Skip to content

Legal

Cookie Policy

Effective

1. Summary

The LyEve marketing site (lyeve.com) sets no cookies. The customer portal sets HTTP-only cookies that are strictly necessary for authentication, plus short-lived ones while you sign in with GitHub or enter a two-step sign-in code. A GitHub sign-in passes through our API host, api.lyeve.com, which sets its own copies of the sign-in cookies. Both sites keep your light or dark preference in local storage. Every cookie and storage key we set is listed below. None of them is for analytics or advertising, so there is nothing to accept or decline. We count visits without storing anything in your browser. The privacy policy says what our server records about a visit.

2. Cookies we set

Name Domain Purpose Lifetime Category
lyeve-portal-sessionapp.lyeve.com, api.lyeve.comKeeps you signed in to the customer portal (HTTP-only, SameSite=Lax)Expires with the session, 30 days by defaultStrictly necessary
lyeve-portal-csrfapp.lyeve.comProves a form submission came from the portal itself (HTTP-only, SameSite=Lax)Same lifetime as the session cookieStrictly necessary
lyeve-portal-oauth-stateapp.lyeve.com, api.lyeve.comTies the start and the end of a GitHub sign-in together (HTTP-only, SameSite=Lax). Set only while that sign-in is in progress10 minutesStrictly necessary
lyeve-portal-mfaapp.lyeve.com, api.lyeve.comCarries a sign-in from the password or GitHub step to the two-step code step, for accounts with two-step sign-in on (HTTP-only, SameSite=Lax). Set only while that sign-in is in progress5 minutesStrictly necessary
__Host-lyeve-portal-nextapp.lyeve.comRemembers the portal page you were going to while a GitHub sign-in is in progress, so you land there afterward (HTTP-only, SameSite=Lax)10 minutesStrictly necessary
lyeve-portal-support-viewapp.lyeve.comSet only in the browser of a LyEve support agent who opens an account through a support link. It shows a banner saying whose account is open and that the visit is recorded (HTTP-only, SameSite=Lax)As long as the support link allowsStrictly necessary
lyeve-themelyeve.com, app.lyeve.comLight or dark preference (localStorage, not a cookie)PersistentFunctional
sveltekit:scroll, sveltekit:snapshotapp.lyeve.comReturns you to where you were on a portal page when you go back to it. The framework the portal is built on writes both, and the second holds nothing today (sessionStorage, not a cookie)Until the tab closesFunctional

No advertising, marketing, or cross-site tracking cookies are ever set.

3. Third-party

PayPal (when you start a paid subscription or one-time order) sets its own cookies on paypal.com for fraud prevention. Those cookies are governed by PayPal's privacy policy.

4. Managing cookies

You can clear all cookies in your browser settings at any time. Removing the session cookie logs you out of the customer portal and you will need to log in again. Removing the CSRF cookie may break form submissions until the next page load. Removing a sign-in cookie while a GitHub or two-step sign-in is in progress cancels that sign-in, so start it again.

5. Changes

If we add new cookies in the future we will update this page and notify active subscribers by email.

On 2026-10-06 every portal cookie took a name that starts with lyeve-portal. A browser signed in before then may still hold a cookie under its earlier name, which keeps it signed in until that session ends and is removed when you sign out. Nothing new is stored.

On 2026-10-08 lyeve.com stopped keeping the lyeve-visit identifier in session storage. A tab opened before then may still hold it until the tab closes. It is not read or sent by any page served since.

6. Contact

Questions? privacy@lyeve.com