Jotholm

Jotholm Cookie Policy

Last updated: 21 June 2026
Effective: 21 June 2026

This policy explains the cookies and similar technologies Jotholm uses. It should be read with the Privacy Policy.

1. What cookies we use

Jotholm uses a small number of strictly-necessary cookies to sign you in and keep the service secure. These are the only cookies we set:

CookiePurposeCategoryDurationFlags
wb_accountFront-door account session; keeps you signed in across workspacesStrictly necessary~30 days (sliding)HttpOnly, Secure, SameSite=Lax
wb_sessionPer-workspace session; authenticates you within a workspaceStrictly necessary~365 days (sliding)HttpOnly, Secure, SameSite=Lax
oidc_stateHolds OAuth state during "Sign in with Google" to prevent CSRFStrictly necessary~10 minutesHttpOnly, Secure, SameSite=Lax
invite_claimCarries an invite acceptance through the sign-in flowStrictly necessary~10 minutesHttpOnly, Secure, SameSite=Lax

These are the only cookies set on the user-facing application; our infrastructure sets no additional cookies on your traffic, and no third-party CDN or tracker proxies it. Any cookies used by our internal operator/administrative tools are not part of the user-facing service and are out of scope for this list.

2. What we do not use

3. Consent model

All cookies we set are strictly necessary to deliver a service you have actively requested (signing in, maintaining your session, securing the OAuth flow). Under the ePrivacy Directive / PECR, strictly-necessary cookies are exempt from prior consent. Because we set no non-essential cookies, Jotholm does not currently require a cookie-consent banner, and we do not show one.

This exemption holds only while every cookie remains strictly necessary. If any analytics, marketing, embedded third-party, or other non-essential cookie/tracker is added, a compliant consent mechanism (granular, opt-in, as easy to refuse as to accept, no pre-ticked boxes) becomes mandatory before it is set. That would also require a UX change and an update to this policy.

The "strictly necessary → no banner" position (for the EU/EEA target market, under the ePrivacy Directive / PECR) and the ~365-day sliding wb_session lifetime both follow from the strictly-necessary nature of these cookies. The long lifetime is a persistent per-workspace session cookie that keeps you signed in across visits; it will be revisited if any non-essential cookie is ever introduced.

4. Managing cookies

Because our cookies are strictly necessary, disabling them in your browser will prevent you from signing in or using the service. You can clear cookies via your browser settings at any time; signing out also invalidates your session.