Cookie Policy

Last updated Jul 27, 2026

Draft for legal review. This document is a template and has not been reviewed by counsel. Do not treat it as final legal advice until it has been reviewed and finalized.

This Cookie Policy explains how Progma, Inc. ("Progma") uses cookies and similar technologies on our platform and websites (the "Service"). It should be read together with our Privacy Policy.

1. What are cookies?

Cookies are small text files placed on your device when you visit a website. Similar technologies include local storage and session storage. They are widely used to make websites work, to keep you signed in, and to remember preferences.

2. How we use cookies

We use cookies primarily to operate core functionality. Our use falls into the following categories:

  • Strictly necessary cookies. Required for the Service to function. These include authentication and session cookies set by our authentication system (Better Auth), which keep you signed in and protect your session. The Service cannot function properly without these.
  • Preference cookies. Remember choices about how the interface is displayed, such as whether the admin sidebar is expanded.

We do not use analytics or advertising cookies, and we do not use cookies to track you across other websites. Some interface preferences, such as your light/dark theme choice, are stored in your browser's local storage rather than in cookies.

3. Cookies we set

CookieTypeDescriptionDuration
better-auth.session_tokenStrictly necessaryStores the session token that keeps you signed in and secures your sessionSession
better-auth.session_dataStrictly necessaryStores session data when the session cookie cache is enabledSession
better-auth.dont_rememberStrictly necessaryRecords that you chose not to stay signed in ("remember me" disabled)Session
better-auth.two_factorStrictly necessaryIdentifies a pending two-factor authentication challenge between entering your password and entering your code. Signed, and holds only an opaque identifier10 minutes
better-auth.last_used_login_methodStrictly necessaryRemembers your most recent sign-in method to streamline signing in (readable by client-side scripts)Session
progma.admin-sidebar-openPreferenceRemembers whether the admin sidebar is expanded or collapsedPersistent (up to 1 year)

4. Third-party cookies

When you sign in using a third-party identity provider (for example, Google), that provider may set its own cookies subject to its own policies. We do not control third-party cookies.

5. Managing cookies

Most browsers let you view, manage, and delete cookies through their settings. Blocking strictly necessary cookies will prevent you from signing in or using core features. Because the Service relies on authentication cookies to function, it is not designed to operate without them.

6. Changes to this Policy

We may update this Cookie Policy from time to time. Material changes will be indicated by updating the "Last updated" date.

7. Contact

Questions about this Cookie Policy may be sent to support@progma.app.