Cookies
What we actually set
Contract Scanner sets exactly two cookies, both strictly necessary for the site to work at all:
- Session cookie - a random, opaque token that identifies your logged-in session. Without it, you'd be asked to log in on every single page.
- CSRF token cookie - a security token used to confirm that form submissions (login, changing settings, etc.) genuinely came from a page we served you, not a malicious third-party site.
Your light/dark theme preference is remembered in your browser's local storage, not a cookie, and never leaves your device.
Why there's no cookie consent banner
Under the Privacy and Electronic Communications Regulations (PECR), cookies that are "strictly necessary" for a service you've asked for - like staying logged in, or basic security checks - are exempt from the requirement to ask for consent before setting them. Both cookies above fall into that category: the site cannot function as a logged-in application without them, and neither is used for analytics, advertising, or tracking you across other sites. That's a deliberate, current-state assessment, not a shortcut - if that ever changes (analytics, marketing pixels, a payment provider's own cookies), a real consent mechanism needs to be added before those cookies are set, not after.
Third parties
We use Resend to send account/notification emails and, optionally, Telegram's bot API if you link a Telegram account - neither sets cookies in your browser as part of using Contract Scanner. See our privacy policy for how we use these processors.