Legal
Cookie Policy
The short version: one essential session cookie, no analytics, no advertising, no tracking.
Last updated: 29 August 2026
01What we use
The dashboard stores exactly what it needs to keep you signed in — nothing more:
| Storage | Purpose | Lifetime |
|---|---|---|
| session cookie | httpOnly cookie set by the API after Discord login. Authenticates your requests. Not readable by scripts. | Session / up to 30 days |
| nimbus.session | Fallback bearer token held in sessionStorage where the cookie flow is unavailable. Never written to localStorage. | Until the tab closes |
Both are strictly necessary: without them the dashboard cannot know who you are or which servers you manage.
03Third parties
- Google Fonts sets no cookies, but your browser contacts Google's servers to download the typefaces, which exposes your IP address to Google.
- Discord sets its own cookies during the OAuth login redirect, on Discord's domain, under Discord's privacy policy. We neither set nor read them.
04Managing cookies
You can block or delete cookies in your browser settings. Blocking the session cookie will sign you out and prevent logging in until it is allowed again — the dashboard genuinely cannot work without it.
Clearing sessionStorage or closing the tab removes the fallback token immediately.
05Changes and contact
Any change to what we store appears on this page with a new date. Questions: nimbus.legal@proton.me.
