Effective date: 10 September 2026 Last updated: 10 September 2026 Version: 1.0
*The English and Swedish versions are intended to have the same meaning. If they differ, the English version prevails. Mandatory law always applies.*
This Cookie Policy explains how Kaizensu AB, company registration number 559595-6359, operating Percher ("we", "us", "our"), uses cookies and similar technologies on percher.app (the "Website"), in the dashboard and, for the access cookies described below, on customer app subdomains on percher.run. It supplements the Privacy Policy. Cookies and storage used by customer apps themselves are the app owner's responsibility.
Cookies are small text files a website stores on your device to recognise it and remember information about your visit. Browser local storage and session storage work in a similar way and are subject to the same rule in the Swedish Electronic Communications Act (lagen (2022:482) om elektronisk kommunikation, "LEK"): storing or reading information on your device requires your consent unless it is strictly necessary to provide a service you have requested.
We use the cookies below only for authentication, security or access functions you request. Where a cookie is strictly necessary for such a function, the LEK consent exception applies. Some are set only when the relevant function is used; blocking one may stop that function from working.
| Cookie | Purpose | Duration | Type |
|---|---|---|---|
BetterAuth session cookie (e.g. better-auth.session_token, with the __Secure- prefix over HTTPS) | Authentication — keeps you logged in to the dashboard after you sign in | Up to 7 days (renewed on continued activity) | HttpOnly, Secure, SameSite=Lax |
| BetterAuth OAuth-state cookie (framework-managed name under the BetterAuth prefix) | Security — binds a user-initiated GitHub or Google sign-in to its callback and helps prevent login CSRF | Up to 5 minutes; expired when the callback completes | HttpOnly, Secure, SameSite=Lax |
_percher_gh_install | Security — a one-time token that binds a GitHub App installation flow to your session and prevents replay. Set only if you choose to connect GitHub | Up to 10 minutes; deleted when the installation callback completes | HttpOnly, Secure, SameSite=Lax |
_percher_pw | Access — set on a password-protected app's own subdomain (appname.percher.run) once you have entered the correct password, so you do not have to re-enter it on every page load. Set only if the app owner has enabled password protection. Contains only an HMAC signature, no password | 7 days | HttpOnly, Secure (over HTTPS), SameSite=Lax |
_percher_sess | Access — set on a private app's own subdomain after a signed-in Percher user has been authorised for that app. Contains a signed Percher user identifier | Up to 14 days; access is checked on each request | HttpOnly, Secure (over HTTPS), SameSite=Lax |
The dashboard session cookie contains a random token validated against our database. Percher's app-access cookies are removed before a request reaches the customer app.
We use no analytics cookies, no marketing cookies and no third-party trackers. The visitor statistics we provide to app owners and the aggregate statistics for Percher's own service hosts (percher.app, percher.run, api.percher.run, docs.percher.app and mcp.percher.app) are derived on our own server from the web server's access logs and write nothing to the visitor's browser. Unique visitors and sessions are counted using a hash of the IP address, the User-Agent, the relevant Application or first-party host identifier and a salt; a separate salt is generated for each UTC date and deleted from our live database no later than 48 hours after it was created. No IP address is stored in the statistics themselves; IP addresses appear in the web server's operational access logs, kept for at most 7 days. Sections 2 and 5 of the Privacy Policy describe the processing, the retention periods and the backup caveat. If we introduce browser storage that is not strictly necessary, we will update this policy and obtain any consent required before setting it.
Apps deployed on the Service (appname.percher.run) may set their own cookies. The app owner is the controller for its app and is responsible for informing visitors and obtaining any consent. Percher itself sets only the app-access cookies in Section 2.1 on an app's subdomain.
Providers we call server-to-server, such as our payment provider Polar, set no cookies via the Website; a payment takes place at Polar, which may set its own cookies under its own policies. On the sign-up and password-reset pages and the public support-access form we load Cloudflare Turnstile, a bot-protection service that runs in your browser and may use local storage or a cookie to perform the requested challenge. We do not use that storage for marketing. Whether the LEK consent exception applies depends on the storage being strictly necessary for that requested security function. Section 3 of the Privacy Policy describes the data Cloudflare processes.
| Key | Purpose | Type |
|---|---|---|
Theme preference (percher-theme, percher-v2-theme) | Remembering whether you chose the light or dark interface — the dashboard uses percher-theme, the public and sign-in pages percher-v2-theme | Local Storage |
Banner status (percher.plan-opened-banner.dismissed) | Remembering that you dismissed an information banner during the current tab | Session Storage |
Dismissed one-time tip (percher-appstore-nudge-dismissed) | Remembering that you dismissed the one-time hint about publishing an app to the app stores | Local Storage |
Percher badge state (_pb_min) | Remembering whether you collapsed the Percher badge on a hosted app | Local Storage |
These keys normally contain no personal data and remember an interface choice or an action you requested. The LEK consent exception applies where the storage is strictly necessary for the requested function; otherwise any consent required by law is obtained before storage. You can clear this data in your browser settings.
You can manage and delete cookies and site data in your browser settings. Blocking an authentication or access cookie may prevent you from logging in, using the dashboard or opening a protected app. If we introduce cookies or storage that require consent, they will not be set before that consent is given, and we will provide a way to withdraw it.
| Storage | Legal basis |
|---|---|
| Authentication, security and access cookies | The LEK consent exception, only where storage is strictly necessary for an expressly requested function |
| Functional local storage | The LEK consent exception where strictly necessary for the requested function; otherwise prior consent where required and, for personal-data processing, GDPR Art. 6(1)(a) |
We update this policy when our use of cookies changes, for example if we start using new types of cookies or change the purpose of existing ones. Changes are announced via the Website, and the current date is shown at the top.
*Last updated: 10 September 2026* *© 2026 Kaizensu AB — Percher, percher.app*