Cookie Notice
Effective 24 August 2026
No analytics, no advertising, no cross-site tracking. Everything we store is needed to sign you in or to remember a preference you set.
A complete list of what we store in your browser, and why. It is short because we do not track you.
1Why there is no cookie banner
Consent banners exist because most sites load third-party trackers before you have agreed to anything. We load none, so under Canadian, European and UK law there is nothing here that requires your consent, and a banner would be friction without purpose.
Everything listed below is either required to sign you in and keep the service secure, or it remembers a preference you set yourself. Nothing tracks you across other websites, and nothing is shared with an advertiser or data broker.
If we ever add analytics or advertising, we will put a real consent banner in place first, with reject as easy as accept, and update this page before anything new is set.
2Cookies we set
The three Cloudflare cookies are set by our infrastructure provider for security. They appear only when the relevant protection is triggered, so you may not see all of them.
| Name | Set by | Expires | Purpose |
|---|---|---|---|
| better-auth.session_token | First party | On session expiry | Keeps you signed in. Without it you would have to log in on every page. |
| better-auth.session_data | First party | 5 minutes | A short-lived cache of your session so that most requests do not need a database lookup. |
| tersa-setup-done | First party | 1 year | Records that you finished onboarding, so you are not sent back to the setup screen. |
| __cf_bm | Cloudflare | 30 minutes | Bot mitigation. Distinguishes real browsers from automated traffic. |
| _cfuvid | Cloudflare | Session | Lets rate limiting tell apart different users sharing one IP address. |
| cf_clearance | Cloudflare | Session | Records that a security challenge was passed, so you are not challenged again. |
3What we store in your browser
Cookies are only part of the picture, and most cookie policies quietly omit the rest. These entries live in your browser's local and session storage rather than in cookies, they are never transmitted to us as headers, and they hold preferences rather than identifiers.
| Key | Storage | Purpose |
|---|---|---|
| tersa-favorite-models | Local | The models you starred, so they stay at the top of the picker. |
| tersa-last-models | Local | The model you last used for each node type, so new nodes start where you left off. |
| tersa-recent-models | Local | Your recently used models, for quick reselection. |
| tersa-active-canvas | Local | Which canvas you had open, so returning reopens it. |
| tersa-canvas | Local | A legacy local copy of a canvas from an earlier version. Read once, migrated to your account, then removed. |
| openrouter-code-verifier | Session | A one-time proof used to secure connecting your OpenRouter account. Deleted the moment the connection completes. |
4Third parties
When you subscribe you are handed off to Stripe's own checkout pages. Stripe sets its own cookies on its own domain to process the payment and prevent fraud; those are covered by Stripe's privacy policy, not ours. We never receive your card details.
Apart from Stripe and Cloudflare, no third party sets anything in your browser on aBuck. There is no Google Analytics, no advertising pixel, no affiliate tracker, no chat widget and no session recorder.
5Your choices
You can clear or block all of this from your browser settings at any time. Blocking the authentication and security cookies will stop you being able to sign in — they are the ones the service genuinely cannot work without. Clearing local storage only loses your model preferences and which canvas reopens; your actual work is stored on your account, not in your browser.
We honour the Global Privacy Control signal by default. That costs us nothing, because we set no advertising or analytics cookies to disable. If you have questions about anything on this page, write to support@abuck.app.