Grailsome uses a single HTTP-only, secure, same-site session cookie to maintain your login status. That’s it.
2. What We Don’t Use
No third-party tracking cookies
No analytics platforms (Google Analytics, Mixpanel, etc.)
No advertising cookies or pixels
No cross-site tracking of any kind
No CAPTCHA services
3. Local Storage
Your browser’s local storage may be used to preserve UX preferences (such as sort order or filter selections). This data stays in your browser and is never transmitted to our servers.
4. How to Control Cookies
You can clear or block cookies in your browser settings at any time. Clearing the Grailsome session cookie will sign you out. Since we use only one essential cookie, blocking it will prevent you from signing in.
5. Security Overview
For completeness, here is how we protect your data:
Encryption at rest — field-level encryption on sensitive data (email, collection contents, item details)
Encryption in transit — HTTPS with HSTS enforcement on all connections
Payment security — credit card numbers never touch our servers; all payments processed by Stripe (PCI DSS Level 1 certified)
File storage — photos stored on private AWS S3 buckets, accessible only through authenticated application access; no public file URLs
AI data handling — photos and item data sent to AI providers for identification and valuation only; providers cannot train on your data
Data deletion — account deletion permanently removes all data; uploaded files removed from storage within 30 days