Cookie Policy

Every cookie Invy sets, what it does, and how long it lasts.

Most cookie policies are vague because the list is long and unflattering. Ours is short, so here is all of it.

Invy sets four cookies. All four are strictly necessary, all are first-party, and none are used for advertising, profiling, or cross-site tracking.

We do not set marketing cookies. We do not embed advertising pixels or social media trackers. We do not sell or share browsing data. There is no cookie banner because, under the rules that require one, there is nothing here to ask you to consent to.

The cookies we set

Cookie Purpose Lifetime Flags
auth_token Keeps you signed in. Without it you would re-enter your password on every page. 7 days HttpOnly, SameSite=Lax, Secure in production
csrf_token Security. Proves a form submission came from Invy and not another site acting through your browser. 7 days HttpOnly, SameSite=Lax, Secure in production
bulk_flash Carries a one-off confirmation message (“Moved 3 units”) across a single page load, then expires. 15 seconds HttpOnly, SameSite=Lax

What the flags mean

  • HttpOnly — JavaScript cannot read the cookie, which limits what a content-injection bug could steal. Every cookie Invy sets is HttpOnly.
  • SameSite=Lax — the cookie is not sent when another website makes requests to Invy, which is what stops cross-site request forgery.
  • Secure — the cookie is only sent over HTTPS.

None of these cookies contain your password. None track you across other websites, because none of them are readable by any site other than Invy.

How sessions, CSRF protection, and account security work in more detail is covered in the Security Overview.

Analytics

Where analytics are enabled, Invy uses Umami, which is cookieless. It counts page views and referrers without setting a cookie, without a persistent identifier, and without building a profile of you. It is also optional: a self-hosted Invy can run with analytics switched off entirely, and then no analytics requests leave your browser at all.

We use Umami specifically because the common alternative — Google Analytics — sets cookies, retains identifiers, and feeds an advertising business. That tradeoff is not worth it for counting page views.

Bot protection

Sign-in and password-reset pages may load Cloudflare Turnstile, which tells human visitors apart from automated password-guessing attempts. Turnstile is designed not to track users across sites and does not require a cookie banner. It only loads on authentication pages, and only when configured.

Turning cookies off

You can block or delete cookies in your browser settings, and Invy’s marketing and documentation pages will work normally.

Signing in will not. auth_token is how Invy knows the session is yours and csrf_token is what protects your account from other sites acting through your browser — so blocking them does not degrade the app, it prevents you from using it. There is no way around that, for any site that keeps you logged in.

Changes

If we add a cookie, it goes in the table above. If a category ever appears here that is not strictly necessary, we will say so plainly rather than bury it.

See also the Security Overview for how Invy protects your data more broadly.

This page describes Invy as currently built and is updated as the software changes.

Loading...
Processing