Cookie Policy
Last updated: July 19, 2026
What are cookies?
Cookies are small text files that websites store on your device. Browsers also provide similar storage (localStorage and sessionStorage) that this policy covers as well, since European ePrivacy rules apply to any information stored on your device.
Cookies we set
ReviewOps sets only first-party cookies that are strictly necessary for the Service to function or that store a preference you chose yourself. We do not use advertising cookies, tracking pixels, or cross-site analytics, and there is no consent banner because nothing we set requires consent under ePrivacy rules.
- Session cookie (
better-auth.session_token) — keeps you signed in after login. HttpOnly and Secure; expires with your session (30 days). Required for any authenticated page. - Session cache (
better-auth.session_data) — a short-lived, signed copy of your session so pages load without a database round-trip. - Theme cookie (
theme) — your light/dark mode choice, stored for one year so the server can render pages in your chosen theme without a flash. Set only when you pick a theme; contains nothing but the theme name. - Sign-in flow cookies — during passkey or email-code sign-in, our authentication library may set short-lived cookies that hold the in-progress sign-in challenge. They expire within minutes and exist only to complete the sign-in you initiated.
Browser storage we use
- Theme preference (localStorage) — your light/dark mode choice and color preset.
- In-app notice dismissals (localStorage and sessionStorage) — remembers which banners (e.g. the passkey reminder or plan notices) you have dismissed, so they stay dismissed.
- Subscription status cache(sessionStorage) — a five-minute cache of your plan status — and a small flag recording whether your organization has any apps yet — so page navigation doesn’t re-query them.
- Sign-up in progress (sessionStorage) — during the two-step sign-up flow, the name and email you entered are held in sessionStorage between the form and the code-entry step. Cleared when sign-up completes and discarded automatically when the browser tab closes.
- Invitation token (sessionStorage) — if you open a team invitation link before signing in, the invitation token is held in sessionStorage so you land back on the invitation after authenticating. Discarded when the tab closes.
All of these are functional, first-party, and never used for tracking.
Analytics
We measure aggregate website usage using a self-hosted analytics tool (Umami) configured in privacy mode: it sets no cookies at all, visitor identifiers are hashed and rotated daily, and analytics events are never linked to your account. Under ePrivacy guidance from CNIL (France), ICO (UK), and Garante (Italy), this configuration does not require consent.
Payment pages
When you open the upgrade checkout, the payment form is served by our billing provider, Lemon Squeezy, from their domain. Lemon Squeezy may set its own cookies and collect its own telemetry within that checkout, governed by their privacy policy. No Lemon Squeezy code runs on ReviewOps pages until you open the checkout.
Your choices
Because we only use strictly necessary cookies, user-chosen preferences, and functional storage, there is nothing to opt in or out of. You can delete all cookies and site data via your browser settings, but doing so will sign you out of ReviewOps and reset your preferences.
Changes
If we ever add analytics, advertising, or other non-essential cookies, we will update this policy and present a consent banner before setting them.
Contact
Questions about cookies can be sent to [email protected].