Cookie Policy
Last updated 15 July 2026
This policy explains the cookies and similar browser storage that RateHive uses at ratehive.app. In short: we only set cookies that are strictly necessary to sign you in and keep the app working. We do not use advertising or third-party tracking cookies.
1. Strictly-necessary cookies
These are required for authentication and security. Without them you could not sign in or stay signed in, so they are not subject to consent. They are set by our authentication layer (Auth.js) when you sign in.
| Cookie | Purpose | Retention |
|---|---|---|
| authjs.session-token | Keeps you signed in (session token). May be prefixed (__Secure-/__Host-) and split across numbered chunks. | Session / until expiry |
| authjs.csrf-token | Protects sign-in requests against cross-site request forgery. | Session |
| authjs.callback-url | Remembers where to return you after signing in. | Session |
When a paid subscription is involved, our payment processor (Stripe) may set its own cookies on its hosted checkout and billing pages to process payments securely and prevent fraud. Those are governed by Stripe's own policies.
2. Browser storage for preferences
The app also uses your browser's local storage (not cookies, and never sent to a server) to remember interface preferences — for example whether the estimate comment layer is shown and the widths of resizable columns, saved per project. This data stays on your device and is not used to track you.
3. Managing cookies
You can delete or block cookies through your browser settings. Because the cookies above are strictly necessary, blocking them will prevent you from signing in and using the Service.
4. More information
For how we handle personal data more broadly, see our Privacy Policy. Questions? Contact [email protected].