Cookie Policy
VERA sets a small number of cookies, all of them for making the product work. There are no advertising cookies, no marketing tags, no cross-site tracking pixels, and no third-party ad networks. That is why you do not see a consent banner: we do not set anything that requires consent under the ePrivacy rules for non-essential cookies.
- Version
- 1.0
- Effective
- July 28, 2026
- Last updated
- July 28, 2026
- Revisions
- 1
On this page (7 sections)
1. Essential cookies
These are required for authentication and for security. Blocking them prevents you from signing in or completing an integration connection.
| Cookie | Purpose | Set by | Lifetime | Can you disable it? |
|---|---|---|---|---|
| authjs.session-token (__Secure- prefixed over HTTPS) | Keeps you signed in. Holds a signed JSON Web Token identifying your account and its session revocation counter. | VERA (Auth.js) | Session, expiring per Auth.js defaults | No, not while signed in |
| authjs.csrf-token | Cross-site request forgery protection on sign-in and sign-out. | VERA (Auth.js) | Session | No |
| authjs.callback-url | Remembers where to return you after a sign-in redirect. | VERA (Auth.js) | Session | No |
| vera_integration_oauth | Holds the OAuth state and PKCE verifier while you complete a connection to a third-party platform, plus any value you typed before starting (such as a store domain). | VERA | 10 minutes | No, only set during a connection flow |
| vera_gmail_oauth | The same short-lived state for the Gmail connection flow specifically. | VERA | 10 minutes | No, only set during a connection flow |
2. Preference cookies
These remember a choice you made so the product behaves the way you expect. They are functional, they hold no identifier, and clearing them costs you nothing but the preference.
| Cookie | Purpose | Set by | Lifetime | Can you disable it? |
|---|---|---|---|---|
| vera_industry | Remembers the industry you selected on a landing page so sign-up and onboarding can be pre-filled. Holds an industry slug only. | VERA | 30 days | Yes, clear it in your browser. The site still works. |
| vera-demo | Records that you switched the app into demonstration mode, which shows sample data instead of your real records. | VERA | Session | Yes, switch demo mode off in the app |
3. Browser storage that is not a cookie
VERA stores your light or dark theme choice in your browser's local storage under the key vera-theme. It is read before the first paint so the interface does not flash the wrong theme. It never leaves your browser and is not a cookie.
4. Analytics
Our public marketing pages use Vercel Web Analytics and Vercel Speed Insights. These products are designed to measure traffic and page performance without setting cookies and without building a cross-site profile of visitors, which is why they do not appear in the tables above.
The custom events VERA sends alongside them carry only a closed set of values: an industry slug, which surface a click came from, a numeric position, a dwell time in seconds, and a search term trimmed to 60 characters. No email address, name, account identifier, or free-typed content is ever included.
5. Third-party cookies
VERA does not embed third-party advertising, retargeting, social, or session-recording scripts, so no third party sets a cookie on our pages.
When you are redirected to a third party to complete a task, that party sets its own cookies on its own domain under its own policy. This happens when you check out or manage billing on Stripe's hosted pages, when you sign in with Google, and when you authorize an integration on a provider's consent screen. Those cookies are outside VERA's control.
6. Your controls
Every browser lets you view, block, and delete cookies, usually under privacy or site settings. Blocking essential cookies will break sign-in, which is a limitation of how session authentication works rather than a choice we made.
VERA does not currently respond to the Do Not Track browser header, which lacks a common interpretation. It does honor Global Privacy Control signals for California residents as described in the California Privacy Notice, though because we do not sell or share personal information there is nothing for the signal to opt you out of.
7. Changes
If VERA introduces a cookie that is not strictly necessary, we will add it to this page, and we will ask for consent before setting it where consent is required.
Change history
Every revision of this document, newest first. Material changes are notified to account holders before they take effect where practicable.
- v1.0July 28, 2026
Initial Cookie Policy published, enumerating every cookie the application sets.
Questions about this document?
Legal and contracts: support@myvera.io. Privacy and data rights: support@myvera.io. Security reports: support@myvera.io.
Related
This document is a carefully drafted policy written against how VERA actually works. It is not legal advice, and it should be reviewed by a licensed attorney in your jurisdiction before you rely on it.
