Legal
Cookie Policy
Last updated: 5 September 2026 · Version 2026-09-05
Lucreo uses the minimum number of cookies needed to keep you signed in and remember your preferences. We run no advertising or cross-site tracking cookies, and optional measurement cookies only run if you accept them.
1. What cookies are
Cookies are small text files stored by your browser when you visit a site. Similar technologies — such as localStorage and sessionStorage — store data in the browser in the same way. This policy covers both, and forms part of our Privacy Policy. Effective 5 September 2026.
2. Categories we use
Strictly necessary (always on)
Required to sign you in, keep your session valid, protect against cross-site request forgery and remember your consent choice. The Service cannot function without them, so they are set without consent as permitted under the ePrivacy Directive and GDPR.
Preferences (functional)
Remember interface choices such as your selected store, sidebar state and table settings, so the app looks the same when you return.
Analytics (optional — consent required)
Aggregated, first-party measurement of feature usage and errors so we can improve the product. These are only set after you press Accept in the cookie notice, and are never used to build advertising profiles.
Advertising and tracking
We do not use any. Lucreo sets no advertising, retargeting or cross-site tracking cookies, and embeds no third-party ad pixels.
3. Cookies we set
| Name | Type | Purpose | Duration |
|---|---|---|---|
sb-*-auth-token | Strictly necessary | Stores your authenticated session issued by our authentication provider, so you stay signed in between page loads. Held in browser storage on your device. | Until sign-out or expiry (up to 30 days) |
lucreo_consent | Strictly necessary | Records whether you accepted or rejected optional cookies, so we stop asking. | 12 months |
lucreo_store | Preferences | Remembers the store selected in your workspace switcher. | 12 months |
sidebar_state | Preferences | Remembers whether the app sidebar is expanded or collapsed. | 7 days |
__cf_bm, cf_clearance | Strictly necessary | Set by Cloudflare, our edge and security provider, to distinguish humans from bots and mitigate abuse. | 30 minutes to 12 months |
__stripe_mid, __stripe_sid | Strictly necessary | Set by Stripe on billing pages for fraud prevention during checkout. Only present when you visit a payment page. | 30 minutes to 12 months |
4. How to control cookies
- In Lucreo: use the cookie notice shown on your first visit. To change your choice later, delete the
lucreo_consentcookie in your browser settings and reload the page — the notice will reappear. - In your browser: all major browsers let you block or delete cookies for a specific site. Blocking strictly necessary cookies will prevent you from signing in.
- Do Not Track: because we run no cross-site tracking, there is nothing for a DNT or Global Privacy Control signal to disable. We honour them by design.
Rejecting optional cookies does not reduce any Lucreo feature you pay for.
5. Changes and contact
If we add a cookie or a measurement tool, we will update this page and, where consent is required, ask for it before the cookie is set. Questions: privacy@lucreo.io. Third-party providers that may set cookies are listed at /subprocessors.