Last Updated: September 30, 2026
Cookie Policy
1. Essential Authentication Cookies
We use strictly necessary `HttpOnly`, `Secure`, `SameSite=Lax` cookies managed by Better Auth to maintain your authenticated session across requests.
2. Anonymous Upload Identity Cookie (`anon_id`)
When an unauthenticated visitor uploads a file, the server generates an HMAC-signed `anon_id` `HttpOnly` cookie (`Path=/`, `SameSite=Lax`). This cookie allows you to manage your pending/ready uploads and seamlessly claim ownership (`POST /api/files/claim`) after signing in, at which point the cookie is automatically cleared.
3. UI Preference Storage
Theme preferences (Light, Dark, or System mode) are stored locally to prevent visual flashing during page navigation. We do not use third-party advertising or cross-site tracking cookies.