This Cookie Policy explains what cookies and similar technologies Billune uses, why we use them, and how you can control them.
1. What Cookies We Use
Billune uses a small, deliberately-minimal set of cookies:
Strictly Necessary
access_token— httpOnly, Secure, SameSite=None. Holds your signed JWT session (7 days). Without it you can't stay logged in.session_token— httpOnly, Secure, SameSite=None. Holds your Emergent Google OAuth session (7 days) if you signed in with Google.
Preference (client-side storage, not a cookie)
billune-theme— stored in your browser's localStorage to remember whether you prefer light or dark theme. Nothing sensitive.
Third-Party Cookies
- When you check out via Stripe, Stripe sets its own cookies on the checkout page for fraud prevention. Those cookies are governed by Stripe's privacy policy.
- We do not use Google Analytics, Facebook Pixel, or any third-party advertising cookies.
2. Email Open Tracking
Invoice emails you send from Billune include a 1×1 tracking pixel so we can tell you when a client opens your invoice ("read receipts"). This is a common transactional-email technique and does not use cookies. See the Privacy Policy for retention details.
3. How to Control Cookies
- You can delete or block cookies via your browser settings.
- If you block the strictly-necessary cookies above, you will not be able to stay signed in.
- To reset your theme preference, clear localStorage for this site.
4. Changes
If we add a new cookie or tracking technology, we will update this page and, if it is more than strictly-necessary, ask for your consent first.
5. Contact
Questions: privacy@billune.app.