LEGAL
Cookie Policy
MindPolar sets exactly two cookies. Both are required for the product to function — this policy explains what each one does and why no consent banner is used.
Document status
This document is a draft prepared to describe MindPolar's systems accurately. It is not legal advice, and it requires review by qualified legal counsel before it governs any account, transaction, or data processing.
1
The cookies MindPolar sets
| Cookie | Purpose | Duration | Category |
|---|---|---|---|
| better-auth.session_token | Keeps you signed in between requests. Set the moment you sign in; read on every request to identify your session. | Session-lifetime, matching the platform's session expiry | Strictly necessary |
| mp_last_workspace | Remembers which organization you last worked in, so returning to the app opens the right workspace instead of a picker. Set client-side only; never read by the server for any authorization decision. | Up to 1 year, or until you clear it | Strictly necessary (functional) |
2
Why there is no cookie-consent banner
Under the EU ePrivacy Directive (Art. 5(3)), a cookie that is "strictly necessary" to provide a service the user explicitly requested does not require prior consent — only disclosure, which this page provides. Both cookies above meet that bar: one keeps you signed in (the product cannot function for an authenticated user without it), and the other is a functional convenience with no tracking or advertising purpose and no cross-site use.
A banner is not recommended here — deliberately, not by omission
An unnecessary consent banner is its own UX cost, and this policy does not recommend one reflexively. Counsel should confirm this holds under India's DPDP Rules 2025 consent-manager framework as well as ePrivacy — that framework is newer and less litigated, and its applicability to a two-cookie, no-tracking product is a judgment call rather than a settled reading of the text.
3
No analytics, advertising, or third-party tracking
MindPolar does not use Google Analytics, advertising pixels, session-replay tools, or any other third-party tracking script — verified against the web application's dependencies and rendered pages. Fonts are self-hosted at build time (Next.js's own font optimisation), so no request for a font ever reaches a third party or discloses your IP address to one.
If a third-party analytics or tracking tool is ever added, it will appear in this table with its own category, and — if it is not strictly necessary — this policy's guidance on a consent banner is revisited at that point, not assumed to still hold.
Version history
- v1.0.0Pending — not yet published
Initial draft, pending legal review.