Legal
Cookie Settings
Last updated: July 14, 2026
Short version: One Person uses two essential cookies to keep you signed in — and that's all. No ad trackers, no cross-site profiling. Here's exactly what runs, and your controls for anything optional.
Your preferences
Essential cookies can't be turned off — they are how sign-in works. The optional categories below are off by default and saved on this device.
Every cookie we set
| Name | Category | Lifetime | What it does |
|---|---|---|---|
| op_access | Essential · httpOnly | Short-lived session token | Proves you're signed in on each request. |
| op_refresh | Essential · httpOnly | Up to 30 days | Silently renews your session so you aren't logged out mid-work. |
| op_cookie_prefs | Preference · localStorage | Until you clear it | Remembers the choices you make on this page. |
Both auth cookies are httpOnly (scripts can't read them) and sent only to our own domain. Signing out removes them.
Third parties
If you sign in with Google, Google sets its own cookies on its own domains during that flow, governed by Google's policies. Embedded content you choose to add — like a YouTube video used as an invoice page background — is loaded from privacy-enhanced domains where available and only on pages where you placed it.
Managing cookies in your browser
Every major browser lets you inspect, block, or delete cookies in its settings. Blocking the essential cookies will sign you out and prevent sign-in from working — everything else about the marketing site still works.
Questions
More detail on how we handle data overall lives in the Privacy Notice. Anything else: privacy@oneperson.app.