Cookie policy
The Denby website sets no cookies at all; we count visits with Cloudflare Web Analytics, which doesn't use them. The Denby app and client portals set only the cookies needed to keep you signed in and remember your display preference. There are no advertising, tracking or third-party cookies anywhere.
Because every cookie we set is strictly necessary, there is no cookie banner. Our privacy policy covers everything else we collect.
Cookies in the app and client portals
| Cookie | Set when | What it does | Lasts |
|---|---|---|---|
denby.session_token and related denby. cookies | A firm user signs in | Keeps you signed in to the firm app; includes a short-lived cookie during two-step sign-in | 30 days, renewed while in use, or until you sign out |
denby_portal_… | A client opens their portal link | Keeps a client signed in to that firm’s portal only | 30 days, renewed while in use |
denby_admin | A Denby staff member signs in to the internal admin | Admin session; never set for customers | 8 hours |
theme | You choose light or dark mode in the app | Remembers your choice | 1 year |
All sign-in cookies are marked HttpOnly and Secure, so scripts can’t read them and they are only sent over HTTPS. Each sign-in has its own cookie and its own session, so a client’s portal cookie can never open the firm app. See our security page for how sign-in works.
The website
Pages on denby.app outside the app set no cookies. Visit counts come from Cloudflare Web Analytics, run by Cloudflare, which already hosts Denby. It records no personal identifiers, sets no cookies and needs no consent. We don’t load it for browsers that send Do Not Track.