Legal

Cookie policy

Every cookie DropTheDoc sets, what it does, how long it lasts, and why we do not show you a consent banner.

Effective
26 July 2026
Version
1.0

There are four cookies, and all of them are strictly necessary

DropTheDoc runs no advertising cookies, no analytics, no tracking pixels and no third-party trackers of any kind. We set four cookies, all of them required to sign you in and keep you in the right workspace. That is why you are not being asked to accept anything.

1.What cookies are

A cookie is a small text file a website asks your browser to store and send back on later requests. Similar technologies include local storage, which keeps data in the browser without sending it anywhere. This policy covers both.

Cookies are called first-party when the site you are visiting sets them, and third-party when someone else does. Every cookie DropTheDoc sets is first-party.

2.Every cookie we set

Name

dtd_session

Purpose

Keeps you signed in. Holds an opaque random token, never your identity or password. The server stores only a SHA-256 hash of it, so the cookie is useless to anyone who obtains the database.

Type

Strictly necessary

Expires

30 days, or immediately when you sign out or change your password

Attributes

HttpOnly, SameSite=Lax, Secure in production

Name

dtd_workspace

Purpose

Remembers which workspace you were last working in, so you land in the right place. Holds a workspace identifier. Access is still checked against your membership on every request, so this cookie cannot grant access to anything.

Type

Strictly necessary

Expires

1 year

Attributes

HttpOnly, SameSite=Lax, Secure in production

Name

dtd_oauth_state

Purpose

Protects single sign-on against cross-site request forgery by tying the request that starts a sign-in to the response that finishes it. Set only if you sign in with Google, GitHub or Microsoft.

Type

Strictly necessary

Expires

10 minutes, and deleted as soon as sign-in completes

Attributes

HttpOnly, SameSite=Lax, Secure in production

Name

dtd_oauth_next

Purpose

Remembers the page you were heading to before you were asked to sign in, so you are returned there afterwards. Set only during single sign-on.

Type

Strictly necessary

Expires

10 minutes, and deleted as soon as sign-in completes

Attributes

HttpOnly, SameSite=Lax, Secure in production

Every one of these is marked HttpOnly, which means JavaScript on the page cannot read it, and SameSite=Lax, which stops it being sent from another site's request. In production they are also Secure, so they travel only over HTTPS.

3.Local storage

Key

theme

Purpose

Remembers whether you chose light mode, dark mode or your system setting, so the page does not flash the wrong colour on load.

Sent to us?

No. It stays in your browser and is never transmitted.

4.What we do not set

For the avoidance of any doubt, DropTheDoc does not use:

  • Advertising or retargeting cookies.
  • Analytics of any kind, including Google Analytics, and no product analytics or session replay.
  • Social media pixels or share-button trackers.
  • Fingerprinting, cross-site or cross-device tracking.
  • Third-party cookies. No other party sets a cookie through our pages.

We also do not sell or share personal data collected through cookies, because there is none to sell.

6.Controlling cookies

You can block or delete cookies in your browser settings, usually under Privacy. You can also use private browsing.

What breaks if you block them

Because all four cookies are strictly necessary, blocking them stops you signing in. You will be able to read the public pages, and a recipient can still open a signing link, but the account side of DropTheDoc will not work.

Browser "Do Not Track" and Global Privacy Control signals are respected by default in the sense that there is no tracking to turn off.

7.Changes and contact

If our cookie use changes, we will update the table above and the version at the top of this page, and we will ask for consent first where consent is required. Questions go to privacy@dropthedoc.xyz.

Version history

  • Version 1.0 · 26 July 2026

    First publication.