NARA

/cookies · last updated 29 April 2026

Cookie policy.
Nothing creepy.

The full list of cookies NARA sets, what each does, and how to clear them. Short version: nothing creepy, no third-party ad tags.

Essential

These cookies are required for the platform to work. We can't disable them without breaking sign-in.

access_tokenshort-lived (15 min) session cookie set by auth-service after login. httpOnly, Secure, SameSite=Lax.
refresh_token30-day rotating refresh token. httpOnly, Secure.
user_id, user_email, user_roledisplay-only cookies set so we don't have to round-trip on every page render. Never trusted server-side for authorization.
session_idopaque session identifier, used to correlate audit logs.

Functional

These cookies remember your preferences. You can clear them at any time from your browser.

themeyour chosen colour scheme (dark / light / system).
last_chat_modelthe model you last selected, prefilled on next visit.

Analytics

We use PostHog to understand how people move through the product. Cookies are only set after you've authenticated — anonymous traffic is not tracked.

ph_<token>_posthogPostHog session + identification cookie. SameSite=Lax.
You can opt out of analytics from /settings.

Marketing

We don't run third-party advertising trackers (no Meta Pixel, no Google Ads, no LinkedIn Insight). The marketing site is plain HTML to a browser that has never visited.

Changing your mind

Clear cookies in your browser to reset everything; you'll need to sign in again.

Disable analytics from /settings inside the app.

Questions · [email protected]