Cookie Policy

Last updated: 05-10-2026

This policy explains the cookies and browser storage Profolio uses. Profolio is run by Bednal Limited (see the Privacy Policy for our details).

1. The short version

Profolio uses only cookies and browser storage that are strictly necessary for the service to work, or that remember preferences you set. We do not use analytics, advertising or tracking cookies, and no third party sets cookies on Profolio's own pages.

Because of that, we do not show a cookie consent banner: the law does not require consent for storage that is strictly necessary for a service you have asked for. If we ever add analytics or anything else that needs your consent, we will ask for it first and update this policy.

2. Cookies

NamePurposeTypeHow long
__Secure-better-auth.session_tokenYour session cookie: keeps you signed in. It cannot be read by scripts on the page and is sent only over HTTPS.Strictly necessary7 days from when you last used Profolio on that device, or until you sign out
__Secure-better-auth.two_factorSet only while you are entering a two-factor code, to remember that your password was correctStrictly necessary10 minutes
__Secure-better-auth.trust_deviceSet only if you tick "Trust this device" when entering a two-factor code, so that device is not asked againStrictly necessary30 days
__Secure-better-auth.better-auth-passkeySet only while you register or use a passkey, to hold the one-time challengeStrictly necessary5 minutes
__Secure-better-auth.dont_rememberSet only if a sign-in asks not to be remembered, so the session ends when you close the browserStrictly necessaryUntil you close the browser
demo-modeTells our server that you are using demo mode, so that it serves sample data.Strictly necessary24 hours, or until you leave demo mode

Our sign-in system is Better Auth, which runs on our own servers: these cookies are ours and are not shared with anyone.

3. Browser storage

Profolio also stores some information in your browser's local storage and session storage. This is not sent to us automatically.

Local storage (kept until you clear it)

KeyPurposeType
theme, profolio-themeYour light, dark or system theme choicePreference
currencyYour display currencyPreference
pwa-install-dismissedRemembers that you dismissed the prompt to install Profolio as a web appPreference
demo-mode, demo-session-start, demo-session-id, demo-session-token, demo-token, demo-api-keys, user-data, and keys starting user-demo-user-id- and user-profile-demo-user-idDemo mode only: the demo session and its sample dataStrictly necessary for demo mode

Session storage (cleared when you close the tab)

KeyPurposeType
dashboard-visited-in-session, keys starting preload-completed-Whether pages have already loaded once this session, to avoid repeating workStrictly necessary
pwa-session-dismissedRemembers, for this session, that you dismissed the install promptPreference
demo-api-keysDemo mode onlyStrictly necessary for demo mode

4. Stripe

When you start a subscription or manage billing, you leave Profolio for pages hosted by Stripe, our payment provider. Stripe sets its own cookies on those pages, for example to prevent fraud. Stripe's cookie policy at https://stripe.com/cookies-policy/legal applies to them.

5. Sign-in with Google or Apple

If you choose to sign in with Google or Apple, you are taken to that provider's own page, and its cookies and policies apply there.

6. Managing cookies

You can delete or block cookies and browser storage in your browser's settings. If you block the session cookie you will not be able to sign in. Clearing local storage resets your theme and currency preferences.

7. Contact

Questions about this policy: support@profolioapp.com.