Legal
Cookie Policy
Effective 26 February 2026
We use a minimal number of cookies, all of them strictly necessary to operate Hearth & Crate.
Cookies we set
| Name | Purpose | Lifetime |
|---|---|---|
| access_token | Keeps you signed in (HTTP-only, SameSite=Lax) | 12 hours |
| refresh_token | Lets the app refresh your session silently | 7 days |
| hearth.cookies-ack | Remembers that you've dismissed the cookie banner | 12 months (localStorage) |
What we don't use
No analytics cookies (Google Analytics, Plausible, etc.). No advertising or tracking pixels. No third-party social cookies.
Disabling cookies
The auth cookies are strictly necessary — if you block them you won't be able to sign in. You can clear them at any time from your browser settings.