Cookie policy
Last updated 15 August 2026
The full list — there are not many, and only the analytics ones need your permission.
1. What we mean by cookies
“Cookies” here covers cookies proper and the two other things a site can keep in your browser: local storage and session storage. The rules are the same for all three, so we list all three.
2. Strictly necessary — always on
These make the site work. They are not used to profile you, and there is no way to switch them off and still have an account.
- better-auth.session_token — your signed-in session. A cookie, set when you sign in, deleted when you sign out, and otherwise expiring after 7 days. HTTP-only, so scripts on the page cannot read it.
- omniio-theme — local storage, not a cookie. Remembers whether you chose light, dark or system so the page does not flash the wrong colours on load. Stays until you clear your browser data.
- omniio-consent — local storage. Records the answer you gave the cookie banner, so we can honour it and stop asking. Without it we would have to show the banner on every page.
That is the whole list. When an MCP client authorises against Omniio, or when you connect an upstream server, the session cookie above is the only one involved — the OAuth state and the PKCE verifier for those flows are held server-side in our database, not in your browser.
3. Analytics and measurement — only with consent
Nothing in this section loads until you press “Accept” on the banner. If you decline, or simply never answer, the scripts are never added to the page and none of these cookies are set.
- Google Analytics 4 — _ga and _ga_<id>, up to 2 years. Tells us which pages people read and roughly where they arrived from, so we know what to write more of. Set by Google, which we run in consent mode with everything denied until you say otherwise; IP addresses are truncated and we have advertising features switched off.
- Meta Pixel — _fbp, up to 3 months, plus _fbc if you arrived from a Meta ad. Measures whether an advert led to a sign-up. Set by Meta.
Both are third-party services with their own privacy notices, and both act as processors for the measurement they do for us. Our privacy policy explains what that means for your data.
4. What we measure without any cookie
Vercel Web Analytics counts page views for us. It sets no cookie, stores no identifier in your browser and does not follow you between sites, so it runs whatever you choose above. It is aggregate traffic data and nothing more.
Our servers also keep ordinary request logs — the sort every web server keeps — for security and debugging. Those are not cookies and you cannot turn them off, but they are short-lived.
5. What we do not do
We do not sell your data, we do not run advertising cookies of our own, and we do not embed third-party trackers beyond the two named above. The signed-in application sets no analytics cookie at all: measurement is confined to the public marketing pages.
6. Changing your mind
Your choice is not permanent. Reopen the banner and pick again — the new answer replaces the old one immediately, and declining after having accepted also clears the cookies that were set.
You can also delete cookies and site data for omniio.dev in your browser’s settings, which resets everything including your theme and your consent record. Most browsers additionally offer a “do not track” or blocking mode, and we honour Global Privacy Control where your browser sends it.
7. Changes to this policy
If we add a cookie, it will be listed here before it is set, and the date at the top will change. Questions go to sales@omniio.dev.