Last updated: 20 September 2026
Cookie Policy
This page lists everything that Solory stores in your browser: cookies, and the other storage that works the same way. It is written to be complete rather than short. If you only want to change your choice, use the Cookie settings link in the footer of any page - it reopens the banner and takes effect at once.
1. The short version
Nothing we store ourselves tracks you. What we set either keeps you signed in, remembers a preference, or holds work you have not finished, and all of it stays in your browser or on our own servers. Two third parties - Google and Meta - do set tracking cookies, and neither is loaded at all unless you have said yes. Refusing costs you nothing: the application works identically.
The banner asks two separate questions, measurement and advertising, and you can accept one and refuse the other. Your answer is remembered for 182 days, after which you are asked again.
2. Cookies we set ourselves
These are set by Solory. None of them needs your consent: each one is either required to deliver the service you asked for or remembers a choice you made on screen.
| Name | What it does | How long it lasts |
|---|---|---|
| sb-<project>-auth-token | Keeps you signed in. Split into -token.0 and -token.1 when it is long, and accompanied briefly by -code-verifier while a magic link or a Google sign-in is completing. It is readable by the application in your browser, which is how the app knows who you are without asking the server on every click. | Until you sign out, and up to 400 days |
| NEXT_LOCALE | Remembers which of the five languages you chose, so the next page arrives in it. | 1 year |
| sidebar_state | Remembers whether you left the sidebar open or collapsed. | 7 days |
| solory_consent | Records your answer to the cookie banner, so you are not asked again on every page. | 182 days |
| solory_consent_id | A random number with no meaning of its own, stored alongside your answer. It is what lets us show, if we are ever asked, which choice was recorded and when - without knowing who made it. | 182 days |
| active_account_id | Which account you are working in, for people who belong to more than one - their own and a client's, or a shared team account. It is read by the server on every request, which is why it is a cookie and not a preference kept in the browser. | 1 year, or until you switch back |
| impersonation_session_id | Names an open support session. It is set only in a Solory administrator's own browser, and only while a support session that you or the law has authorised is running - never in your browser, and never as a result of anything you do. The server re-checks the session on every request, so the cookie by itself grants nothing. | 8 hours, or until the session is ended |
| google_oauth_state | A one-time value that proves the Google connection you come back with is the one you started. Set only while you are connecting your calendar, and deleted the moment you return. | 10 minutes |
3. Cookies set by others, and only if you agree
Nothing in this section is loaded before you consent. Refuse, and the script is never fetched - not fetched and then told to stay quiet, but never requested at all, so no cookie of theirs can be set.
| Who | What it does | How long it lasts |
|---|---|---|
| Google Analytics (_ga, _ga_<id>) | Tells us which pages are read and roughly how people move through them, so we know what to improve. Set only if you accept measurement cookies. Page addresses are reduced to their general shape before they are sent, and pages reached through a personal link - a client portal, a signature page - are excluded entirely. | Up to 2 years |
| Meta (_fbp, and fr on Meta's own domain) | Measures whether our advertising works. Set only if you accept marketing cookies. Meta decides its own purposes for this data rather than acting on our instructions, which makes it a joint controller with us for it and not our processor. | Up to 90 days |
Withdrawing consent stops both immediately and clears the choice we recorded. Cookies already set by Google or Meta are theirs, in their own name: your browser's settings remove them, and both publish their own instructions for doing so.
4. Other storage in your browser
A cookie travels to the server with every request. The storage below never leaves your browser unless the application deliberately sends it, which is why it is used for drafts and preferences. It is listed here because the law treats it the same way, and because some of it holds real content rather than a setting.
| Name | What it holds | Until when |
|---|---|---|
| email-compose-autosave | An email you started writing and have not sent - the recipients, the subject and the body. It is offered back to you for 7 days so that a closed tab does not cost you the message. | 7 days, or until you send or discard it |
| command-palette-recent | The last five records you opened, so the search box can offer them first. It holds their names - a client, a project, an invoice. | Until you sign out |
| solory.timer.session.v1 | A running or paused time-tracking session, so that reloading the page does not lose the minutes. | Until you stop the timer or sign out |
| solory.locale | The same language choice as the cookie, kept here as well so the interface can render in it before the server answers. | Until changed |
| theme | Whether you chose the light or the dark interface. | Until changed |
| solory.activeAccountId | Which account you last had open, for people who belong to more than one. | Until you sign out |
| solory.sidebarView | Which view of the sidebar you prefer. | Until changed |
| solory.dismissedAnnouncements | Which in-app announcements you have already closed, so they stay closed. | Until changed |
| solory.waitlist-popup-dismissed | That you closed the invitation to join the waiting list, so it is not offered again. | Until changed |
| solory.pwa.install-hint.dismissed | That you closed the hint offering to install the app to your home screen. | Until changed |
| Name | What it holds | Until when |
|---|---|---|
| cold-lead-compose-intent | A message the assistant drafted for a lead, carried from the dialog where you generated it to the screen where you edit and send it. It contains the address and the draft. | The life of the tab |
| solory.billing.upgradeTarget, solory.billing.upgradeInterval | Which plan and billing period you were buying, so the page you return to from the payment provider knows what to confirm. | The life of the tab |
| solory.validation.balanceBefore | Your address-checking balance before a purchase, so the page can show you what arrived. | The life of the tab |
| Name | What it holds | Until when |
|---|---|---|
| solory-outbox (IndexedDB) | Work you did while your connection was down, waiting to be sent: queued time entries, and the raw image data of receipt photographs you attached to an expense. It is emptied as each item is uploaded. | Until the item is sent, or you clear it |
| solory-static-... (Cache Storage) | Copies of the application's own files - scripts, styles, icons - so it starts quickly and keeps working offline. It holds no personal data. | Until a new version replaces it |
Signing out clears the items above that belong to your account. Your browser's own controls clear all of it, and doing so costs you only the unfinished work listed here.
5. Email tracking is not a cookie, and is described elsewhere
Our emails record whether they were opened and which links were clicked, using an invisible image and rewritten links rather than a cookie. That is explained, including what you can do about it and the limit we currently have, in section 6 of the Privacy Policy.
6. Changing your mind, and asking us anything
Use the Cookie settings link in the footer of any page to reopen the banner and change or withdraw your answer. Withdrawing is as easy as giving consent, takes effect immediately, and does not affect the lawfulness of what was measured before.
Questions about this page, or about anything in it, go to support@solory.ch. We answer in the language you write in, where it is one of the five the Service speaks.