We set a small number of cookies, and every one of them is either required for the platform to work or set because you chose something. None are advertising or cross-site tracking cookies, and no third-party analytics or advertising script runs on any page.
We do measure how the product is used, but that happens on our servers as aggregate counts per workspace — never through a cookie, and never per person.
Required for sign-in and for protecting your account. Blocking these will break the platform.
Sign-in cookies. One keeps you signed in. There are separate ones for staff, for client-organisation contacts, and for candidates, because those are three separate boundaries that deliberately cannot reach one another.
Two-factor cookies. If your workspace uses two-factor sign-in, one short-lived cookie carries you between entering your password and entering your code. A second is set only if you tick remember this machine: it is a persistent cookie that survives closing the browser and lets that device skip the code next time, so do not tick it on a shared computer. Signing out of every session, or turning two-factor off and on again, invalidates it.
Security cookies. One protects every form you submit against being triggered from another site. Another holds short-lived state for multi-step flows, such as the job-creation wizard and the handshake when you connect a Google or Microsoft account. It expires after 30 minutes of inactivity.
Signing in to apply. Two more are set only while you are starting or continuing an application. One remembers which role you were applying to across the sign-in step; the other holds the email address you typed, so the "check your email" page can tell you where the link went without putting your address in the web address, where it would end up in browser history and server logs. It is encrypted, unreadable to page scripts, and expires after 15 minutes.
All sign-in cookies are inaccessible to page scripts, restricted from cross-site use, and sent only over an encrypted connection.
Set only when you choose something: your light or dark appearance, your interface mode, and the last pipeline and job you looked at so returning to a list puts you back where you were. They hold no personal data and nothing that identifies you — the last of them carries a job's own internal reference, which identifies a role in your workspace rather than a person. All of them are marked secure outside development and cannot be read by page scripts.
We set none, and we embed no third-party script that would.
Two things take you to another company's site, which will set its own cookies on its own domain under its own policy: Stripe when you manage billing, and Google or Microsoft when you connect a calendar or mailbox. Those cookies are never set on our domain.
Every cookie we set is either strictly necessary or a direct result of something you did, so none of them requires consent before it is set. If that ever changes, we will ask first and update this page.