Cookie policy
The single cookie this site sets, why there is no consent banner, and the third-party connections worth knowing about.
Updated on August 31, 2026
1. What this site sets
A cookie is a small file stored on your device when you visit a site. This one sets a single cookie, and only once you have signed in.
| Name | Purpose | Duration | Category |
|---|---|---|---|
| better-auth.session_token | Keeps you signed in between pages | 7 days | Strictly necessary |
This cookie is set by the site itself, never by a third party. It holds an opaque session identifier, no personal data in clear text. Without it, staying signed in from one page to the next is impossible.
2. Why you are not shown a banner
Article 82 of the French Data Protection Act requires consent before any tracker is stored, but exempts those whose sole purpose is to enable or facilitate communication, or which are strictly necessary to deliver a service the user has expressly requested.
The session cookie falls within that exemption: it only keeps you authenticated. Since no other tracker is set, a consent banner would have nothing to ask you. That is why there is none — not an oversight.
3. What this site does not do
- No audience measurement, anonymised or otherwise.
- No advertising cookie, no retargeting.
- No social share buttons, no social pixels.
- No sale or transmission of browsing data to third parties.
- No persistent local storage of your content in the browser: your résumés are saved on the server, tied to your account.
4. Third-party connections
Two resources load from third-party servers. They set no cookie, but they do involve a connection from your browser, which transmits your IP address to the server contacted. For transparency:
- The typefaces used by the résumé templates load from Google Fonts (fonts.googleapis.com and fonts.gstatic.com) whenever a preview is displayed. Your IP address and your browser's technical characteristics are transmitted to Google on that occasion.
- The payment form for the Pro plan is provided by Stripe, which applies its own security and fraud-prevention trackers during checkout.
5. Managing cookies
You can delete stored cookies or block them at any time from your browser settings. Deleting the session cookie signs you out immediately; blocking it makes signing in impossible, but does not prevent you from reading the public pages.
Signing out from the application removes the cookie with no further steps.
6. Changes
Should a tracker requiring consent ever be introduced — audience measurement, for instance — a consent mechanism would be put in place before anything is stored, and this page updated. Questions: hello@koumastudio.com.