Cookie Policy
Effective date: 2026-06-15 Last updated: 2026-06-15
This Cookie Policy explains how Essence.Report uses cookies and similar technologies. It forms part of, and should be read with, our Privacy Policy.
What are cookies
Cookies are small text files placed on your device when you visit a website. Similar technologies include localStorage, IndexedDB, and session storage.
Categories we use
Strictly necessary (cannot be disabled)
| Name | Purpose | Provider | Duration |
|---|---|---|---|
__session | Authentication session | Clerk | Session |
__client_uat | Auth state validation | Clerk | 7 days |
__cf_bm | Bot detection (set on Clerk auth domains) | Clerk (via Cloudflare) | 30 min |
_cfuvid | Rate-limit / visitor identifier (Clerk auth domains) | Clerk (via Cloudflare) | Session |
These are required for the Service to function. Disabling them will prevent sign-in.
Functional (browser-stored, no server cookies)
| Storage | Purpose | Duration |
|---|---|---|
theme (localStorage) | Light/dark theme preference | Until cleared |
essence-workspace-draft (localStorage) | Workspace draft autosave | Until cleared or 30 days idle |
essence (IndexedDB) | Local report index | Until cleared |
Clear via browser settings: Settings → Privacy → Clear site data.
Analytics (optional, anonymised)
| Name | Purpose | Provider | Duration |
|---|---|---|---|
PostHog $pageview events | Aggregate page-view counts | PostHog | N/A (event-based) |
We do not use:
- Advertising cookies
- Cross-site tracking
- Fingerprinting
- Third-party tracking pixels
- Session replay (unless explicitly enabled in future with user consent)
Browser controls
Most browsers allow you to:
- See cookies stored
- Delete cookies
- Block all cookies (note: this will disable sign-in)
- Block third-party cookies
- Send a Global Privacy Control (GPC) or "Do Not Track" (DNT) signal (we honour these for optional analytics)
Consent (EEA / UK)
Strictly-necessary cookies are set on the basis of our legitimate interest in operating and securing the Service (and, for authentication, to perform our contract with you). Where required by law in the EEA and UK, we set optional analytics cookies only with your consent — requested when you first visit and adjustable at any time via Settings → Privacy. We also honour a GPC/DNT signal. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.
Updates
Material changes to this Policy will be notified per § 16 (Changes to this Policy) of the Privacy Policy.