookies — the ones needed to sign you in and keep you signed in. Under EU/UK ePrivacy rules, strictly necessary cookies are exempt from prior consent. We do not use analytics, advertising, or cross-site tracking cookies. If that ever changes, we will ask for your consent first.

Cookies we use

Signing in is handled by Auth0 (Okta, Inc.), our identity provider. Your access tokens are kept in memory by the app, not in cookies. The cookies below exist solely to authenticate you and maintain your session.

Cookie Set by Purpose Type Retention
auth0.is.authenticated Speleo (first-party, via the Auth0 SDK) Records that you have an active session so we can silently restore it when you return, without a full login redirect. Strictly necessary ~1 day
_legacy_auth0.is.authenticated Speleo (first-party, via the Auth0 SDK) Same as above, as a fallback for browsers that don’t support the SameSite attribute. Strictly necessary ~1 day
theme (localStorage) Speleo (first-party) Remembers your light/dark theme choice. Not a cookie, but stored on your device in the same way. Functional Until you clear it
auth0 Auth0 (on its authentication domain) Maintains your Auth0 login session so you stay signed in and can move between apps (single sign-on). Strictly necessary Session – up to a few days
did, did_compat Auth0 (on its authentication domain) Identifies the device for attack protection (bot/brute-force detection) during sign-in. Strictly necessary ~1 year

The Auth0 cookies (auth0, did, did_compat) are set on Auth0’s own authentication domain, not on speleo.app. Exact names and durations are controlled by Auth0 and may change; see Auth0’s documentation for details.

What we do not use

  • Analytics or measurement cookies (e.g. Google Analytics).
  • Advertising or retargeting cookies.
  • Social media or cross-site tracking cookies.

Managing cookies

You can block or delete cookies through your browser settings, and most browsers let you refuse third-party cookies. Because the cookies above are strictly necessary, blocking them will prevent you from signing in and using your account. Clearing the theme value simply resets your appearance preference.

Changes to this policy

We may update this policy as the service evolves. When we do, we will revise the “Last updated” date above. If we ever introduce non-essential cookies, we will update this policy and ask for your consent before setting them.

Contact

Questions about this policy? Email us at [email protected].