Legal Template Notice: This document is a structural starter template provided for SaaS boilerplate demonstration and does not constitute formal legal advice. Replace placeholders with counsel-reviewed terms before production launch.

Last Updated: September 30, 2026

Cookie Policy

1. Essential Authentication Cookies

We use strictly necessary `HttpOnly`, `Secure`, `SameSite=Lax` cookies managed by Better Auth to maintain your authenticated session across requests.

2. Anonymous Upload Identity Cookie (`anon_id`)

When an unauthenticated visitor uploads a file, the server generates an HMAC-signed `anon_id` `HttpOnly` cookie (`Path=/`, `SameSite=Lax`). This cookie allows you to manage your pending/ready uploads and seamlessly claim ownership (`POST /api/files/claim`) after signing in, at which point the cookie is automatically cleared.

3. UI Preference Storage

Theme preferences (Light, Dark, or System mode) are stored locally to prevent visual flashing during page navigation. We do not use third-party advertising or cross-site tracking cookies.