Cookies

Oat uses cookies to keep you signed in and to protect an account connection while it happens. That is the whole list.

Last updated 23 September 2026

The operating company name, its registered address and the governing law for these terms are to be confirmed by counsel before public launch. Everything else on this page describes what the service does today.

What is set

Cookies set by Oat and by Clerk on its behalf
CookieSet byPurposeLasts
Session cookies (names beginning __session and __client_uat)ClerkKeeps you signed in and lets the server verify who is making a requestYour session; refreshed while you use the desk
oat_oauth_<provider>OatHolds a one-time nonce while you connect an outside account, so a replayed or cross-workspace callback is rejected15 minutes, deleted when the connection completes

Both are strictly necessary for the service to work, so they are set without a consent banner. They are httpOnly where the browser allows it and are never readable by scripts on the page.

What is not set

There are no analytics tags, no advertising pixels, no social-media embeds and no marketing cookies on this site or on the desk. We do not fingerprint browsers and we do not use local storage to track you. If that changes, this page changes first and a consent choice appears before any such technology runs.

Third-party services you connect

When you sign in to a provider to connect an account, that provider sets its own cookies on its own domain during the sign-in. Those are governed by the provider's policy, not this one.

Controls

Your browser lets you view and delete cookies at any time. Deleting the session cookie signs you out. Blocking cookies entirely stops the desk from working, because it cannot tell who you are without one.

Questions go through the contact page. The privacy notice covers everything else we collect.