Incantory
Sign in

Draft for owner/legal review. This text is being reviewed before it becomes final and may change. It already describes how Incantory works today; questions to [email protected].

Cookie statement

Last updated

Incantory does not use advertising, tracking or analytics cookies. Every cookie we set is strictly necessary for something you asked for, such as staying signed in, so the law does not require a consent banner and we do not show one.

Cookies we set

NamePurposeLifetimeSet when
incantory_sessionKeeps you signed in. Holds a random token; we store only its hash. HttpOnly, Secure, SameSite=Lax.30 days, renewed while you use the site; removed when you sign outYou sign in
incantory_oauth_github, incantory_oauth_appleProtects "Sign in with GitHub/Apple" against forged requests (signed state and PKCE verifier). Scoped to /api/auth.10 minutes, deleted when you returnYou start a GitHub or Apple sign-in
incantory_webauthnHolds the one-time challenge while you sign in with a passkey. Scoped to /api/auth/passkey, SameSite=Strict.5 minutes, deleted after useYou sign in with a passkey
incantory_discord_linkProtects the "Link Discord" flow against forged requests. Scoped to /settings/discord.10 minutes, deleted when you returnYou link your Discord account

Cloudflare

The site is served through Cloudflare, which may set its own strictly necessary security cookies (for example __cf_bm for bot protection or cf_clearance after a security check). They do not track you across sites. The Turnstile check on some forms runs in a Cloudflare frame and does not set tracking cookies on incantory.ai.

Things stored in your browser, not in cookies

A few conveniences are kept in your browser's local storage. They are never sent to us.

KeyPurpose
incantory.themeYour light, dark or system theme choice
incantory.recentRecent searches and pages in the command palette (⌘K)
incantory.mastodon-instanceThe Mastodon server you last shared to
incantory.admin.flashA one-off confirmation message in the admin area (staff only)

Analytics without cookies

Page analytics uses Umami, which we host ourselves. It does not set cookies or use local storage, and it does not follow you across sites. See the privacy policy for what it records.

Managing cookies

You can block or delete cookies in your browser settings. If you block incantory_session, you can still browse, but you will not be able to sign in.

Questions: [email protected].