Cookie Policy
Effective: August 23, 2026
This page describes the cookies and similar technologies that Decka uses, what they are used for, and how you can control them. It supplements our Privacy Policy.
What is a cookie?
A "cookie" is a small text file that a website places on your device. Some cookies are required for the site to function; others are optional and used for product improvement.
Categories we use
We organize the cookies we set into four categories:
- Strictly necessary cookies are required to operate the Service — for example, to keep you signed in, to protect against cross-site request forgery during sign-in, and to remember your cookie preferences. These cookies do not require consent under applicable privacy laws.
- First-party measurement cookies are set by Decka itself and read only by Decka. They record which marketing page or email brought you to us, so we can tell which of our own pages and messages work. They are never shared with an advertising network, are not used to build a profile, do not follow you to other websites, and carry no name or email address — only a short label of our own and, for email, an opaque identifier for the message that was sent.
- Advertising measurement cookies are set by Decka, but unlike the category above, what they hold IS sent to an advertising network. Today there is exactly one: if you arrive from an advert, it stores the click identifier that network put on the link, so that if you go on to create an account we can tell them their advert worked. It holds nothing of ours about you — no name, no email address, not even a label of our own — and we send that network nothing else. Because it shares data with an advertising network, it is treated like the optional analytics cookies below: in regions with an opt-in regime it is set only if you click "Accept" on the cookie banner.
- Optional analytics cookies are used to understand how the Service is used so we can improve it. They are off by default and only set if you click "Accept" on the cookie banner. Associated browser and authenticated server-side product analytics are also sent only while that explicit choice is current.
Cookies we set
| Name | Purpose | Category | Duration |
|---|---|---|---|
slidoodle-access-token |
Keeps you signed in (HttpOnly, Secure, SameSite=Lax) | Strictly necessary | 1 hour |
slidoodle-refresh-token |
Re-issues your access token when it expires (HttpOnly, Secure, SameSite=Strict) | Strictly necessary | 90 days |
slidoodle-pending-auth |
Holds the temporary token used during email verification (HttpOnly, Secure, SameSite=Lax) | Strictly necessary | 10 minutes |
slidoodle-auth-flash |
Temporarily carries a sanitized sign-in error between authentication pages (HttpOnly, Secure, SameSite=Lax) | Strictly necessary | 1 minute |
slidoodle_mcp_consent |
Binds a short-lived MCP authorization approval to the signed-in user, requested client, redirect URI, scopes, and PKCE challenge (HttpOnly, Secure, SameSite=Strict) | Strictly necessary | 5 minutes |
slidoodle-cookie-consent |
Records your cookie banner choice so we don't ask again (SameSite=Lax) | Strictly necessary | 12 months |
slidoodle-campaign |
Remembers which campaign link or landing page brought you to Decka, so we can measure which of our pages lead to an account (SameSite=Lax, Secure, readable by our own scripts) | First-party measurement | 30 days |
slidoodle-email-click |
Set only when you click a link in a Decka email, so we can tell that the email brought you back. Holds an opaque identifier for that message and nothing about you (HttpOnly, Secure, SameSite=Lax) | First-party measurement | 7 days |
slidoodle-rdt |
Set only when you arrive from a Reddit advert, so that if you go on to create an account we can tell Reddit their advert worked. Holds the click identifier Reddit itself put on the link, and nothing about you. In opt-in regions it is set only after you accept (HttpOnly, Secure, SameSite=Lax) | Advertising measurement | 7 days |
| OAuth state / nonce cookie | CSRF protection during single-sign-on flows (HttpOnly, Secure) | Strictly necessary | ~10 minutes |
PostHog cookies (ph_*) |
Product analytics — only set if you click "Accept" on the cookie banner | Optional analytics | Up to 12 months |
| Stripe cookies and similar browser storage | Payment security, fraud prevention, and payment authentication when a Decka billing form loads Stripe.js | Strictly necessary for billing | Set by Stripe and varies by technology |
Managing your choice
You can change your optional-cookie choice at any time using the Cookie settings link in the footer. Reopening the banner replaces your earlier choice.
Refusing optional cookies does not block essential cookies — without those, you cannot stay signed in.
You can also block or delete cookies using your browser's settings. Doing so may prevent parts of the Service from working as expected.
Managing first-party measurement cookies
The two FIRST-PARTY measurement cookies above — slidoodle-campaign and slidoodle-email-click — are set without a banner prompt, because they exist only to attribute our own pages and emails to our own results and are never shared with anyone. The advertising measurement cookie slidoodle-rdt is different: because its contents are sent to the advertising network that referred you, in regions with an opt-in regime it is set only after you accept. You can delete or block any of them in your browser's settings at any time; nothing on the Service stops working if you do. If you do not want to receive marketing email from us at all, every marketing message carries a one-click unsubscribe link, and your email preferences can be changed from your account settings.
Third parties
PostHog sets optional analytics cookies only after you accept analytics. Stripe may set strictly necessary payment-security cookies or similar storage when you open a Decka billing form. See the Subprocessors page for the current providers. We do not allow advertising networks to set cookies on the Service.
Changes
We may update this page when we add, remove, or change a cookie. Material changes will be reflected in the version metadata at the top of this page.
Contact
Questions about this policy can be sent to legal@decka.dev.