Skip to main content
← Crumble

Cookie policy

Last updated: 2026-04-28

This policy explains the cookies and similar local-storage entries Crumble sets in your browser. It complements our privacy policy.

What we set today

Crumble currently uses only essential cookies. We do not set analytics, advertising, or third-party tracking cookies. There are no third-party trackers on our pages.

Name
Purpose
Duration
crumble_session
Keeps you signed in. HMAC-signed, HttpOnly, SameSite=Lax, Secure.
30 days, refreshed on use
oauth_state
One-shot CSRF guard for the Google OAuth sign-in handshake. Cleared the moment sign-in completes.
Until sign-in completes (max 10 min)
pending_ref
Holds an invite/referral code from a ?ref=… link so it survives the OAuth round-trip and is applied at onboarding. Cleared after it is claimed.
24 hours
crumble_consent
Stores your cookie preferences from the consent banner. Mirrored in localStorage.
1 year

We also use localStorage for in-app preferences (theme, last-seen tutorial) and for the consent record. localStorage is not transmitted to our servers.

Categories

  • Essential — required for the service to function (sign-in, CSRF, referral capture, your saved consent choice). Cannot be disabled. No consent is required under the ePrivacy Directive for strictly necessary cookies.
  • Analytics — not used at present. The toggle is in the banner so we can ask for consent before adding any in the future.
  • Marketing — not used at present. Same reason as above.

Manage or revoke consent

You can change your cookie preferences at any time:

The button reopens the consent banner. To fully erase your consent record, clear cookies and localStorage for this site in your browser settings — the banner will appear again on your next visit.

Third-party services

When you use specific features, your browser contacts third parties directly:

  • Google during sign-in (OAuth consent screen).
  • OpenStreetMap / CARTO basemap tiles when the map renders.
  • Cloudflare Turnstile on the login page (a privacy-respecting CAPTCHA, no cookies).

These third parties may set their own cookies on their own domains under their own policies. We do not control or read those cookies.

Contact

Questions about this policy: privacy [at] crumble [dot] me.

Privacy · Terms · Cookies · Security
v3.89.9