Cookie Policy
Last updated: 25 August 2026
This page lists every cookie FinanceFlow sets and explains what each one is for. The list is short, because the service only uses cookies it needs in order to work.
Cookies we set
All of the cookies below are strictly necessary: they are what makes signing in possible and keeps that sign-in secure. They are set by the application itself, not by anyone else.
- Session cookie. Created when you sign in and holds your signed session token. It is what tells the application, on each request, that you are you. Deleting it signs you out.
- CSRF token cookie. Set on the sign-in and sign-out forms. It protects those forms against cross-site request forgery, where another site tries to submit a request as you.
- Callback URL cookie. Short-lived. It remembers the page you were trying to reach when you were asked to sign in, so you can be returned there afterwards.
What we do not use
FinanceFlow sets no analytics cookies, no advertising cookies and no tracking pixels. There is no Google Analytics, no advertising network and no social media tracker in the application. Nobody outside the service is given the ability to set a cookie through it.
Because every cookie we set is strictly necessary for a service you asked for, no consent banner is presented. If analytics or similar tools are added in future, this page will be updated first and consent will be requested where the law requires it.
Other browser storage
Your choice of light or dark appearance is kept in your browser’s local storage rather than in a cookie. It never leaves your device and is not sent to the service with your requests. Clearing your browser’s site data resets it to the default.
Managing cookies
Every browser lets you view, block and delete cookies through its settings. Because the cookies listed above are what carry your sign-in, blocking or deleting them will sign you out and prevent you from using the application until they are allowed again.
More information
For how information is handled once you are signed in, see the Privacy Policy. For questions about this page, use our contact page.