Cookie policy
Cookie policy
2026-09 · The Spanish version governs where both exist.
The only cookie we set
dm_session, strictly necessary, httpOnly, Secure and SameSite=Lax, with a 30-day sliding expiry. It holds a session token that keeps you logged in. It is exempt from consent under Spanish AEPD guidance because the service cannot function without it, and it is never used for tracking.
Storage on your device that is not a cookie
Your browser's local storage holds the material used to decrypt your own conversations (a key derived on your device from your master key) and your local conversation cache. It stays on your device, is transmitted only as ciphertext, and disappears if you clear your browser data. This is strictly necessary functionality, not tracking.
What we do not use
No tracking cookies, no advertising pixels, no fingerprinting, no third-party scripts on this domain. Analytics, when enabled, is self-hosted, cookieless and never joined to accounts; it sets no cookies and stores no identifiers.
Because only strictly necessary storage is used, you will not see a cookie-consent banner on this site.