Cookie Policy
Last updated: October 10, 2026 (version 1.1)
1. What this covers
This policy describes the cookies and similar browser storage ClearPath uses, what each one is for, and how to refuse the ones that are not essential. It sits alongside our Privacy Policy, which covers personal data more broadly.
2. Cookies we set
ClearPath sets the five cookies below, and every one of them is strictly necessary — the service cannot work without them, so they do not require consent. Which of them your browser is carrying depends on where you are: the first three are set whether or not you have an account, and the last two exist only while you are signed in.
| Cookie | Purpose | Lifetime |
|---|---|---|
authjs.csrf-token | Ensures a sign-in request genuinely came from our own page. Set by the first page you open, before any sign-in | Until you close the browser |
authjs.callback-url | Remembers which page to return you to after you sign in. Set by the first page you open, before any sign-in | Until you close the browser |
clearpath-language | Remembers your language so the page renders in the right language and reading direction on the server, without a flash of the wrong one | 1 year |
authjs.session-token | Keeps you signed in and identifies your account on each request | Up to 7 days, counted from the last time you used ClearPath rather than from when you signed in — or until you close the browser, if you left “Remember me” unticked. Signing out ends it either way |
cp-session-only | Records that you left “Remember me” unticked, which is what keeps the session cookie above tied to this browser session. Set only when that box is unticked | Until you close the browser |
3. Things we store in your browser that are not cookies
Some preferences are kept in your browser’s local storage rather than in a cookie. They are never transmitted to us with your requests, and they stay on your device:
- your theme choice;
- the workspace you last had open;
- your cookie choice itself, so we can tell whether you have answered the banner.
Clearing your browser’s site data removes these as well as the cookies above.
4. Analytics and advertising
We set no analytics cookies and no advertising cookies. We run no third-party advertising, and we do not sell or share cookie data.
The product contains an integration for a privacy-respecting analytics provider that is not enabled. If we ever turn it on, it will load only after you have allowed the analytics category in the consent banner — and if you later withdraw that consent, the scripts stop loading and the cookies already set are deleted. Until then, choosing “reject” changes nothing, because there is nothing to reject.
5. Third parties
If you connect an optional integration — Microsoft, LinkedIn or another provider — that provider may set its own cookies during the sign-in flow it controls. Those cookies are governed by that provider’s own policy, not this one. We do not embed third-party trackers, advertising pixels or social widgets on our pages.
6. How to refuse or withdraw
Use the cookie banner, which is available on the public site and inside the application, to change your choice at any time. Withdrawing consent takes effect immediately: we stop loading the relevant scripts and delete the cookies that category had already set.
You can also clear or block cookies in your browser settings. Note that blocking the strictly necessary cookies in section 2 will prevent you from signing in at all.
7. Changes
If we begin using a cookie that is not listed here, we will update this page before doing so, and non-essential cookies will remain behind the consent banner.
8. Contact
PROPOSED – lawyer review Questions about this policy: our contact page (subject “Privacy”).