Cookie policy
Every cookie DropTheDoc sets, what it does, how long it lasts, and why we do not show you a consent banner.
- Effective
- 26 July 2026
- Version
- 1.0
There are four cookies, and all of them are strictly necessary
DropTheDoc runs no advertising cookies, no analytics, no tracking pixels and no third-party trackers of any kind. We set four cookies, all of them required to sign you in and keep you in the right workspace. That is why you are not being asked to accept anything.
1.What cookies are
A cookie is a small text file a website asks your browser to store and send back on later requests. Similar technologies include local storage, which keeps data in the browser without sending it anywhere. This policy covers both.
Cookies are called first-party when the site you are visiting sets them, and third-party when someone else does. Every cookie DropTheDoc sets is first-party.
2.Every cookie we set
Name
dtd_session
Purpose
Keeps you signed in. Holds an opaque random token, never your identity or password. The server stores only a SHA-256 hash of it, so the cookie is useless to anyone who obtains the database.
Type
Strictly necessary
Expires
30 days, or immediately when you sign out or change your password
Attributes
HttpOnly, SameSite=Lax, Secure in production
Name
dtd_workspace
Purpose
Remembers which workspace you were last working in, so you land in the right place. Holds a workspace identifier. Access is still checked against your membership on every request, so this cookie cannot grant access to anything.
Type
Strictly necessary
Expires
1 year
Attributes
HttpOnly, SameSite=Lax, Secure in production
Name
dtd_oauth_state
Purpose
Protects single sign-on against cross-site request forgery by tying the request that starts a sign-in to the response that finishes it. Set only if you sign in with Google, GitHub or Microsoft.
Type
Strictly necessary
Expires
10 minutes, and deleted as soon as sign-in completes
Attributes
HttpOnly, SameSite=Lax, Secure in production
Name
dtd_oauth_next
Purpose
Remembers the page you were heading to before you were asked to sign in, so you are returned there afterwards. Set only during single sign-on.
Type
Strictly necessary
Expires
10 minutes, and deleted as soon as sign-in completes
Attributes
HttpOnly, SameSite=Lax, Secure in production
Every one of these is marked HttpOnly, which means JavaScript on the page cannot read it, and SameSite=Lax, which stops it being sent from another site's request. In production they are also Secure, so they travel only over HTTPS.
3.Local storage
Key
theme
Purpose
Remembers whether you chose light mode, dark mode or your system setting, so the page does not flash the wrong colour on load.
Sent to us?
No. It stays in your browser and is never transmitted.
4.What we do not set
For the avoidance of any doubt, DropTheDoc does not use:
- Advertising or retargeting cookies.
- Analytics of any kind, including Google Analytics, and no product analytics or session replay.
- Social media pixels or share-button trackers.
- Fingerprinting, cross-site or cross-device tracking.
- Third-party cookies. No other party sets a cookie through our pages.
We also do not sell or share personal data collected through cookies, because there is none to sell.
5.Why there is no cookie banner
Article 5(3) of the ePrivacy Directive 2002/58/EC, and the national laws implementing it, require consent before storing information on a user's device, but exempt storage that is strictly necessary to provide a service the user has explicitly requested. Signing you in, and keeping you signed in, is exactly that.
Since every cookie we set falls within that exemption and we run no optional cookies at all, there is nothing for you to consent to and nothing for you to reject. Asking anyway would be theatre. If we ever introduce a non-essential cookie, we will ask for consent before setting it, offer a genuine reject option that is as easy as accepting, and update this page first.
6.Controlling cookies
You can block or delete cookies in your browser settings, usually under Privacy. You can also use private browsing.
What breaks if you block them
Because all four cookies are strictly necessary, blocking them stops you signing in. You will be able to read the public pages, and a recipient can still open a signing link, but the account side of DropTheDoc will not work.
Browser "Do Not Track" and Global Privacy Control signals are respected by default in the sense that there is no tracking to turn off.
7.Changes and contact
If our cookie use changes, we will update the table above and the version at the top of this page, and we will ask for consent first where consent is required. Questions go to privacy@dropthedoc.xyz.
Version history
- Version 1.0 · 26 July 2026
First publication.