Legal · cookies
Cookie Policy
1. What we set today
Pace-ly currently sets one cookie. It is strictly necessary to operate the Service and is exempt from consent under Article 5(3) of the ePrivacy Directive (2002/58/EC) as transposed into Swedish Lag (2003:389) om elektronisk kommunikation §6.
| Name | Purpose | Lifetime | Type |
|---|---|---|---|
__Secure-authjs.session-token (prod) / authjs.session-token (dev) | Keeps you signed in across requests. Set by Auth.js when you sign in with Discord. | 30 days, sliding | Strictly necessary · HttpOnly · SameSite=Lax · Secure in production |
2. What we do not set
We do not use:
- Advertising cookies or third-party ad pixels.
- Google Analytics, Segment, or any third-party analytics SDK.
- Tracking pixels, fingerprinting, or session-replay tools.
If any of this ever changes we will update this Policy and add a consent banner before the new cookies fire. We honour the Sec-GPC: 1 Global Privacy Control header for any future analytics. Sending GPC opts you out automatically.
3. Local storage and similar
The Pace-ly Client (desktop app) stores its pairing token and a one-time telemetry-consent flag in its application data folder, and saves recordings (telemetry, and any lap video or audio you capture) locally on your device until you choose to upload them. The web app uses browser local-storage for non-personal UI preferences (e.g. last-selected chart).
4. Third-party hosted pages
Payment and subscription management happen on Stripe-hosted pages, not on our domain. Those pages set their own cookies (for example to prevent payment fraud), governed by Stripe’s cookie and privacy notices. We do not set or control those cookies. If in future we embed third-party components directly on our own pages, we will update this Policy and obtain consent before any non-essential cookie is set.
5. Contact
Questions about this Cookie Policy? Email support@pace-ly.com.