Cookie Policy

Draft — pending legal review before public launch. Last updated: July 17, 2026

This page lists the cookies Mintward uses and how to control them. It sits alongside our Privacy Policy, which covers everything else we collect.

What are cookies?

Cookies are small text files a site stores in your browser. Some are essential — they're how a site remembers you're logged in from one page to the next. Others are optional and used for things like analytics. We keep ours to a minimum.

Cookies we use

NamePurposeDurationCategory
next-auth.session-tokenKeeps you signed in after you log in.Up to 30 daysStrictly Necessary
next-auth.csrf-tokenProtects sign-in against cross-site request forgery.SessionStrictly Necessary
next-auth.callback-urlRemembers where to send you after a successful sign-in.SessionStrictly Necessary
mtw_tdRemembers a device you marked "trusted" so you can skip the MFA code on it. Only set if you tick "remember this device".30 daysFunctional

Over HTTPS, the next-auth.* cookies carry a __Secure- or __Host- prefix — a browser hardening detail; their purpose is unchanged. “Session” means the cookie is cleared when you close your browser.

Third-party cookies

None. We don't run third-party advertising or analytics cookies. If we add site analytics, we plan to use a cookieless, privacy-first tool. Note that if you reach Square's hosted checkout to manage billing, Square may set its own cookies on its pages, governed by Square's privacy terms.

Managing cookies

You can block or delete cookies from your browser's settings — see the help pages for Chrome, Safari, or Firefox. Because our essential cookies are how sign-in works, disabling them means you won't be able to log in or stay logged in.

Changes and contact

We'll update this page if the cookies we use change; material changes get the same 14-day notice described in our Privacy Policy. Questions go to support@mintward.app.