Cookies
RoleWake uses only first-party cookies that are strictly necessary to sign you in and keep sign-in secure. No analytics, no ads, no tracking pixels.
Cookies we set
On the live site, which is served over HTTPS, the names carry a security prefix — the second name in each row.
| Name | Purpose | Duration |
|---|---|---|
authjs.session-token__Secure-authjs.session-token | Keeps you signed in: a signed, encrypted token naming your account. Split into .0, .1 … if it grows large. | 7 days, renewed while you use RoleWake; deleted when you sign out. |
authjs.csrf-token__Host-authjs.csrf-token | Protects the sign-in and sign-out forms against cross-site request forgery. | Until you close your browser. |
authjs.callback-url__Secure-authjs.callback-url | Remembers the page to return to after you sign in. | Until you close your browser. |
authjs.pkce.code_verifier__Secure-authjs.pkce.code_verifier | Secures the exchange with Google — set only while you sign in with Google. | 15 minutes. |
RoleWake stores nothing else in your browser — not even your interface language.
Third-party cookies
Stripe’s checkout and billing portal, and Google’s sign-in page, run on their own domains and set cookies there under their own privacy policies. We don’t read them.
How to opt out
These cookies are strictly necessary, so there is no opt-out and no banner. Signing out deletes the session cookie, and you can delete your account at any time from Settings → Login & Security. More in the privacy policy.