Legal
Cookie Policy
Effective date: September 21, 2026
This is the current Cookie Policy of Broctic Inc. It explains the cookies and similar browser storage used on broctic.com and in the Broctic console.
Summary
Cookies are small files a website stores in your browser; local storage is a similar mechanism that stays on your device and is not sent to our servers. We group what we use into two categories:
- Necessary — always on. Needed to sign you in, keep the service secure, and remember choices you make, including your cookie choice.
- Analytics — off until you accept. Would help us understand how the website is used. Today we do not load any analytics or advertising scripts on broctic.com, so accepting this category currently sets nothing. If we add an analytics tool, it will run only if you have opted in, and we will list it here first.
What we set
| Name | Purpose | Duration | Category |
|---|---|---|---|
| __Secure-better-auth.session_tokenCookie | Keeps you signed in after you log in. | 7 days, renewed while you use Broctic | Necessary |
| __Secure-better-auth.session_dataCookie | Short-lived signed copy of your session so each request does not hit the database. | 5 minutes | Necessary |
| better-auth state / PKCE cookiesCookie | Protect the GitHub and Google sign-in flow against tampering (CSRF/PKCE). | Removed when sign-in completes | Necessary |
| broctic_sidebarCookie | Remembers whether the console sidebar is expanded or collapsed. | 1 year | Necessary |
| broctic.cookie-consentLocal storage | Records your cookie choice so we don't ask again. | Until you clear it or change your choice | Necessary |
| themeLocal storage | Remembers light or dark mode in the signed-in console. | Until you clear it | Necessary |
| broctic.currency, broctic.range, broctic.research.*Local storage | Remember display preferences in the console (currency, date range, research filters). | Until you clear it | Necessary |
Sign-in cookies are HttpOnly, Secure and SameSite=Lax, and are set on .broctic.com so the website, console and API share one session. Cookie names may differ slightly outside production (for example, without the __Secure- prefix).
Third-party cookies
Broctic’s own pages do not set third-party cookies. When you choose to sign in with GitHub or Google, or connect a service such as Apple, Instagram or TikTok, you are taken to that provider’s site, which may set its own cookies under its own policy. The in-browser app preview in the Studio is provided by Expo Snack, which is loaded from Expo and may use its own storage.
Changing your choice
You can change your choice at any time using the Cookie settings link in the footer of every page. Withdrawing consent stops optional analytics from then on. You can also clear or block cookies and local storage in your browser settings; blocking necessary cookies will prevent you from signing in. Signing out removes your session cookies.
More information
For how we handle personal data more broadly, see our Privacy Policy. Questions? Email irennie@broctic.com.