PixMenderOpen image tool
Legal

Cookie and browser storage policy

The essential cookie and local browser storage PixMender uses for sign-in, security, verification and temporary image drafts.

Effective · Last updated

01

What this policy covers

Cookies are small values stored by a website in your browser. PixMender also uses session storage, local storage and IndexedDB for narrowly defined product functions. These technologies do not all send data to the server, but this policy explains them together so you can understand what remains on your device.

02

Authentication cookie

After sign-in, the API sets a cookie named session so authenticated pages and requests can recognize your account. It is HTTP-only, uses Secure transport in production, has SameSite=Lax protection, applies across the service and expires after 30 days. It is strictly necessary for browser-based account access and is removed when you log out.

03

Temporary verification state

During email signup and verification, sessionStorage may temporarily hold the email address being verified and whether a delivery attempt failed. localStorage may hold a validated PixMender path so verification opened in a new tab can return you to the page you requested. The browser normally clears sessionStorage when the tab or browser session ends, and PixMender removes these verification values after successful activation.

04

Pre-signup image draft

If you choose an image and operation before creating an account, the image draft may be saved in your browser's IndexedDB so you can continue after signup. A localStorage marker lets the app detect that draft. The draft stays on your device, expires after 48 hours and is cleared after it is used or when you remove the site's stored data.

05

Analytics and advertising

PixMender does not currently set optional analytics or advertising cookies. If we add non-essential browser tracking, we will update this policy and request consent where required before activating it. Third-party sites reached from a PixMender link apply their own cookie policies.

06

Your controls

You can log out to clear the session cookie or use browser settings to block and delete cookies, local storage and IndexedDB. Blocking essential storage may prevent sign-in, verification or draft recovery. Browser controls affect only that device and profile. Questions can be sent to [email protected].