01At a glance
- We set one cookie. It is called
mokara_token— prefixed__Host-in production — it keeps you signed in, and it lasts seven days. - No analytics, advertising, social or performance cookies. No third party sets a cookie through our pages, because no third party appears on them.
- No cookie consent banner — deliberately. The single cookie is strictly necessary to provide the feature you asked for, which is the exemption every sensible e-privacy regime recognises. Section 4 explains it.
- No other storage on your device. No
localStorage, nosessionStorage, no IndexedDB, no service worker. Nothing is written to your browser except that one cookie. - If this ever changes — an analytics tool, a preference stored between visits, a first-party measurement script — this page gains a row, a consent banner appears first, and the date at the top moves.
05Other storage on your device: none
Checked against the code, item by item:
localStorage/sessionStorage— not used. Interface preferences such as which task group is collapsed or which filter is active live in memory for the session, and reset when you close the tab.- IndexedDB / Cache Storage — not used. There is no offline mode and no local database.
- Service worker — none. Mokara cannot run in the background on your device, and there is no push-notification channel.
- Canvas and WebGL fingerprinting — none. The animated background on the landing page is a generated shader; pointer position drives parallax locally and is never transmitted or stored.
- Cookies on the landing page for visitors who are not signed in — none. Browsing the marketing pages sets nothing at all; the cookie appears only when you log in or sign up.
06Third-party cookies, scripts and requests
No third party sets a cookie through our pages, and loading our pages does not make your browser ask anyone else for anything. There is no analytics script, no advertising pixel, no social embed, no video embed, no map, no chat widget, no A/B-testing tool and no error reporting service. Even the webfonts are served from our own origin rather than a font CDN, so a page view does not leak your visit to Google.
Requests the browser does make go to our own API under the same origin, and the response headers allow-credentials only for origins the operator has configured. The images of the product on our landing page are screenshots stored as files on our server, not embedded previews of your own data.
A self-hosted instance is stricter still
Because nothing in the software calls out to us, an installation behind your firewall issues no third-party requests at all. Your browser will not contact our servers unless you point it there.
07Controlling, blocking and deleting the cookie
You can block or delete cookies in your browser at any time; it is your browser and your machine. Blocking a strictly necessary cookie does not make you safer, it just makes the product unusable — but the choice is yours and here is what each route costs:
| Browser | Where the setting is | Effect of blocking mokara_token |
|---|---|---|
| Chrome / Edge | Settings → Privacy and security → Cookies and other site data | You cannot sign in, or you are signed out on the next request. |
| Safari | Settings → Privacy → Manage Website Data | Same — the session cannot be established. |
| Firefox | Settings → Privacy & Security → Cookies and Site Data | Same. Blocking all cookies also breaks other sites, which is why per-site exceptions are the better tool. |
| Any browser, one-off | The padlock or site-information icon in the address bar → cookies for this site → remove | Signed out immediately, as if you had pressed Sign out. |
7.1Private and incognito browsing
Works normally. The cookie exists only for that window and is destroyed when you close it, which is the cheapest way to use a shared or borrowed computer. On any device that is not yours, always sign out rather than relying on the window closing.
7.2What still happens if you block it
The landing, sign-up and login pages remain readable. Anything behind sign-in returns to the login screen, because an unauthenticated request is not allowed to see data — which is the point.
08How long you stay signed in
Seven days, from the moment the token is issued — not seven days from your last visit, so an idle session does end and you will be asked to sign in again. Logging out ends it at once: your browser deletes the cookie and the server simultaneously invalidates the token itself, so even a previously captured copy stops working the moment you sign out. We chose a week rather than a single-tab-session cookie because a task board is something you return to during the day over several days; if you would prefer shorter, that is a browser-level control (clear on exit, or private mode) rather than a setting we need to build.
09Do Not Track and Global Privacy Control
We do not track you across sites or sessions, so there is no tracking for a signal to switch off, and our software does not read Do Not Track or Global Privacy Control header values. That is not us overriding your preference — a GPC signal is a request not to be sold or shared for cross-context behavioural advertising, and we do not do that with anyone’s data, signalled or not. If we ever add measurement that is affected by such a signal, we will honour it and rewrite this section to say how.
10Changes to this policy
This page changes when the storage our product uses changes. The date at the top is the last change. Material additions — anything that is not strictly necessary, or that a third party sets — arrive with a consent mechanism in place before the cookie does, not after.
11Questions and contact
If you find Mokara storing something on your device that this page does not list, that is a bug or a lie, and we want to know about either one immediately — [email protected].
What the cookie means for your personal data is covered in the Privacy Policy; the rules for using an account are in the Terms of Use.
Also relevant