The short cookie story.
Last updated: 2026-08-01
Taxottic uses only the cookies it needs to keep you signed in and to make sign-in, passkeys, and basic security work. We do not set advertising cookies. We do not load third-party tracking pixels. We do not run an analytics or crash-reporting SDK. We do not sell or share your data with ad networks.
The banner you may have seen asking you to accept is a notice about how we process your data generally, not a cookie consent, because every cookie below is strictly necessary. Your acknowledgement is recorded on your account rather than in a cookie.
| Cookie | Purpose | Lifetime |
|---|---|---|
| sb-<project>-auth-token | Holds your signed-in session. Split across numbered chunks when it is too large for one cookie. | Rotated on use, cleared when you sign out. |
| tx_passkey_challenge | Holds a short-lived challenge during a passkey sign-in or registration. | A few minutes. |
| taxottic_oauth_state | Guards the Google and Microsoft sign-in handshake against cross-site request forgery. | 10 minutes. |
| taxottic_oauth_nonce | Ties the identity token returned by Google or Microsoft to the sign-in you started. | 10 minutes. |
| taxottic_oauth_next | Remembers the page you were heading to so we can return you there after sign-in. | 10 minutes. |
| _oauth_next | The same return-to-page memory, set in the browser for the mobile app and installed-app sign-in path. | 10 minutes. |
| taxottic_last_invite_link | Carries the invite link you just generated across one page reload so it can be shown to you. | Read once, then cleared. |
| taxottic_last_invite_email_status | Carries the result of sending an invite email across one page reload so it can be shown to you. | Read once, then cleared. |
Strictly necessary cookies do not require consent under GDPR because the service cannot function without them. If we ever add an analytics or marketing cookie, you will be asked to consent first and we will list it on this page.