1. Our position
Under EU rules, consent is required for cookies that are not strictly necessary to deliver a service you asked for. We do not use any. That means there is nothing here for you to consent to, and building a banner that asks you to “accept” cookies we do not set would be theatre.
So the notice you may have seen at the bottom of the page is exactly that — a notice. It has one button, it tells you what is set, and dismissing it stores one first-party cookie so it stops appearing. It has no “reject” button because there is nothing optional to reject.
2. What is actually set
Checked against the live site: the public marketing pages — this one, the homepage, pricing, features, FAQ, docs and the legal pages — set no cookies at all until you interact with the notice. The rest appear only once you sign in.
| Cookie | Set by | Purpose | Lifetime | When |
|---|---|---|---|---|
sbs_cookie_consent |
Us (first party) | Remembers that you have seen the cookie notice, so it stops appearing. Contains the single value "necessary" and nothing else. | 12 months | Only when you dismiss the notice. |
wordpress_logged_in_* |
Us (first party) | Keeps you signed in. Without it there is no way to have an account. | Session, or 14 days if you choose “remember me” | Only after you sign in. |
wordpress_sec_* |
Us (first party) | Authenticates you on secure pages of the application. | Session, or 14 days if you choose “remember me” | Only after you sign in. |
wordpress_test_cookie |
Us (first party) | Checks that your browser accepts cookies before the sign-in form is submitted, so we can show a useful error instead of failing silently. | Session | Only on the sign-in page. |
wp-settings-*, wp-settings-time-* |
Us (first party) | Remembers interface preferences of a signed-in user. | Up to 12 months | Only after you sign in. |
All of these are first-party, none of them profile you, and none of them are shared with anyone.
3. What we do not set
- No analytics of any kind — no Google Analytics, no self-hosted analytics, no page-view pixel.
- No advertising, remarketing or conversion-tracking cookies.
- No social-network embeds, share buttons or “like” widgets.
- No session-recording or heat-mapping tools.
- No third-party chat widget.
- No fingerprinting, and no local-storage substitute used for tracking.
The one third-party resource this site loads is a web font stylesheet from
Google Fonts (fonts.googleapis.com and
fonts.gstatic.com). It sets no cookie — but your browser fetches it
directly, so Google receives your IP address and user agent on every page view. That
is a data transfer even though it is not a cookie, so we name it here as well as in
the sub-processor list.
We intend to self-host these fonts and remove the request entirely.
4. Payments and Stripe
When you subscribe, checkout happens on Stripe's own hosted page and billing management happens in Stripe's billing portal. Those are Stripe's pages under Stripe's domain, and Stripe sets its own cookies there for fraud prevention and session handling. That is outside this website's control and is covered by Stripe's own policies. We never see or store your card details.
5. How to control cookies
Every browser lets you view, block and delete cookies, usually under Privacy or
Settings. You can block ours entirely — with one consequence you should know about:
the sign-in cookies are what keep you signed in, so blocking them makes the
application unusable. Blocking or deleting sbs_cookie_consent only means
the notice appears again.
Deleting the consent cookie yourself is a complete withdrawal — there is no server-side record of it, because we do not need one.
6. If this ever changes
If we ever add something that is not strictly necessary — an analytics tool, an embedded video, a chat widget — we will do two things before it ships: update this page, and replace the notice with a real consent mechanism that defaults to off and lets you refuse without losing the service. Until then, this page is deliberately boring.
Questions: [PRIVACY EMAIL]. See also the Privacy Policy.