Legal
Cookie policy
Last updated 25 September 2026
Draft. This text is a working draft pending legal review, and the company details are still to be confirmed. It describes how Caseta works today; it will be updated before launch.
Cookies are small text files a website stores in your browser. Caseta uses only a handful, all set by Caseta itself (first-party), to keep you signed in and remember your preferences. We don't use analytics, advertising or tracking cookies, and we don't share cookie data with anyone.
The cookies we use
| Name | Purpose | Type | Duration |
|---|---|---|---|
caseta-web.session_token | Keeps you signed in to Caseta. HTTP-only, so page scripts can't read it. | Strictly necessary | 7 days, renewed while you use Caseta; removed when you sign out |
caseta-admin.session_token | The same, for the Caseta team's admin area. | Strictly necessary | 7 days, renewed while in use; removed on sign-out |
caseta-web.pending_email | Remembers which address we just sent a confirmation link to, so the next page can show it and let you ask for a new link. HTTP-only. | Strictly necessary | 15 minutes |
caseta-theme | Remembers whether you chose the light, dark or system display. When you're signed in, your account's choice is copied here. | Preference | 1 year |
caseta-appearance | Remembers your accent colour and density for your account's pages, so they show straight away. Copied from your account when you sign in. | Preference | 1 year |
sidebar_state | Remembers whether the admin sidebar is open or collapsed (admin area only). | Preference | 7 days |
caseta-web.two_factorcaseta-admin.two_factor | Holds a sign-in in progress while you enter your two-factor code (only if you use two-factor authentication). HTTP-only. | Strictly necessary | 10 minutes |
caseta-web.two_factor_setupcaseta-admin.two_factor_setup | Holds the setup of two-factor authentication while you scan the QR code and enter the first code. Encrypted and HTTP-only. | Strictly necessary (set only when you turn two-factor on) | 10 minutes, removed when the setup finishes |
caseta-web.passkey_challengecaseta-admin.passkey_challenge | Holds the one-time challenge while you add a passkey or sign in with one, so your device's answer can be checked. HTTP-only. | Strictly necessary (set only when you use a passkey) | 5 minutes |
caseta-web.trust_devicecaseta-admin.trust_device | Remembers that you asked to trust this device, so signing in skips the two-factor step. HTTP-only. | Strictly necessary (set only when you choose it) | 30 days, renewed when you sign in |
On the live site the sign-in cookies are sent over HTTPS only, and their names start with __Secure- (for example __Secure-caseta-web.session_token).
Why there is no cookie banner
Under the EU ePrivacy rules and Spain's LSSI-CE, cookies that are strictly necessary for a service you asked for (such as staying signed in), or that only remember a choice you made (such as dark mode), don't need prior consent. Caseta uses no other kind. If that ever changes, we'll ask for your consent first and update this page.
Managing cookies
You can delete or block cookies in your browser settings. If you block the sign-in cookies you won't be able to sign in; if you delete the display cookie, Caseta falls back to your device's light / dark setting.
For how we handle personal data in general, see the privacy policy.