What we set

When you log in, InvoiceMint sets one cookie named im_session. It is an HttpOnly session identifier. The server stores only a hash of that value. The cookie is SameSite=Lax, and it is marked Secure when the site is served over HTTPS.

If a network sends an unusual number of requests, the site asks for a short verification code and then sets im_clearance. That cookie is HttpOnly, lasts about 30 minutes, and only records that the check was completed. It is not used to build a profile.

A CSRF token is returned to the signed-in app in the session response and kept in memory. It is not a tracking cookie.

What we do not set

There are no advertising cookies, no third-party analytics cookies, and no marketing pixels in this application.

Local storage

Guest invoices and the in-progress editor use local storage. That is not a cookie. It stays on your device until you clear it or replace the draft.

How long the session lasts

The session cookie lasts 14 days, or until you log out. Logging out deletes the server session.