Last updated · June 28, 2026

Cookie Policy

This page lists the cookies and similar storage technologies that Signum sets when you use our marketing site (signum.email), the dashboard (app.signum.email), and the API. It is a companion to our Privacy Policy; if anything here is unclear, that’s the more comprehensive document.

1. What is a cookie?

A cookie is a small text file a website asks your browser to store. It travels back to the same website on subsequent requests. Cookies have a name, a value, a domain, a path, and an expiry. They’re mostly used for session continuity (keeping you signed in) and preferences (remembering choices).

We treat localStorage, sessionStorage, and IndexedDB the same way for the purposes of this policy — they’re cookie-equivalent technologies and the same rules apply.

2. The cookies we use

Signum uses only strictly necessary and functional cookies. We do notuse advertising cookies, tracking pixels for analytics, or any third-party marketing trackers on our own sites. (Our product instruments emails you send, but that’s recipient-side beacons, not browser cookies on your devices.)

Strictly necessary — authentication and session

  • signum_token · on app.signum.email and api.signum.email· HTTP-only, Secure, SameSite=Lax. Purpose: holds the signed JWT proving you’re logged in. Expiry: 30 days. Removed: on logout, or when revoked by the JWT denylist.
  • signum_oauth_state · on app.signum.email during the Google OAuth flow only. Purpose: protects the OAuth callback against CSRF attacks (the value is generated, stored, and verified server-side). Expiry: 5 minutes. Removed: immediately after a successful OAuth callback or when the flow times out.
  • signum_oauth_verifier · on app.signum.email during the Google OAuth flow only. Purpose: the PKCE code verifier — an additional CSRF/replay protection layer for OAuth. Expiry: 5 minutes. Removed: immediately after a successful OAuth callback.

Functional — preferences and UX

  • signum.archive.exportId.me · localStorage, on app.signum.email. Purpose: caches the in-flight personal-data export ID so a refresh during a long export doesn’t lose track of the job. Expiry: cleared automatically when the export completes, expires, or fails.
  • signum.archive.exportId.full · localStorage, on app.signum.email. Purpose: same as above but for workspace-wide exports (Owner role). Expiry: same.

3. Cookies we do NOT use

  • No third-party analytics (no Google Analytics, no Plausible, no Mixpanel, etc.) on signum.email or app.signum.email.
  • No advertising or retargeting cookies. We don’t run ad campaigns on our properties.
  • No social-share trackers. Share buttons (where present) link out directly without injecting third-party scripts.
  • No A/B testing cookies. We test changes by inspection and shipping, not by splitting traffic.
  • No fingerprinting. We do not collect or transmit canvas fingerprints, device IDs beyond the standard user-agent header, or hardware concurrency.

4. Tracking pixels in emails you send

Signum’s core product inserts tracking pixels and click-rewrites into emails you send, when you opt to track that send. Those signals fire from your recipients’email clients, not from any browser you control. They are subject to a separate set of rules:

  • Recipients can opt out via the one-click link Signum appends to every tracked send. Opt-outs are honoured indefinitely.
  • Six layers of bot detection filter out automated previews (Apple MPP, Gmail proxy, security scanners) before counting an open.
  • Recipient IP addresses are never stored. Only the engagement event, a timestamp, and a coarse device class are kept.
  • Full details in the Privacy Policy, sections 4 and 5.

5. How to control cookies

You can control cookies through your browser settings. Removing the strictly-necessary cookies above will sign you out. Removing the functional ones will lose any in-flight export progress but not affect access to your account.

On signum.email(this marketing site), we set no cookies on first visit. You can browse the site, read the docs, fill in the contact form, all without a single cookie being written to your device. That’s why we don’t show a cookie banner here.

On app.signum.email, signing in writes signum_token. You consent to that when you click the “Sign in with Google” button — without it we can’t hold your session.

6. Updates to this policy

We’ll update this page if we add, remove, or change the purpose of any cookie. The “Last updated” date at the top reflects the most recent change. Material changes will also be noted in the changelog.

Contact

Questions or concerns? [email protected] reaches a human.