Cookie Notice

Effective 24 August 2026

No analytics, no advertising, no cross-site tracking. Everything we store is needed to sign you in or to remember a preference you set.

A complete list of what we store in your browser, and why. It is short because we do not track you.

1Why there is no cookie banner

Consent banners exist because most sites load third-party trackers before you have agreed to anything. We load none, so under Canadian, European and UK law there is nothing here that requires your consent, and a banner would be friction without purpose.

Everything listed below is either required to sign you in and keep the service secure, or it remembers a preference you set yourself. Nothing tracks you across other websites, and nothing is shared with an advertiser or data broker.

If we ever add analytics or advertising, we will put a real consent banner in place first, with reject as easy as accept, and update this page before anything new is set.

2Cookies we set

The three Cloudflare cookies are set by our infrastructure provider for security. They appear only when the relevant protection is triggered, so you may not see all of them.

NameSet byExpiresPurpose
better-auth.session_tokenFirst partyOn session expiryKeeps you signed in. Without it you would have to log in on every page.
better-auth.session_dataFirst party5 minutesA short-lived cache of your session so that most requests do not need a database lookup.
tersa-setup-doneFirst party1 yearRecords that you finished onboarding, so you are not sent back to the setup screen.
__cf_bmCloudflare30 minutesBot mitigation. Distinguishes real browsers from automated traffic.
_cfuvidCloudflareSessionLets rate limiting tell apart different users sharing one IP address.
cf_clearanceCloudflareSessionRecords that a security challenge was passed, so you are not challenged again.

3What we store in your browser

Cookies are only part of the picture, and most cookie policies quietly omit the rest. These entries live in your browser's local and session storage rather than in cookies, they are never transmitted to us as headers, and they hold preferences rather than identifiers.

KeyStoragePurpose
tersa-favorite-modelsLocalThe models you starred, so they stay at the top of the picker.
tersa-last-modelsLocalThe model you last used for each node type, so new nodes start where you left off.
tersa-recent-modelsLocalYour recently used models, for quick reselection.
tersa-active-canvasLocalWhich canvas you had open, so returning reopens it.
tersa-canvasLocalA legacy local copy of a canvas from an earlier version. Read once, migrated to your account, then removed.
openrouter-code-verifierSessionA one-time proof used to secure connecting your OpenRouter account. Deleted the moment the connection completes.

4Third parties

When you subscribe you are handed off to Stripe's own checkout pages. Stripe sets its own cookies on its own domain to process the payment and prevent fraud; those are covered by Stripe's privacy policy, not ours. We never receive your card details.

Apart from Stripe and Cloudflare, no third party sets anything in your browser on aBuck. There is no Google Analytics, no advertising pixel, no affiliate tracker, no chat widget and no session recorder.

5Your choices

You can clear or block all of this from your browser settings at any time. Blocking the authentication and security cookies will stop you being able to sign in — they are the ones the service genuinely cannot work without. Clearing local storage only loses your model preferences and which canvas reopens; your actual work is stored on your account, not in your browser.

We honour the Global Privacy Control signal by default. That costs us nothing, because we set no advertising or analytics cookies to disable. If you have questions about anything on this page, write to support@abuck.app.