Cookie Policy
The smallest number of cookies it is possible to use and still have a site you can sign into and pay on. Every one of them is strictly necessary.
The short version.
We use the smallest number of cookies it is possible to use and still have a site you can sign into and pay on. Every one of them is strictly necessary. There is no analytics, no advertising, no tracking, and nothing that follows you anywhere.
That is why you are not being asked to agree to anything. There is no banner, because there is nothing to consent to. If that ever changes, you will be asked properly, and nothing non essential will be set until you say yes.
1. What cookies are, briefly
A cookie is a small text file a website asks your browser to keep. When you come back, the browser hands it over, so the site knows things like "this is the same person who signed in a minute ago".
Websites can also store information in your browser in other ways, mainly local storage and session storage. They work differently but the privacy rules treat them the same way, so this policy covers all of it. Where we say "cookies", we mean any of it.
2. The rule we work to
Under the Privacy and Electronic Communications Regulations 2003, as amended by the Data (Use and Access) Act 2025, a site must ask your permission before storing anything on your device, unless it falls into one of a small number of exceptions. Since February 2026 those exceptions cover things that are strictly necessary to provide what you asked for, and also a short list of low risk purposes such as remembering how you like the site to look, keeping software secure, and counting visits for the site's own statistics. The low risk ones do not need consent, but they do need to be explained to you and you must be able to say no.
Everything we set is in the strictly necessary group: signing in, staying signed in and paying safely. Nothing we set falls into the low risk group, and nothing we set needs your consent. We have not taken the opportunity to add the things the new rules would now allow us to add.
3. What we set, in full
3.1 On the public website
The public pages set nothing unless you sign in or go to pay. Read as much as you like, as often as you like. Nothing is stored, nothing is counted, nothing knows you were there.
Fonts are served from our own site rather than from a third party, so simply loading a page does not tell any other company you visited us.
3.2 Once you sign in
| Name | What it is | Set by | How long |
|---|---|---|---|
sb-[project]-auth-token, sometimes split across sb-[project]-auth-token.0 and .1 when it is too large for a single cookie | Holds your sign in tokens so you stay signed in as you move between screens. Without it you would be asked to sign in on every page. It contains your account identifier and your email address, and it is split in two only because browsers cap the size of a single cookie | Us, through our database and authentication provider | Until the session expires, or 14 days of not being used, or you sign out |
sb-[project]-auth-token-code-verifier | A short lived security value used during sign in and password reset, to prove the request came from the same browser that started it | Us | Deleted as soon as sign in finishes |
These are first party. They belong to thetrueself.app and no other company can read them. They do not contain anything you have written. Not a word of it. Your writing never goes into a cookie.
3.3 When you pay
Payment is handled by Stripe, which is regulated for this. Paying takes you to Stripe's own secure checkout, and Stripe sets cookies to check the payment is really coming from you and not from someone using your card. We do not load Stripe's software on the pricing page or anywhere else you are only looking, so nothing of Stripe's is set until you actually go to pay.
| Name | What it is | Set by | How long |
|---|---|---|---|
__stripe_mid | Fraud prevention. Recognises the device across payments | Stripe | Up to 12 months |
__stripe_sid | Fraud prevention within a single payment | Stripe | Around 30 minutes |
These are strictly necessary too: without them the payment cannot be checked and would be refused. Stripe is a data controller in its own right for what it collects here, and its policy is at stripe.com/privacy.
3.4 Other storage in your browser
| What | Why | How long |
|---|---|---|
| A draft of what you are writing, held in your browser | So that a dropped connection, a closed tab or a flat battery does not lose your words before they reach us | Cleared once the writing has saved |
| Your accessibility preferences, such as text size or reduced motion, if you set them | So the space stays as you left it | Until you clear your browser data, or until you turn it off |
The draft is your writing, so it is your personal information, and we treat it as carefully as everything else. It stays on your own device, it is never put in a cookie, and it goes nowhere until it saves to your Room.
The accessibility preference is not strictly necessary, it just makes the space nicer to use. Under the rules described in section 2 that means you have to be able to say no to it, so there is a switch in your account settings to turn it off, and turning it off deletes it. Nothing else changes if you do.
4. What we do not use
To be entirely clear, none of the following exist anywhere on this site:
- Google Analytics, or any other analytics or measurement tool
- Advertising cookies, retargeting, conversion pixels or audience lists
- Meta, TikTok, LinkedIn, X or any other social media pixel or share widget
- Session recording, heat mapping, scroll tracking or mouse tracking
- A/B testing or personalisation tools
- Third party chat widgets
- Third party font services. Our typeface is served from our own site
- Third party embedded video or media
- Cookies that follow you to other websites, of any kind
Nobody counts how long you spent on a screen, how often you signed in, or whether you started writing and stopped.
5. Why there is no cookie banner
Banners exist to collect consent for cookies that need it. Everything we set is strictly necessary, so there is nothing to consent to and a banner would be theatre.
Publishing this policy, being straight about what is set and why, and giving you a way to switch off the one preference that is not strictly necessary, is what the rules actually require of a site like this.
6. Controlling cookies yourself
You can block or delete cookies in your browser at any time. The help pages for the main browsers explain how:
- Chrome · Settings, then Privacy and security, then Third party cookies
- Safari · Settings, then Privacy
- Firefox · Settings, then Privacy and security
- Edge · Settings, then Cookies and site permissions
One honest warning. Everything we set is strictly necessary, so blocking cookies for this site will stop you signing in, and will stop payments going through. There is no way around that, and it is not a design choice we can undo. The public pages will still work perfectly.
Do Not Track and Global Privacy Control. These signals ask sites not to track you. We do not track anyone, so there is nothing for the signal to switch off. It is honoured by default.
7. If this ever changes
Since February 2026 the law would let us count page views on our own site without asking you, as long as we told you and let you opt out. We are choosing not to take that up on the terms the law allows. If we ever add anything at all beyond what is listed above:
- we will update this policy first, with the version and date changed
- we will ask you properly, even where the law would let us simply tell you. Refusing will be as easy as accepting, with no pre ticked boxes and no dark patterns
- nothing beyond the strictly necessary will be set unless and until you say yes
- you will be able to change your mind at any time, in the same number of clicks
- we will not put analytics of any kind inside A Place to Land. How a parent uses that space is nobody's business but theirs
That is a promise we are making to you, not a rule we are being held to. We think it is the right way round for a space like this one.
8. Where this fits
This policy sits alongside the [Privacy Notice], which explains everything else we hold and why, and the [Terms of Use].
9. Getting in touch
Questions about cookies, or about anything in this policy, to [privacy@thetrueself.app] or [ADDRESS].
If you are not happy with our answer, you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113.
The True Self · Cookie Policy · Version 1.0 · [DATE] Related documents: [Privacy Notice] · [Terms of Use] · [Accessibility Statement]