Cookie Policy
Effective date: 2 July 2026 Last updated: 3 July 2026
This Cookie Policy explains the cookies and similar client-side storage technologies (such as localStorage and sessionStorage) used by Sairaph Mail (the "Service"), operated by WELLDONE (Aleja Wyzwolenia 11/6, 70-552 Szczecin, Poland; NIP PL8531508847) at mail.sairaph.com. It supplements our Privacy Policy (see Section 8 of that document); terms defined there apply here.
Summary: Sairaph Mail is built to be privacy-first. We use only strictly necessary cookies and storage to run the Service, keep it secure, and remember your choices. We do not use analytics cookies, third-party advertising cookies, or cross-site tracking cookies.
---
1. What we set, and why
1.1 Strictly necessary (no consent required)
These are required for the Service to function, to keep it secure, or to honour your choices; under the ePrivacy rules they are exempt from the consent requirement.
- Authentication token - stored in your browser's
localStorage. Purpose: keeps you signed in to the dashboard. Set by: Sairaph Mail (first party). Duration: until you sign out or it expires/is cleared. Without it, the dashboard cannot keep you logged in. - Consent-decision record - stores your cookie/privacy choices. Purpose: so we can remember and honour your preference and not ask repeatedly. Set by: Sairaph Mail (first party). Duration: persistent until you change your choice or clear it.
- Cloudflare Turnstile - runs on the signup form and may set its own storage/cookies. Purpose: distinguishing humans from automated bots (security / abuse prevention). Set by: Cloudflare (our sub-processor; see
SUB_PROCESSORS.md). Duration: short-lived / per challenge. - `sairaph_oauth_state` - an HttpOnly cookie. Purpose: carries a signed, short-lived CSRF state token, OIDC nonce, and PKCE verifier for the "Log in with Google / Apple / Microsoft" social-login flow, so we can verify the provider's redirect back to us is genuine. Set by: Sairaph Mail (first party), only when you start a social-login attempt. Duration: 10 minutes, then it expires; a completed or abandoned login also clears it.
- `sidebar_state` - a cookie readable by the dashboard's own script. Purpose: remembers whether you left the dashboard's navigation sidebar expanded or collapsed, so it opens the way you left it next time. Set by: Sairaph Mail (first party). Duration: 7 days from when you last toggled it.
The sairaph_oauth_state cookie above is set with the Secure flag outside local development and SameSite=Lax; neither it nor sidebar_state is used for advertising, analytics, or cross-site tracking.
---
2. Managing your choices
2.1 You can control storage through your browser settings (e.g. blocking or clearing cookies and site storage). Note that blocking strictly-necessary storage - such as the authentication token or the OAuth-state cookies - will prevent the dashboard, or the specific sign-in/connect flow that depends on it, from working correctly.
2.2 The items in Section 1.1 cannot be switched off through a preferences control, because the Service (or your saved preference) depends on them.
---
3. Sub-processors
3.1 The only third party that may set storage in connection with the Service is Cloudflare (Turnstile, strictly necessary security). Full details of our sub-processors, their roles, regions, and transfer mechanisms are in SUB_PROCESSORS.md.
---
4. Changes to this Policy
4.1 We may update this Cookie Policy to reflect changes to the technologies we use or to the law. For material changes, we will notify you by updating this page (and, where appropriate, through the cookie/privacy banner) with a new effective date.
---
Contact: WELLDONE, Aleja Wyzwolenia 11/6, 70-552 Szczecin, Poland (NIP PL8531508847) - privacy: privacy.mail@sairaph.com.
If you have questions about these terms, contact us at privacy.mail@sairaph.com.
*Sairaph Mail, operated by WELLDONE, Sairaph.com.*