Last updated: 2026-05-31
These run regardless of consent because the platform cannot function without them. nuna_access: 15-minute access token (httpOnly + secure + sameSite=lax). nuna_refresh: 30-day refresh token (httpOnly + secure + sameSite=lax). nuna_csrf: CSRF double-submit token for state-changing requests. nuna-cookie-consent (localStorage): your banner choice so we don't ask twice.
These run only after you Accept on the consent banner. ph_*: PostHog product analytics. Helps us understand which features engineers actually use so we know what to ship next. No third-party tracking; no advertising network.
On first visit, click 'Reject all' on the consent banner. To change your mind later, clear your browser's localStorage for nuna.online and the banner will re-appear. We are building a settings-page toggle for this in a future release.
Questions or concerns about cookies: privacy@nuna.online.