Cookie Policy
Titanium sets five cookies. All are first-party, all are strictly necessary to sign you in, and none of them track you. This page lists every one.
The short version
We use cookies for one thing: signing you in and keeping the sign-in process safe. We set no analytics cookies, no advertising cookies, and no third-party cookies. The website loads no tracking scripts at all — no Google Analytics, no tag manager, no social pixels, no third-party fonts.
Because every cookie below is strictly necessary to provide a service you asked for, we do not show a cookie consent banner. There is nothing optional to consent to. If we ever add a non-essential cookie, we will ask you first.
Every cookie we set
All five are first-party — set by titanium.day itself, readable by nobody else. All are
marked HttpOnly, so JavaScript in your browser cannot read them, and SameSite=Lax, which stops other sites sending them. In production they are also
marked Secure, so they travel only over HTTPS.
| Cookie | What it does | How long |
|---|---|---|
auth-session | Keeps you signed in. Holds your session token. Also refreshed on requests the mobile app makes, so the app can hold it too. | 30 days, extended while you keep using Titanium |
g_oauth_state | Security. Ties an in-progress Google authorisation — connecting your calendar — to your browser, so a third party cannot complete it in your place. | 10 minutes |
pending-email | Carries your email between the two steps of creating an account. | 15 minutes |
pending-id | Carries the identifier of the account being created between those same two steps. | 15 minutes |
pending-password-hash | Carries the credential created in step one of signup — already hashed, never the password itself — so step two can finish the account. | 15 minutes |
The three pending- cookies exist only during signup and are cleared as soon as
the account is created. g_oauth_state exists only while a Google authorisation is
in flight.
Other things stored on your device
Cookies are not the only local storage a modern app uses, so for completeness. Your sign-in token is of course sent to us with each request — that is what signs you in. Everything else below stays on your device and is sent to nobody:
Signing out clears your token, but the cached screens, the widget data and any cached affirmation audio can remain on the device afterwards. On a shared or borrowed device, delete the app or clear the site data to remove them.
The iOS app and analytics
The iOS app does not use cookies for analytics, but it does include Google Firebase analytics and crash reporting, which identify your installation and your account. That is not cookie technology, so it is not listed above — it is described in full in the Privacy Policy, including how to have it stopped for your account.
Controlling cookies
Every browser lets you view, block and delete cookies, usually under Privacy or Site Settings. You are free to do so — but because our cookies are the mechanism that keeps you signed in, blocking or deleting them will sign you out and prevent you from signing back in. Blocking them does not reduce any tracking, because we do not track you.
We do not need to offer advertising opt-outs, "do not sell" links, or third-party tracker controls, because there are no such trackers to opt out of.
Changes, and contact
If we add, remove or change a cookie, we will update the table above and the date at the top of this page. Questions about anything here: