Cookie Policy
Every cookie and browser storage key the SpaltX platform sets, what each one holds, how long it lives, and how to clear it.
Contents · 8 sections
Plain-language overview. Almost everything we set exists so that signing in works, and how many of those cookies you get depends on whether you use a second factor or a passkey. The exceptions are small records of a choice you made in the interface, such as the staff sidebar being collapsed or a search box remembering what you last typed. There are no advertising or analytics cookies anywhere on the site, so the brief notice on your first visit is an acknowledgment, not a consent request.
Summary only. The numbered sections below are the document.
Our approach
Almost everything the Platform sets exists so that signing in works. These claims hold without qualification:
- No advertising cookies and no ad networks.
- No third-party analytics and no session-replay recording.
- No social media trackers and no cross-site tracking of any kind.
- Nothing we set is sold or shared, and none of it builds a profile of you.
The cookies that sign you in are httpOnly where the browser allows it, so page scripts cannot read them. One cookie is not: adm-rail is written by the staff console in the browser and any script on an admin page could read it. It holds the digit 0 or 1 and nothing else, so there is nothing in it to identify anyone by.
Sign-in cookies are strictly necessary for something you asked us to do, which is the category cookie-consent laws exempt. adm-rail is a preference rather than a necessity, and we do not claim the exemption covers it by right. What we rely on instead is narrower: it is written only when a staff member clicks the control that collapses the rail, on an internal console nobody reaches without a staff sign-in. Clicking that control again undoes it. Nobody is given it for browsing the public site.
The brief notice on your first visit is therefore informational rather than a consent gate: there is no advertising or analytics here for a reject button to switch off. If we ever add a category that genuinely requires consent, we will ask for it before setting it and update this policy.
Other browser storage
A few things are kept in localStorage instead of a cookie. Storage of that kind is never attached to a request, so it stays on your device and our servers never receive it.
| Key | What it holds | Who gets it |
|---|---|---|
spaltx_cookie_notice | That you dismissed the notice at the bottom of the page, so you are not shown it again. This is why the notice itself adds no cookie. | Anyone |
spaltx.recent-searches* | The last few things you typed into a search box, so the box can offer them back to you. Your own words, kept on your own device and never sent to us as history. The account area and the staff console keep their own under spaltx.recent-searches.account and spaltx.recent-searches.admin. | Anyone who uses search |
spaltx.help-feedback.* | That you already answered the was-this-helpful prompt on a given article, so it is not asked twice. One entry per article, and it records that you answered rather than what you answered. | Anyone reading help articles |
forge:maximized | Whether a staff design studio was left running full screen. | Staff |
forge:start:pins | Which documents a staff member pinned on a design studio start screen. | Staff |
Clearing site data for our domain removes all of them. Recent searches have their own control: open a search box and use Clear beside the recent list.
Bot protection and links to other sites
Nothing on this site loads a script from another company. No advertising network or analytics vendor can set a cookie here, and no social platform learns that you visited.
One piece of infrastructure is worth naming plainly. Our host runs bot protection in front of signing in and the forms that reach a person here, and it can set a first-party cookie whose name begins with KP_ to tell a real browser from an automated one. The host sets that cookie rather than us, so its exact lifetime is not ours to state. It is there to keep automated traffic off the surfaces a person has to answer.
Where a page here links out, the site you land on has its own cookie practices and its own notice, and neither is ours to speak for.
Managing cookies
Your browser gives you full control over cookies: you can inspect them, delete them, and block them per site (look under Privacy or Site Settings in the browser menu). What blocking costs you here depends on which one you block:
- Blocking or deleting the sign-in cookies signs you out and prevents signing in.
- Deleting
better-auth.trust_devicemeans the next sign-in asks for your authenticator code again, which is the safe outcome, not a broken one. - Deleting
adm-railcosts a staff member one collapsed sidebar. Nothing else notices. - Reading the public site, including the blog, works fine without any cookies.
Signing out removes the cookies that carry your session. It deliberately leaves better-auth.trust_device in place, since the point of that one is to be remembered by a browser you told us to trust. On a shared or borrowed machine, clear site data rather than relying on signing out.
Clearing site data for our domain removes everything we ever set, cookies and browser storage alike. The cookie notice will appear again on your next visit, because the record of you having dismissed it is one of the things you just cleared.
Do Not Track and Global Privacy Control
These signals ask a site to stop tracking you across the web, and none of what they turn off happens here. There are no advertising identifiers on this domain and no sale or sharing of personal data. Where a law treats a Global Privacy Control signal as a formal opt-out, we honor it, and you should expect to see no difference. Our Privacy Policy covers this in more detail.
Changes and contact
When we add a cookie or a new kind of browser storage, it gets a row in one of the tables above and the effective date at the top of this page moves. Material changes, such as any category that would require consent, get advance notice on the Platform.
Questions about cookies go to support@spaltx.com with COOKIES in the subject line.
