Cookie Policy
Last updated 17 September 2026
What we use, and what we don't
Levare Core only uses cookies that are strictly necessary to make the application work — for authentication and security. We don't use analytics, advertising, or cross-site tracking cookies. As a result, we don't show a cookie consent banner: strictly necessary cookies are exempt from consent requirements under applicable law, because the site can't function without them.
Your theme preference (light/dark) is stored in your browser's local storage, not a cookie, and never leaves your device.
Cookies we set
| Cookie | Purpose | Duration |
|---|---|---|
| Session cookie | Keeps you logged in between page loads. | Cleared on logout / expires after inactivity |
| Two-factor pending cookie | Remembers that you've passed the password step and still need to enter your 2FA code. | Short-lived, cleared after login completes |
| Acting agency cookie | Used by our own staff for support access to a specific agency's workspace. | Session-length |
| Google OAuth state cookie | Security check (prevents cross-site request forgery) during the optional Google Calendar connection flow. | Short-lived, cleared once the connection completes |
Third-party embeds
The marketing site doesn't embed any third-party widgets, trackers, or analytics scripts. Fonts are self-hosted at build time rather than loaded from Google's servers at runtime, so no font-related requests are made to a third party either.
Managing cookies
Because our cookies are all strictly necessary, blocking them in your browser will prevent you from staying logged in. Questions: matthew@levarestudio.com.