Cookie Policy
1. The short version
Sincejar sets one strictly-necessary cookie, and only once you sign in: your session. It is httpOnly, so no script on the page can read it. Your preferences are kept in your browser's local storage.
Everything we store is needed to provide the Service you asked for: keeping you signed in, remembering your settings, and showing your data quickly. None of it is used for analytics, advertising or tracking.
We do not run analytics, advertising, or third-party tracking scripts on this site. Measured on a fresh visit to the home page: this site sets zero cookies, stores three items in local storage (your theme, your accent colour, and a cache of exchange rates), and makes no request to any third-party origin at all: no font CDN, no tag manager, nothing. Fonts are served from our own domain precisely so that loading the page does not hand your IP address to anyone else.
If that ever changes, this page will be updated first, we will ask before anything non-essential is stored, and it will stay off until you agree.
2. Strictly necessary (always on)
These are required for the service to work at all. They cannot be switched off, and under UK/EU rules they do not require consent.
• sincejar_session (cookie, httpOnly, secure, SameSite=Lax): keeps you signed in. Set when you sign in, cleared when you sign out, and expires after 30 days without use. Whether you have passed two-factor authentication is recorded on our server against this session, not in a separate cookie.
• sincejar_oauth (cookie, httpOnly, secure, SameSite=Lax): exists only for the few minutes of a "Continue with Google / GitHub" sign-in, to check that the provider sent you back to the same browser. Deleted as soon as that sign-in finishes.
Under the ePrivacy Directive (and the UK PECR), storage that is strictly necessary to provide a service the user has requested does not require consent. Everything listed on this page falls into that category.
We do not show a cookie consent banner, because we do not set anything that requires consent. Under the ePrivacy rules consent is needed for non-essential storage (analytics, advertising, tracking), and we use none of it: there is no analytics SDK, no advertising pixel and no cross-site tracker anywhere in this site or the app. Asking you to agree to categories that do not exist would be theatre, and it would create a consent record we have no reason to hold.
If that ever changes (if we add analytics, for instance), we will ask first, and nothing non-essential will be set before you agree.
3. Preferences stored on your device
These live in your browser's local storage. They stay on your device, are not transmitted to us as part of ordinary requests, and are removed if you clear site data.
• sincejar-theme, sincejar-brand: light/dark mode and accent colour.
• sincejar-rates-v1: a cached table of currency exchange rates, so converted totals render without refetching public rate data on every page. It contains no personal data.
• sincejar-confirm-delete, sincejar-haptics: interface preferences you set in Settings.
• sincejar-suggestion-usage: counts of which topics you ask the assistant about, so the suggested prompts get more useful. It stores topic labels and counts only. It never stores your messages, and it is never sent to a server.
• sincejar_expenses_…, sincejar_budgets_…, sincejar_profile_…: cached copies of your own expenses, budgets and profile so pages show instantly while fresh data loads. Removed when you sign out.
• sincejar-age-blocked: set only if the age check at sign-up was not passed, so the form cannot simply be retried. Contains no date of birth.
• sincejar-synced-timezone: the last timezone we sent, so we do not repeat the call on every launch.
4. Analytics and marketing
None at present, and no banner asking about them. We removed it: there was nothing to consent to, and keeping a consent record we had no need for is itself data we would rather not hold. If we ever add analytics or marketing, we will ask before anything is stored, not afterwards.
We do not sell personal information, and we do not share it with advertising networks.
5. Third parties that can see a request
Some providers necessarily receive your IP address when your browser or our server talks to them. They are described in the Privacy Policy under sub-processors. They do not set advertising cookies through this site.
• Our hosting provider: serves the site, runs the database that stores your account, and keeps security logs.
• Google or GitHub: only during a "Continue with …" sign-in you start, on their own pages.
• Our AI provider: receives the text you send to AI features, only when you use them.
6. Managing your choices
There is no consent to change, because nothing non-essential is stored. The controls that do exist are in the app: theme and accent under Settings, and, separately, whether AI features may send your text and images to a third-party provider, which is off until you turn it on and can be turned back off in one tap.
You can clear everything from your browser settings (Clear site data / Clear cookies). This signs you out and resets your preferences to defaults; your account and financial records are not affected.
Blocking the strictly-necessary session cookie in your browser will prevent sign-in from working. That is a limitation of how sessions work, not a choice we make.
7. Changes and contact
If we add a cookie or a tracker, we will update this page and the consent version before it loads, so a previously-given consent is never silently reused for something new.
Questions: support@sincejar.360framed.com.
Last updated: 26 September 2026.