Skip to content

Cookie Policy

Every cookie and browser storage key the SpaltX platform sets, what each one holds, how long it lives, and how to clear it.

Effective July 30, 2026
Contents · 8 sections

Plain-language overview. Almost everything we set exists so that signing in works, and how many of those cookies you get depends on whether you use a second factor or a passkey. The exceptions are small records of a choice you made in the interface, such as the staff sidebar being collapsed or a search box remembering what you last typed. There are no advertising or analytics cookies anywhere on the site, so the brief notice on your first visit is an acknowledgment, not a consent request.

Summary only. The numbered sections below are the document.

01

What cookies are

Cookies are small text records a website asks your browser to store and send back on later requests. They are the standard way a site remembers that you are signed in as you move between pages. Related technologies (localStorage and similar browser storage) can serve the same role, and this policy covers those too. What we set falls into two kinds: the cookies that signing in needs, and the small records that remember a choice you made in the interface. Both are listed below by name.

02

Our approach

Almost everything the Platform sets exists so that signing in works. These claims hold without qualification:

  • No advertising cookies and no ad networks.
  • No third-party analytics and no session-replay recording.
  • No social media trackers and no cross-site tracking of any kind.
  • Nothing we set is sold or shared, and none of it builds a profile of you.

The cookies that sign you in are httpOnly where the browser allows it, so page scripts cannot read them. One cookie is not: adm-rail is written by the staff console in the browser and any script on an admin page could read it. It holds the digit 0 or 1 and nothing else, so there is nothing in it to identify anyone by.

Sign-in cookies are strictly necessary for something you asked us to do, which is the category cookie-consent laws exempt. adm-rail is a preference rather than a necessity, and we do not claim the exemption covers it by right. What we rely on instead is narrower: it is written only when a staff member clicks the control that collapses the rail, on an internal console nobody reaches without a staff sign-in. Clicking that control again undoes it. Nobody is given it for browsing the public site.

The brief notice on your first visit is therefore informational rather than a consent gate: there is no advertising or analytics here for a reject button to switch off. If we ever add a category that genuinely requires consent, we will ask for it before setting it and update this policy.

04

Other browser storage

A few things are kept in localStorage instead of a cookie. Storage of that kind is never attached to a request, so it stays on your device and our servers never receive it.

Browser storage written by the Platform
KeyWhat it holdsWho gets it
spaltx_cookie_noticeThat you dismissed the notice at the bottom of the page, so you are not shown it again. This is why the notice itself adds no cookie.Anyone
spaltx.recent-searches*The last few things you typed into a search box, so the box can offer them back to you. Your own words, kept on your own device and never sent to us as history. The account area and the staff console keep their own under spaltx.recent-searches.account and spaltx.recent-searches.admin.Anyone who uses search
spaltx.help-feedback.*That you already answered the was-this-helpful prompt on a given article, so it is not asked twice. One entry per article, and it records that you answered rather than what you answered.Anyone reading help articles
forge:maximizedWhether a staff design studio was left running full screen.Staff
forge:start:pinsWhich documents a staff member pinned on a design studio start screen.Staff

Clearing site data for our domain removes all of them. Recent searches have their own control: open a search box and use Clear beside the recent list.

05

Bot protection and links to other sites

Nothing on this site loads a script from another company. No advertising network or analytics vendor can set a cookie here, and no social platform learns that you visited.

One piece of infrastructure is worth naming plainly. Our host runs bot protection in front of signing in and the forms that reach a person here, and it can set a first-party cookie whose name begins with KP_ to tell a real browser from an automated one. The host sets that cookie rather than us, so its exact lifetime is not ours to state. It is there to keep automated traffic off the surfaces a person has to answer.

Where a page here links out, the site you land on has its own cookie practices and its own notice, and neither is ours to speak for.

06

Managing cookies

Your browser gives you full control over cookies: you can inspect them, delete them, and block them per site (look under Privacy or Site Settings in the browser menu). What blocking costs you here depends on which one you block:

  • Blocking or deleting the sign-in cookies signs you out and prevents signing in.
  • Deleting better-auth.trust_device means the next sign-in asks for your authenticator code again, which is the safe outcome, not a broken one.
  • Deleting adm-rail costs a staff member one collapsed sidebar. Nothing else notices.
  • Reading the public site, including the blog, works fine without any cookies.

Signing out removes the cookies that carry your session. It deliberately leaves better-auth.trust_device in place, since the point of that one is to be remembered by a browser you told us to trust. On a shared or borrowed machine, clear site data rather than relying on signing out.

Clearing site data for our domain removes everything we ever set, cookies and browser storage alike. The cookie notice will appear again on your next visit, because the record of you having dismissed it is one of the things you just cleared.

07

Do Not Track and Global Privacy Control

These signals ask a site to stop tracking you across the web, and none of what they turn off happens here. There are no advertising identifiers on this domain and no sale or sharing of personal data. Where a law treats a Global Privacy Control signal as a formal opt-out, we honor it, and you should expect to see no difference. Our Privacy Policy covers this in more detail.

08

Changes and contact

When we add a cookie or a new kind of browser storage, it gets a row in one of the tables above and the effective date at the top of this page moves. Material changes, such as any category that would require consent, get advance notice on the Platform.

Questions about cookies go to support@spaltx.com with COOKIES in the subject line.

The whole policy in one sentence
Everything we set either signs you in or remembers a choice you made in the interface, and none of it is watching you or reporting to anyone else.
Cookie Policy | SpaltX