Effective date: 11 June 2026 Last updated: 29 July 2026 Version: 2.0
*This document is drawn up in English, which is the authoritative version. A Swedish translation is available at percher.app/sv/cookies. In the event of any discrepancy, the English version prevails; this does not limit rights you have under mandatory law.*
This Cookie Policy explains how Percher ("we", "us", "our") uses cookies and similar technologies on percher.app (the "Website") and in our dashboard. The policy supplements our Privacy Policy and should be read together with it.
Cookies are small text files stored on your device (computer, mobile phone, tablet) when you visit a website. They are used so that the website can recognise your device and remember information about your visit. Similar technologies, such as the browser's local storage (Local Storage) and session storage (Session Storage), work in a corresponding way and are subject to the same rules.
These cookies are required for the Website and the dashboard to function correctly. They cannot be turned off. No prior consent is required — the exemption for necessary cookies follows from the Swedish Electronic Communications Act (lagen (2022:482) om elektronisk kommunikation, "LEK") and applicable practice.
| Cookie | Purpose | Duration | Type |
|---|---|---|---|
BetterAuth session cookie (e.g. better-auth.session_token, with the __Secure- prefix over HTTPS) | Authentication — keeps you logged in to the dashboard after you sign in with email and password | Up to 7 days (renewed on continued activity) | HttpOnly, Secure, SameSite=Lax |
_percher_gh_install | Security — a one-time token that binds a GitHub App installation flow to your session and prevents replay. Set only if you yourself choose to connect GitHub | Temporary — deleted as soon as the installation returns (callback) | HttpOnly, Secure, SameSite=Lax |
_percher_pw | Access — set on a password-protected app's own subdomain (appname.percher.run) once you have entered the correct password, so that you do not have to re-enter it on every page load. Set only if the app owner has enabled password protection. Contains only an HMAC signature — no password | 7 days | HttpOnly, Secure (over HTTPS), SameSite=Lax |
Technical details: The session cookie contains a randomly generated token. The token is stored in our database so that we can validate your session. _percher_pw contains an HMAC signature bound to the app and the current password. We never store your password or other sensitive information in any cookie.
We use no analytics cookies (Google Analytics, Matomo or similar). The visitor statistics we provide to app owners — visits, unique visitors, sessions, bounce rate, referring sites, device category and country — are derived entirely on our own server from the web server's access logs. Percher's visitor statistics write nothing to the visitor's browser: no cookie, no local storage, and no analytics script in the app. (An app deployed on the Service may set its own cookies — see Section 2.4.) Unique visitors and sessions are counted using a hash of the IP address, the User-Agent, the identifier of the application being visited and a salt. A separate salt is generated for each UTC date, and each salt is deleted from our live database no later than 48 hours after it was created; once a date's salt is gone, our live data can no longer be used to recompute that date's identifiers from an IP address or to match them against another date. No IP address is stored in the visitor statistics themselves; IP addresses do appear in our web server's operational access logs, which are short-lived and used for operating and securing the Service. See Sections 2.2 and 6 of the Privacy Policy for the retention periods and the backup caveat — encrypted backups can hold both the identifier and the salt for longer. If we introduce analytics cookies in the future, this policy will be updated and a cookie banner will be shown on your first visit, where non-necessary cookies are off by default until you expressly accept them.
We use no marketing cookies and have no third-party trackers.
Apps that users deploy on the Service (appname.percher.run) may set their own cookies via their own code. Such cookies are controlled by the respective app owner, who is the controller for their app and responsible for informing their visitors and obtaining any consent — not by Percher. The only cookie Percher itself sets on an app's subdomain is _percher_pw (Section 2.1), and only when the app owner has enabled password protection.
Our AI providers (Anthropic, OpenRouter) and our payment provider (Polar) are called via server-to-server requests and do not set cookies in your browser via the Website. When you make a payment, the payment flow itself takes place at Polar, which may set its own cookies in accordance with its own cookie and privacy policy.
On the sign-up and password-reset pages we load Cloudflare Turnstile, a bot-protection service that runs in your browser to confirm that you are human. Turnstile may set its own local storage or a cookie in your browser as a technical and security necessity for it to function; it is not used to track you for marketing purposes. See Section 4.1 of the Privacy Policy for the data Cloudflare processes. We ourselves set no third-party cookies for tracking.
In addition to cookies, the Website also uses other local storage in the browser:
| Key | Purpose | Type |
|---|---|---|
Theme preference (percher-theme, percher-v2-theme) | Remembering whether you chose the light or dark interface — the dashboard uses percher-theme, the public pages and sign-in pages percher-v2-theme | Local Storage |
| Banner status | Remembering that you dismissed an information banner during the current tab | Session Storage |
These keys normally contain no personal data. The storage is functionally necessary or takes place at your request (e.g. when you switch theme), and technically corresponds to cookies under the Swedish Electronic Communications Act (2022:482). Since the storage is necessary for the functions you have requested, no separate consent is required under LEK. You can clear such data via your browser settings.
You can manage and delete cookies via your browser settings:
Note: If you block strictly necessary cookies, you cannot log in or use the dashboard.
If we introduce cookies requiring consent in the future (analytics, marketing), a cookie banner will be shown on your first visit. You can change your preferences at any time via a link in the footer.
| Type of cookie | Legal basis |
|---|---|
| Strictly necessary | The exemption in the Swedish Electronic Communications Act (2022:482, "LEK") — no consent required |
| Functional local storage (theme, banner status) | Necessary for the requested function under LEK — no consent required |
| Analytics cookies (if applicable in the future) | Consent (GDPR Art. 6.1.a) — requires prior opt-in |
| Marketing cookies (if applicable in the future) | Consent (GDPR Art. 6.1.a) — requires prior opt-in |
We may update this Cookie Policy when our use of cookies changes. We consider material changes to include, for example, starting to use new types of cookies (analytics, marketing or third-party cookies) or changing the purpose of existing cookies in a way that affects you. Such changes are announced via the Website. The current date is always shown at the top of the document.
If you have questions about our use of cookies, contact us:
*Last updated: 29 July 2026* *© 2026 Percher — percher.app*