Cookie Policy
Last updated: September 16, 2026 · Effective: upon publication
1. What cookies are
Cookies are small files a site stores on your device. Similar technologies (local storage, pixels, SDKs) work the same way. This policy explains which we use, why, and how to control them. It supplements our Privacy Policy.
2. Our approach
Seshat is built to use as few cookies as possible — primarily the ones needed to sign you in and keep your account secure. We do not use advertising or cross-site tracking cookies, we do not sell or "share" your information for advertising, and cookies are never tied to the contents of your email.
3. Categories we use
| Cookie / item | Purpose | Category | Duration |
|---|---|---|---|
| Session | Keeps you signed in securely | Strictly necessary | Session |
| CSRF token | Protects forms from forgery | Strictly necessary | Session |
| Preferences | Remembers settings like theme | Functional | 12 months |
4. Consent
Strictly necessary cookies don't require consent — the service can't run without them. Where required by law (e.g., the EU/UK ePrivacy rules), we set non-essential cookies (functional) only after you consent through our cookie banner, and you can change or withdraw consent any time via "Cookie settings" in the site footer. We honor Global Privacy Control (GPC) signals where applicable.
5. Analytics & third parties
We use a privacy-preserving, first-party analytics measure on our public marketing pages to understand aggregate traffic — page views, approximate visitor counts, referring site, and device type. It sets no cookies, uses no third-party analytics provider, and stores no IP addresses or identifiers: each visit is counted through an anonymous, non-reversible hash that resets daily, so it cannot track you across days or across sites, and it is never applied to the signed-in vault. Some strictly necessary cookies are still set by infrastructure providers (e.g., our CDN and hosting provider) listed on our Subprocessors page. We don't permit third-party advertising trackers. Remote images in your archived email are loaded through our own server rather than fetched directly from the sender, so a sender's tracking pixel cannot set a cookie in your browser or see your IP address.
6. Managing cookies
You can block or delete cookies in your browser settings and use our cookie banner to control non-essential categories. Blocking strictly necessary cookies will prevent sign-in and the vault from working. California residents can exercise opt-out rights as described in our Privacy Policy.
7. Changes & contact
We'll update this policy as our cookie use changes and revise the date above. Questions: [email protected].