Cookie Policy
How we use cookies and similar technologies
Last updated: 14 March 2026
TL;DR - What You Need to Know
We Use:
- • Essential cookies (authentication, session)
- • Functional cookies (theme, preferences)
- • Security cookies (CSRF protection)
We DON'T Use:
- • Advertising cookies
- • Third-party tracking cookies
- • Social media cookies
- • Analytics that track you across sites
Bottom line: We only use cookies necessary for Owdyn to work. We don't sell your data or track you across the web.
1. What Are Cookies?
Cookies are small text files stored on your device when you visit a website. They help websites remember information about your visit, like your login status, preferences, and settings.
Similar technologies include:
- Local Storage: Browser storage for app data (longer-term than cookies)
- Session Storage: Temporary storage that clears when you close the browser
- Pixels: Tiny images used for tracking (we don't use these)
2. Cookies We Use
Essential Cookies (Required)
These cookies are necessary for Owdyn to function. You can't opt out without breaking the service.
| Cookie Name | Purpose | Duration |
|---|---|---|
| __Secure-next-auth.session-token | Authentication - keeps you logged in | 24 hours |
| __Secure-next-auth.csrf-token | Security - prevents cross-site request forgery attacks | Session |
| __Secure-next-auth.callback-url | Navigation - redirects after sign-in | Session |
Functional Cookies (Optional)
These cookies remember your preferences. You can clear them without affecting login.
| Cookie Name | Purpose | Duration |
|---|---|---|
| theme-preference | Remember if you prefer light or dark theme | 1 year |
| owdyn_trusted_device | Remember trusted devices to reduce 2FA prompts | 30 days |
3. Cookies We DON'T Use
Owdyn doesn't use tracking or advertising technologies. Here's what we specifically avoid:
Advertising Cookies
We don't show ads or track you for advertising purposes. No Google Ads, Facebook Pixel, or similar tracking.
Cross-Site Tracking
We don't track you across other websites. Your Owdyn activity stays in Owdyn.
Social Media Cookies
No Facebook Like buttons, Twitter embeds, LinkedIn widgets, or social tracking. We respect your privacy.
Analytics Tracking
No Google Analytics or similar services that create user profiles. We use basic server logs only (see Privacy Policy).
4. How to Control Cookies
Browser Settings
Most browsers let you control cookies. Here's how to access cookie settings:
- Chrome: Settings → Privacy and Security → Cookies and other site data
- Firefox: Settings → Privacy & Security → Cookies and Site Data
- Safari: Preferences → Privacy → Manage Website Data
- Edge: Settings → Cookies and site permissions → Cookies and site data
Learn more about cookies: AboutCookies.org
Important Note
Blocking essential cookies will prevent you from logging into Owdyn. These cookies are required for authentication and security. Functional cookies (theme, trusted devices) are optional and can be cleared without affecting your ability to use Owdyn.
Owdyn Settings
You can manage some preferences directly in Owdyn (stored as cookies/local storage):
- Change theme (light/dark) in Settings → Preferences
- Manage 2FA trusted devices in Settings → Security
- Clear all preferences by signing out and clearing browser data
5. Cookie Lifespan
Session Cookies
Deleted automatically when you close your browser. Used for:
- CSRF protection (security)
- Callback URLs (navigation after sign-in)
Persistent Cookies
Stay on your device for a set period (or until you manually delete them). Used for:
- Authentication token (24 hours) - keeps you logged in
- Theme preference (1 year) - remembers light/dark mode
- Trusted device (30 days) - reduces 2FA prompts
You can manually delete persistent cookies at any time through your browser settings.
6. Third-Party Cookies
Third-party cookies are set by domains other than Owdyn (e.g., advertisers, analytics companies).
Good News!
Owdyn does NOT use any third-party cookies for tracking or advertising. All cookies set by Owdyn are first-party only (from owdyn.com domain).
There are two exceptions:
- Google OAuth: If you sign in with Google, Google may set cookies to manage that authentication — we don't control or use those for tracking.
- Canny (public roadmap): When you submit in-app feedback, Owdyn calls Canny's API server-side — no Canny scripts or cookies are set on owdyn.com. However, if you visit our public roadmap at owdyn.canny.io directly, Canny may set its own cookies on that domain, governed by Canny's privacy policy.
7. Updates to This Policy
We may update this Cookie Policy from time to time. If we make significant changes (e.g., adding new types of cookies), we'll notify you via:
- Email to your registered address
- In-app notification
- Updated "Last Updated" date at the top of this page
We recommend reviewing this Cookie Policy periodically to stay informed about how we use cookies.
Questions About Cookies?
If you have questions about our use of cookies:
Email: support@owdyn.nz
Legal entity: OWDYN LIMITED (trading as Owdyn)
NZBN: 9429053482907
Address: Auckland, New Zealand
We typically respond within 3 business days.