Cookie Policy
Last updated: 5 July 2026
This Cookie Policy explains how Speleo (“we”, “us”, “our”) uses cookies and similar technologies on speleo.app. Read it together with our Privacy Policy.
What are cookies?
Cookies are small text files that a site stores on your device so it can work,
or work better. Similar technologies — such as your browser’s
localStorage — store small amounts of data in the same way.
We refer to all of these as “cookies” below.
Do we ask for consent?
No cookie banner is shown, and none is required. We use only strictly necessary cookies — the ones needed to sign you in and keep you signed in. Under EU/UK ePrivacy rules, strictly necessary cookies are exempt from prior consent. We do not use analytics, advertising, or cross-site tracking cookies. If that ever changes, we will ask for your consent first.
Cookies we use
Signing in is handled by Auth0 (Okta, Inc.), our identity provider. Your access tokens are kept in memory by the app, not in cookies. The cookies below exist solely to authenticate you and maintain your session.
| Cookie | Set by | Purpose | Type | Retention |
|---|---|---|---|---|
auth0.is.authenticated |
Speleo (first-party, via the Auth0 SDK) | Records that you have an active session so we can silently restore it when you return, without a full login redirect. | Strictly necessary | ~1 day |
_legacy_auth0.is.authenticated |
Speleo (first-party, via the Auth0 SDK) | Same as above, as a fallback for browsers that don’t support the SameSite attribute. |
Strictly necessary | ~1 day |
theme (localStorage) |
Speleo (first-party) | Remembers your light/dark theme choice. Not a cookie, but stored on your device in the same way. | Functional | Until you clear it |
auth0 |
Auth0 (on its authentication domain) | Maintains your Auth0 login session so you stay signed in and can move between apps (single sign-on). | Strictly necessary | Session – up to a few days |
did, did_compat |
Auth0 (on its authentication domain) | Identifies the device for attack protection (bot/brute-force detection) during sign-in. | Strictly necessary | ~1 year |
The Auth0 cookies (auth0, did, did_compat)
are set on Auth0’s own authentication domain, not on speleo.app.
Exact names and durations are controlled by Auth0 and may change; see
Auth0’s documentation
for details.
What we do not use
- Analytics or measurement cookies (e.g. Google Analytics).
- Advertising or retargeting cookies.
- Social media or cross-site tracking cookies.
Managing cookies
You can block or delete cookies through your browser settings, and most browsers
let you refuse third-party cookies. Because the cookies above are strictly
necessary, blocking them will prevent you from signing in and using your account.
Clearing the theme value simply resets your appearance preference.
Changes to this policy
We may update this policy as the service evolves. When we do, we will revise the “Last updated” date above. If we ever introduce non-essential cookies, we will update this policy and ask for your consent before setting them.
Contact
Questions about this policy? Email us at [email protected].