Cookies & tracking
What cookies and similar technologies Schmatz uses, why, and how you can control them. The inventory is short: cookies needed for authentication and request security, plus on-device preferences.
What is a cookie?
A cookie is a small text file that a website stores on your browser to remember information between visits. Related technologies include local storage, session storage, web beacons, and pixel tags. "Cookies" in this notice refers to any of these mechanisms.
Strictly necessary cookies
We use strictly necessary cookies — those required for Schmatz to function — without requesting consent, because they are essential for the service you have asked us to provide.
Authentication session
- Set by: the Schmatz application through Auth.js
- Purpose: keep you signed in between page views without requiring re-authentication on each request
- Duration: up to 30 days; it is replaced or cleared as the session changes or you sign out
- Type: HTTP-only, secure, same-site
Sign-in and request-protection cookies
- Set by: Schmatz application
- Purpose: protect against cross-site request forgery and safely complete email or Google sign-in flows; temporary OAuth state, nonce, PKCE, or callback cookies may be used when that flow requires them
- Duration: session-only or short-lived, depending on the sign-in step
Analytics & performance cookies
We do not use these. Privacy-safe first-party page and feature events are captured by Schmatz without a third-party analytics cookie. Signed-out acquisition events are recorded only when you enable Analytics in this banner; signed-in users can choose privacy-safe or necessary-only processing in Settings. The event schema excludes raw prompts, email content, credentials, and private tool payloads. If we ever add a third-party analytics provider, this notice will be updated and we will implement an opt-in consent prompt before any analytics cookies are set.
Advertising & targeting cookies
Schmatz does not use any advertising or targeting cookies. We do not sell advertising. We do not share data with ad networks. We have no plans to.
Third-party cookies on linked domains
When you follow a link from Schmatz to an external website (e.g., a regulatory filing on sec.gov or a Ken French research data page), that external site may set its own cookies. Schmatz is not responsible for the privacy practices or cookies of any third-party site you visit through our links.
How to control cookies
The preferences banner
On your first visit, Schmatz shows a small cookie-preferences banner. We set no optional cookies, but the Analytics preference controls privacy-safe signed-out acquisition events. The app works fully whichever option you pick. Your choice is stored in browser local storage and does not activate third-party technology. You can revisit your choice via the Cookie preferences link in the site footer.
Schmatz also uses local storage for on-device settings such as theme, accent, density, reduced motion, dismissed notices, and in-app update preferences. These values normally remain in your browser and are not authentication credentials.
Browser settings
You can control or delete cookies through your browser settings. Useful links:
Blocking strictly necessary cookies (specifically the Auth.js authentication session cookie) will prevent you from staying signed in to Schmatz. There is no work-around because authentication is required to use the service.
Do Not Track
Most major browsers offer a "Do Not Track" signal. There is currently no industry consensus on how to interpret this signal, and Schmatz does not currently change its behavior based on it. Because we do not use advertising or third-party analytics cookies, there is in practice nothing for the signal to disable.
Changes to this notice
If we add any new cookies — particularly third-party analytics or advertising cookies — we will update this notice, revise the "Last updated" date, and (for material additions) request your consent through a banner or in-app notice before any new cookies are set on your device.