Skip to main content

Cookie Policy

Effective: September 7, 2026

Strictly necessary storage

  • __Secure-better-auth.session_token— Peacify's production authentication session cookie. It is HttpOnly, Secure and SameSite=None under the current server configuration. The configured session lifetime is up to 90 days and the session is refreshed periodically while active.
  • Authentication/security flow storage — Better Auth and its sign-in providers may create short-lived, flow-specific security cookies while authentication is in progress. These are used to complete and protect sign-in rather than for advertising.
  • Cloudflare Turnstile security storage— may be used when required by Cloudflare's bot-protection challenge flow. Peacify uses it for security, not behavioral advertising.

Temporary browser storage

The web app uses one sessionStorage entry to carry a pending chat message from the public landing experience into the authenticated app. It is removed after use or when the browser session ends. It is not used for cross-site tracking.

Server-side product analytics

Peacify records a small allowlisted set of content-free product events on the server for product operation and cohort reporting. This does not use advertising cookies or third-party browser analytics. Peacify does not currently use Google Analytics, PostHog, Mixpanel or cross-site behavioral advertising trackers on the web app.

Non-essential cookies

Peacify does not currently enable non-essential advertising or behavioral analytics cookies. If that changes, this notice and the consent controls will be updated before those cookies are enabled where consent is required. For privacy, KVKK and GDPR information, see the Privacy Policy.