SpendlyBack to Spendly
Browser storage

Cookie Policy

Spendly uses necessary storage for secure authentication, language and interface preferences, and remembering your privacy choice. Optional analytics is disabled until you allow it.

Last updated: 22 July 2026

1. What cookies are

Cookies are small text values stored by your browser. Similar browser storage, such as local storage, can remember interface preferences on your device. Some cookies are necessary for a requested service; optional analytics or advertising cookies require a separate choice.

2. Storage currently used

StoragePurposeTypical duration
Firebase authentication storageMaintain the signed-in state and refresh the selected email, Google, or Apple session safely on this deviceSession-dependent; removed when you sign out or clear site data
__Host-spendly_idProvide a short-lived, HttpOnly copy of an already verified Firebase ID token for private server-rendered pages; it never contains a refresh tokenNo later than the current ID token expiry
__Host-spendly_legacy_proofCarry a one-time, HttpOnly proof while an existing customer explicitly links an earlier account to the new Firebase identity5–10 minutes or until consumed
Temporary legacy authentication storageSupport an existing customer who deliberately chooses the controlled account-migration sign-in; it is not used for new accountsOnly for the migration session
spendly_cookie_noticeRemember that the essential-cookie notice was dismissedUp to 12 months
spendly_analytics_consentRemember whether optional Google Analytics is allowed or declinedUp to 12 months
Language and interface storageRemember the language and local UI preferences selected on the deviceUntil cleared or replaced

3. Optional analytics

Spendly does not load Google Analytics, behavioural advertising, or cross-site tracking until you choose “Allow analytics”. If you choose “Only necessary”, optional analytics remains disabled.

Public Resources may send limited first-party, cookieless engagement events to Spendly. They contain no direct account identifier, raw search term, or cross-site identifier and do not write browser storage.

When enabled, Google Analytics measures public page views and selected resource interactions. Spendly does not configure advertising features and does not send account, workspace, financial, or raw search data.

4. Controls

You can remove cookies and local storage in your browser settings. Blocking authentication cookies may prevent login or cause the dashboard to stop working. You can reopen the notice below.

5. Contact

Questions about browser storage or privacy may be sent to privacy [at] spendly.team.