Legal — Cookies

Cookie Policy

The honest version: Bright Ears uses strictly-necessary cookies to keep you signed in securely. We do not run advertising or cross-site tracking cookies, and we do not need a consent banner.

Draft — pending legal review

This document is a working draft and is not yet effective. It has not been reviewed or approved by a lawyer and does not yet govern your use of Bright Ears.

Last updated: June 14, 2026

What they are

What cookies are

Cookies are small files a site stores in your browser. They let a site remember things between page loads — most importantly, that you are signed in. Some serve essential functions; others (which we do not use) track people across sites for advertising.

What we use

The cookies we set (all strictly necessary)

Bright Ears sets only strictly-necessary cookies: authentication/session cookies from our auth provider, Clerk, and a security token to protect against cross-site request forgery. Under the EU ePrivacy Directive and the UK PECR, strictly-necessary cookies are exempt from the consent requirement — so there is no cookie banner. We still disclose them here.

CookieProviderPurposeDuration
__session / __client*ClerkKeeps you securely signed in and maintains your authenticated session.Session / up to ~7 days
__clerk_db_jwtClerkAuth token used to validate your session on each request.Session
CSRF / security tokenBright EarsProtects against cross-site request forgery on form and action submissions.Session

Exact cookie names set by Clerk can vary with their SDK version; the purpose and category above do not change.

Payments

A note on Stripe and checkout

We use Stripe for billing, but our checkout and customer portal are Stripe-hosted— when you subscribe or manage billing, you are redirected to Stripe’s own pages. Stripe’s own cookies (such as __stripe_mid and __stripe_sid) are therefore set on Stripe’s domain, not ours. Bright Ears does not load Stripe’s client-side script on its own pages, so no Stripe cookie is set while you browse Bright Ears.

What we don't use

No advertising, no cross-site tracking

We do not use advertising cookies, cross-site tracking pixels, or third-party marketing trackers, and we do not sell your data. If we ever introduce non-essential cookies (for example, optional analytics), we will update this policy and add a compliant consent mechanism — with Accept-All and Reject-All offered at equal prominence — before any such cookie is set.

Your controls

Managing cookies

You can block or delete cookies in your browser settings. Because our cookies are strictly necessary, blocking them will prevent you from signing in and using the app.

More

Related policies and contact

For the full picture of how we handle personal data, see the Privacy Policy. Questions about cookies can be sent to info@brightears.io.