# Kaabist Cookie Policy

*Version 1.0, effective 10 October 2026.*

Kaabist uses only what is **strictly necessary** to sign you in, protect your session and remember
the choices you make on screen. There are no analytics, advertising or tracking cookies, on the
panel (`app.kaab.ist`), the API (`api.kaab.ist`) or the docs (`docs.kaab.ist`). Because nothing here
is optional, no consent banner is shown.

## Cookies

| Name | Set by | Purpose | Lifetime | Attributes |
|---|---|---|---|---|
| `kaab_session` | API | Keeps you signed in to the panel | 30 days, or until you sign out | `HttpOnly`, `Secure`, `SameSite=Lax` |
| `kaab_csrf` | API | Protects panel requests against cross-site request forgery: the panel reads it and sends it back in a header | 30 days | `Secure`, `SameSite=Lax`; readable by the panel's own script by design |
| Paddle's cookies | Paddle | Checkout, **only on the billing page and only when you open a checkout** | Paddle's policy | See Paddle's cookie policy |

API calls made with an API key use no cookies at all.

## Browser storage

These stay in your browser and are never sent to Kaabist:

| Key | Where | Purpose |
|---|---|---|
| `kaab-color-mode` | panel | Light, dark or system appearance |
| `kaab-docs-color-mode` | docs | The same, on the docs |
| Builder drafts | panel | Unsaved changes to a program you are editing, so a reload does not lose them |
| Provider health history | panel | The recent test results shown on a bring-your-own provider's page |

## Managing them

You can delete cookies and site data in your browser at any time; you will be signed out of the
panel and lose unsaved drafts. Blocking the two Kaabist cookies stops the panel from working; the
API and the docs work without them.

Questions: privacy@kaab.ist.
