Last updated: 05-10-2026
This policy explains the cookies and browser storage Profolio uses. Profolio is run by Bednal Limited (see the Privacy Policy for our details).
Profolio uses only cookies and browser storage that are strictly necessary for the service to work, or that remember preferences you set. We do not use analytics, advertising or tracking cookies, and no third party sets cookies on Profolio's own pages.
Because of that, we do not show a cookie consent banner: the law does not require consent for storage that is strictly necessary for a service you have asked for. If we ever add analytics or anything else that needs your consent, we will ask for it first and update this policy.
| Name | Purpose | Type | How long |
|---|---|---|---|
__Secure-better-auth.session_token | Your session cookie: keeps you signed in. It cannot be read by scripts on the page and is sent only over HTTPS. | Strictly necessary | 7 days from when you last used Profolio on that device, or until you sign out |
__Secure-better-auth.two_factor | Set only while you are entering a two-factor code, to remember that your password was correct | Strictly necessary | 10 minutes |
__Secure-better-auth.trust_device | Set only if you tick "Trust this device" when entering a two-factor code, so that device is not asked again | Strictly necessary | 30 days |
__Secure-better-auth.better-auth-passkey | Set only while you register or use a passkey, to hold the one-time challenge | Strictly necessary | 5 minutes |
__Secure-better-auth.dont_remember | Set only if a sign-in asks not to be remembered, so the session ends when you close the browser | Strictly necessary | Until you close the browser |
demo-mode | Tells our server that you are using demo mode, so that it serves sample data. | Strictly necessary | 24 hours, or until you leave demo mode |
Our sign-in system is Better Auth, which runs on our own servers: these cookies are ours and are not shared with anyone.
Profolio also stores some information in your browser's local storage and session storage. This is not sent to us automatically.
| Key | Purpose | Type |
|---|---|---|
theme, profolio-theme | Your light, dark or system theme choice | Preference |
currency | Your display currency | Preference |
pwa-install-dismissed | Remembers that you dismissed the prompt to install Profolio as a web app | Preference |
demo-mode, demo-session-start, demo-session-id, demo-session-token, demo-token, demo-api-keys, user-data, and keys starting user-demo-user-id- and user-profile-demo-user-id | Demo mode only: the demo session and its sample data | Strictly necessary for demo mode |
| Key | Purpose | Type |
|---|---|---|
dashboard-visited-in-session, keys starting preload-completed- | Whether pages have already loaded once this session, to avoid repeating work | Strictly necessary |
pwa-session-dismissed | Remembers, for this session, that you dismissed the install prompt | Preference |
demo-api-keys | Demo mode only | Strictly necessary for demo mode |
When you start a subscription or manage billing, you leave Profolio for pages hosted by Stripe, our payment provider. Stripe sets its own cookies on those pages, for example to prevent fraud. Stripe's cookie policy at https://stripe.com/cookies-policy/legal applies to them.
If you choose to sign in with Google or Apple, you are taken to that provider's own page, and its cookies and policies apply there.
You can delete or block cookies and browser storage in your browser's settings. If you block the session cookie you will not be able to sign in. Clearing local storage resets your theme and currency preferences.
Questions about this policy: support@profolioapp.com.