Legal
Cookies
Updated September 2026
This page lists every cookie and every item of browser storage that vraelis.com and app.vraelis.com set, who sets it, what it is for, and how long it lasts. It also explains your choices and how to change them.
Your choices
The first time you visit, Vraelis asks you to choose. Essential cookies are always on, because sign-in, security, and payments cannot work without them. Everything else is off until you turn it on:
- Preferences. Remembering display choices on this browser, such as the language you pick and whether the console notes panel is open.
- Analytics. Vercel Speed Insights and an anonymous visit count, described below.
- Advertising measurement. Reporting a sign-up to Meta, described below.
You can read this page, the privacy policy, and the other legal pages before choosing. Everywhere else on Vraelis, including sign-in and the console, you are asked first. “Essential only” and “Save my choices” are equal options, and saving with nothing turned on is the same as essential only.
How to change your choice
Open Privacy choices at any time. It is in the footer of every page on vraelis.com, at the foot of the documentation, under the sign-in form, and in the console sidebar. Your choice is kept in the vraelis_privacy cookie for six months and applies on vraelis.com and app.vraelis.com alike. After six months, or if you clear your cookies, you are asked again.
Turning a category off removes what it stored in this browser and stops it from storing or sending anything more. It cannot recall a measurement or a report that was already sent while it was on.
Global Privacy Control
If your browser sends a Global Privacy Control signal, Vraelis treats it as an opt out of every optional category for as long as the signal is on. The switches stay off, Speed Insights and the visit count do not run, and the server checks the signal (the Sec-GPC header) before it would report a sign-up. Essential cookies are not affected.
Cookies
Names are as set on vraelis.com. A cookie whose name begins with __Secure- or __Host- is only ever sent over an encrypted connection.
| Name | Set by | Purpose | Category | Duration |
|---|---|---|---|---|
| vraelis_privacy | Vraelis | Remembers your privacy choices so you are not asked on every page. Shared by vraelis.com and app.vraelis.com. | Essential | 6 months |
| __Secure-authjs.session-token | Vraelis (sign-in) | Keeps you signed in. Shared by vraelis.com and app.vraelis.com so the console can see your session. Scripts on the page cannot read it. If your account uses two-step verification, it holds the sign-in that is waiting for your code, for up to 15 minutes, until the code is checked. | Essential | 30 days, renewed while you use Vraelis |
| __Host-authjs.csrf-token | Vraelis (sign-in) | Protects sign-in against cross-site request forgery. | Essential | Until you close the browser |
| __Secure-authjs.callback-url | Vraelis (sign-in) | Remembers which page to return you to after you sign in. | Essential | Until you close the browser |
| __Secure-authjs.pkce.code_verifier | Vraelis (sign-in) | Secures the handoff when you sign in with Google or GitHub. | Essential | 15 minutes |
| sx_signup_claim | Vraelis | Lets the browser where you started an email sign-up sign you in once you confirm your address, even if you open the link on another device. | Essential | 24 hours |
| v_sso_oidc | Vraelis | Secures the handoff when you sign in through your organization's single sign-on. | Essential | 10 minutes |
| vraelis_language | Vraelis | The language you picked in the language switch, so the site, the docs and the console open in it. Shared by vraelis.com and app.vraelis.com. Set only if Preferences is on. | Preferences | 6 months |
| vws | Vraelis | Remembers which workspace you are working in, if you belong to more than one. Set when you switch workspace. | Essential | 1 year |
| vr_two_step_nudge | Vraelis | Remembers that you chose Not now on the console's offer to turn on two-step verification, so it stops asking until you close the browser. Set only when you choose Not now. | Essential | Until you close the browser |
| vr_oauth_<provider>, vr_oauth_acct_<provider>, vr_pkce_<provider>, vr_oauth_popup | Vraelis | Secure the handoff when you connect an integration such as GitHub or Vercel. | Essential | 10 minutes |
| vr_stealth | Vraelis | Preview access. Lets a browser that was given access see the site while it is not yet public. | Essential | 30 days |
| __stripe_mid, __stripe_sid | Stripe | Fraud prevention. Set on the Vraelis domain by Stripe's payment script, which loads only on the checkout page. | Essential | 1 year; 30 minutes |
Browser storage
Some features keep data in your browser's local storage or session storage instead of a cookie. Unlike a cookie, it is not sent to Vraelis with each request.
| Name | Set by | Purpose | Category | Duration |
|---|---|---|---|---|
| vraelis:scratchpad | Console, local storage | The notes you type in the scratchpad panel. They stay in this browser and are never sent to Vraelis. | Essential | Until you delete them |
| vraelis:scratchpad-open, vraelis:scratchpad-view | Console, local storage | Whether the scratchpad panel is open, and how it is shown. | Preferences | Until you clear it or turn Preferences off |
| vraelis-locale | Website and console, local storage | The same language choice, kept in this browser. Set only if Preferences is on. | Preferences | Until you clear it or turn Preferences off |
| vraelis-connect-draft-v1 | Console, local storage | Keeps an unfinished form for connecting a system, so a reload does not lose it. | Essential | Until you submit or clear the form |
| vraelis-flow-draft-<id> | Console, local storage | Keeps a new flow you are still writing. | Essential | Until you save or discard it |
| vraelis-oauth | Console, local storage | Passes the result of an integration's sign-in window back to the console. | Essential | Until the next connection replaces it |
| vraelis:balance-before-topup | Console, session storage | Your balance before a top-up, to confirm the purchase arrived. | Essential | Until you close the tab |
| v6.visited | Website, session storage | Marks that this tab's one anonymous visit was counted, so it is not counted twice. | Analytics | Until you close the tab |
| __paypal_storage__ | PayPal, local storage | Written by PayPal's script, which loads only on the checkout page when PayPal is offered, for PayPal's own buttons. | Essential | Until you clear it |
| fieldline-fleet-broken, fieldline-fleet-fixed | Practice drone panel, local storage | The state of the simulated drone panel at /api/fixtures/drone, a demonstration target. Only if you open it. | Essential | Until you clear it |
Analytics
Vercel Speed Insights. With Analytics on, a script from Vercel, our hosting provider, measures how quickly each page loads and responds and sends those timings with the page address, browser, device type, operating system, connection type, and country. Vercel describes it as not tied to any individual visitor or IP address, and it sets no cookies. Turn Analytics off and nothing more is sent, even from a page that is already open.
Visit count. With Analytics on, Vraelis records one anonymous visit per browser tab, with only the page you landed on. A marker in session storage (v6.visited) stops the same tab being counted twice. No cookie, account, or device detail is recorded with it, and your IP address is used only to limit how often a visit can be written, never stored with it.
Advertising measurement
Vraelis places no advertising cookies, pixels, or tags on its pages. With Advertising measurement on, and only then, when you create an account the Vraelis server tells Meta that a sign-up happened and includes a SHA-256 hash of your email address, so Meta can match it to an ad it showed you. The server reads your choice, and any Global Privacy Control signal, from the request that creates the account. With it off, nothing is sent.
Some US state privacy laws may treat this as sharing personal information for cross-context behavioral advertising. That is why it is off unless you turn it on, and why Global Privacy Control turns it off.
Payments
Checkout is handled by Stripe, with PayPal as an alternative, and their scripts load only on the checkout page. Stripe's script sets the two Stripe cookies in the table above on the Vraelis domain to help detect fraud, and Stripe's payment form runs in frames served from Stripe's own domains, which set Stripe's own cookies there. PayPal's script keeps the __paypal_storage__ item listed above in this site's local storage, and if you pay with PayPal, its window comes from paypal.com and sets PayPal's own cookies. Those are governed by Stripe's and PayPal's own cookie policies. They are needed to take a payment safely, so they are essential, and nothing from either loads anywhere else on Vraelis.
Signing in with Google or GitHub
If you choose to sign in with Google or GitHub, you are sent to their sign-in page, which sets their own cookies under their own policies. Vraelis receives your email address and basic profile from them, as described in the privacy policy.
Contact
Questions about cookies or this page? Email [email protected]. See also the privacy policy.