Cookie Policy
Last updated: August 30, 2026
1. Signing you in
Clerk handles sign-in and uses cookies to maintain the authentication session. Blocking those cookies prevents the signed-in product from maintaining a session. Clerk is listed with our other service providers.
The exact Clerk cookie names and lifetimes depend on the deployed authentication configuration. We therefore do not restate third-party defaults here as if they were settings controlled in this codebase.
2. Demo and legacy guest-workspace cookies
Opening the seeded demo without an account sets two first-party cookies. Sealinn no longer creates a new anonymous workspace from the Start Free action: it now asks the visitor to sign up. A guest workspace created under the earlier flow can still exist during its retention window and uses the same two cookies until it expires or is converted:
sv_guestcontains a random token that lets this browser reach the temporary workspace. The live token is in the cookie; only its hash is stored in our database. It contains no name, email address or workspace name. It is HttpOnly, SameSite=Lax, set with Path=/ and Secure in production.sv_guest_kindcontainsdemo, orworkspacefor an existing legacy guest workspace. It is a client-readable layout hint used to reserve the right space for the guest banner; it is not trusted for authentication or authorization. It has the same SameSite, path, production Secure flag and lifetime assv_guest, but it is intentionally not HttpOnly.
For the seeded demo, both cookies expire after 24 hours. For an existing legacy guest workspace, the browser may retain them for up to 400 days, while the server-side workspace is deleted after 30 days without a visit. The longer browser lifetime prevents a still-live legacy workspace from being stranded when its server-side inactivity window is renewed.
Deleting sv_guest does not itself delete the workspace, but this browser loses the token needed to find it. Deleting only sv_guest_kind removes the layout hint and does not grant or revoke access. Creating an account converts an existing legacy guest workspace into an account workspace, after which these guest cookies are no longer used to reach it. Retention details are on the privacy page.
3. Local storage written by Sealinn
Local storage remains in the browser until it is cleared by the browser, the user or application code. Sealinn writes the following first-party values; the analytics-choice value remains dormant unless the planned integration is activated:
themestores a signed-in user’s light, dark or system theme choice. Clearing it returns the interface to the system default.- If Google Analytics is activated after the advance-notice period,
sv:google-analytics-consent-v1stores only whether this browser granted or denied marketing analytics. A missing, unreadable or old-format value is treated as no consent. It does not contain a user or workspace identifier. sv:filedetail-split,sv:sheetdoc-splitandsv:review-splitstore signed-in layout widths for document panes.sv:setup-collapsedandsv:setup-dismissedremember the signed-in setup checklist display state.- Keys beginning with
sealinn-response-workspace-device-draft-v1:hold an unfinished supplier-intake draft on that device. The form fields and questionnaire answers are encrypted with AES-GCM before they enter local storage; the decryption key is derived from that response link and its supplier scope. The draft is not copied to Sealinn’s servers or another browser, and the customer-only reuse consent checkbox is never included in it. A successful submission or the form’s clear control removes it. An invalid or expired draft is not loaded and is removed when that response workspace is next visited; until then, browser storage can retain the ciphertext.
4. Counting page views
We currently use PostHog to see which pages get used and where people give up. It runs in its cookieless mode: it sets no cookie and writes nothing to local or session storage. The work of not counting one visit as two happens on PostHog’s servers instead of by leaving an identifier on your machine. It is on the subprocessors list with everything else that receives data, and what it gets is stated there: which pages are used and which actions are taken — never the contents of a document.
What it is configured NOT to do is the part worth stating: no session recording, no automatic capture of everything you click, no surveys, and no dead-click tracking. It is deliberately proxied through our own domain rather than loaded from a third-party host — which is PostHog’s own documented deployment for a site that would rather not have another origin in its content-security policy, not a way around anything.
Google Analytics is a planned, separate marketing-site integration. Its production environment value is deliberately empty, so it currently loads no Google tag, makes no Google request and sets no Google cookie. It will remain dormant until the promised subprocessor-notice window has elapsed and consent controls have been verified.
If it is activated later, the tag will load only after this browser chooses Allow analytics. A decline loads nothing from Google. Events are limited to allow-listed public marketing pathnames and page titles; query strings, fragments, referrers, signed-in app routes, bearer-link paths, user identifiers and workspace identifiers are excluded. Advertising signals and ad personalization are disabled.
After consent, Google’s default first-party analytics cookies may include _ga and a property-specific name beginning _ga_, with a default lifetime of up to two years. The persistent Privacy choices control can withdraw consent, set Google’s official disable flag and delete those readable first-party cookies for this site. Browser controls can also remove them. Blocking either analytics integration does not block product functionality; nothing in the product checks whether an analytics request completed.
5. Your browser controls
Browsers let you inspect, block and delete site cookies and clear local storage. Blocking sign-in storage prevents the signed-in session from working. Blocking or deleting sv_guest prevents this browser from returning to the seeded demo or an existing legacy guest workspace. Clearing the preference values above resets the corresponding interface choice. Clearing an encrypted supplier draft removes only unsent progress on that device; it does not remove a response already submitted to the customer workspace.
When the planned marketing analytics control is available, choose Privacy choices on any marketing page to allow, decline or later withdraw Google Analytics. Withdrawal stops further Google Analytics sends from this site and removes the readable first-party _ga cookies described above.
Sealinn does not currently change its behavior in response to Do Not Track or Global Privacy Control signals. We do not use those signals as a substitute for the browser’s cookie and storage controls.
6. If this changes
We will update this page when our cookies, browser storage or analytics configuration materially changes. We will also reassess the notice and consent controls that apply in the places where we offer the service; those requirements depend on the technology, purpose and applicable law.
Questions, or a request about your own data: privacy@sealinn.com. What we hold and for how long is on the privacy page; every company that receives any of it is named on subprocessors.
Looking for a different document? They are all listed on the Legal page.
