Cookie Notice

Which cookies and browser storage the site uses, and why.

Version 2026-09-23

1. In short

We use cookies only to keep you signed in, to protect sign-in flows, and to remember your language and theme. We do not use advertising or analytics cookies, and we do not let third parties track you across sites from our pages.

2. Cookies we set

  • tf_session — keeps you signed in to the console. HttpOnly; lasts for the browser session, or 30 days if you chose to stay signed in.
  • tf_admin — the same for platform staff in the admin console. HttpOnly, SameSite=Strict.
  • tf_oauth_state and tf_terms — protect a GitHub, Google or OpenID sign-in against forgery and remember that you accepted the terms while you are away at the provider. Ten minutes.
  • tf_enterprise_… — the same protection for enterprise single sign-on. Minutes.
  • tf-locale and tf-theme — the language and colour theme you picked. One year.

3. Storage in your browser

The console also keeps a few things in your browser's local storage, where they never leave your device: the organisation you last selected, Playground conversation history, which announcements you dismissed, and the density of the key list. Clearing your browser data removes them.

4. Third parties

Sign-up and password-reset forms show a Cloudflare Turnstile challenge to stop automated abuse; it runs in Cloudflare's own frame under Cloudflare's privacy policy. Payments open the payment processor's checkout page, which sets its own cookies under its own policy. Neither is used for advertising.

5. Your control

You can block or delete cookies in your browser settings. Without tf_session you cannot stay signed in; everything else keeps working with defaults.