Cookies
Cookie policy
The whole policy fits on one page because we only set cookies the service needs to work. No advertising cookies, no analytics cookies, no affiliate cookies, no cross-site anything.
The cookies we set
Keeps a host signed in between visits. Set by our authentication provider, Supabase, on our own domain.
Authorizes one guest page without an account. HttpOnly, one per page, and restored by the complete private edit link.
Remembers that you entered a journal PIN correctly so you are not asked on every page.
The private key that lets the same browser read and continue one support conversation. HttpOnly and useless without that conversation.
All four are strictly necessary: the service cannot sign you in, hold your draft, honor a PIN, or continue your requested support chat without them, which is why they do not require a consent choice. Dismissing our cookie notice is remembered in your browser's local storage, not a cookie.
Browser storage
When a guest starts a page, the browser also keeps that page's private recovery key under sq:keysin local storage. It restores a draft if the editing cookie is lost. The complete private edit link also carries the key after # so another browser can recover access; fragments are not sent in page requests or referrers. The key works only while the draft remains live, is never used for advertising, and can be cleared from the browser at any time. A support visitor's private recovery record is stored under sq:support:v1 so the same device can restore that conversation if its HttpOnly cookie is lost. It expires with the support session and is never used across conversations.
Partner referrals
Partner attribution does not set a cookie or write to browser storage. A signed partner link becomes one random first-party identifier in the URL, which is carried through sign-in and discarded from the browser after the new account is credited.
Third parties
If you open our checkout or billing portal, you are on Stripe's pages and Stripe sets its own cookies for payment security and fraud prevention, governed by Stripe's cookie policy. We embed no other third-party services in your browser: no ad networks, no analytics scripts, no social pixels, no tag managers.
Managing cookies
Your browser can block or delete cookies at any time. Blocking ours signs hosts out, prevents guest editors and support chats from working, and re-asks for journal PINs. Once cookies are allowed, a complete private edit link can restore its guest page. Public journals stay readable.
Where this fits
This policy is part of our privacy policy and terms of service. If we ever add a cookie, it gets listed here first and the notice reappears. Questions: use the support chat on any page.
Last updated July 2026