Cookie Policy
Last updated: 2026-08-11
This is the complete, actual list of cookies Drevia sets today. Every cookie this product uses anywhere is listed here, not a generic template list. There are exactly two, and both exist purely to make the product work. Neither is used for advertising or tracking.
Cookies we set
| Name | Purpose | Details |
|---|---|---|
| drevia.auth | Keeps you signed in. | Strictly necessary. HttpOnly (JavaScript can't read it), SameSite=Strict. Expires after 14 days of inactivity. |
| drevia.csrf | Protects your account from cross-site request forgery attacks. | Strictly necessary. Readable by the page's own JavaScript (required so the app can echo it back as a security header), but never sent anywhere except back to Drevia's own servers. |
What we don't use
No advertising cookies, no third-party tracking pixels, and no analytics cookies. This product doesn't currently run any product analytics tool at all. If that changes in the future, this page (and this product's cookie-consent behavior) will be updated to reflect it honestly, rather than silently starting to track visitors under an unchanged policy.
Why there's no cookie banner
Both cookies above are strictly necessary for the product to function. You can't stay signed in, or safely submit forms, without them. Under most cookie-consent frameworks, strictly-necessary cookies don't require a consent banner. This isn't a legal compliance certification; if you operate this product somewhere with stricter requirements, have that reviewed by counsel.
Questions
See our Contact page, or our Privacy Policy for more on how we handle your data generally.