Tregr

Cookie Policy

Last updated: July 17, 2026

This Cookie Policy explains the cookies and similar technologies that Tregr (“Tregr,” “we,” “us”) uses, what each is for, and how long it lasts. It applies to visitors worldwide and should be read alongside our Privacy Policy. Tregr is an independent tool and is not affiliated with Meta Platforms, Inc. or Instagram.

Tregr keeps cookies to an absolute minimum. The only cookies we set are the strictly-necessary ones that sign you in and keep your session secure (listed in section 2). We do not set any preference, analytics, advertising, or cross-site tracking cookies, and we do not sell your data. Currency selection and first-run onboarding — which used to rely on cookies — no longer do (currency is read from your request and a ?currency= link; onboarding progress is saved to your account).

1. What cookies are

A cookie is a small text file a website stores in your browser. Cookies can be “strictly necessary” (the site cannot function as you requested without them — e.g. keeping you logged in) or “non-essential” (they add convenience or tracking, and the core service works without them). The distinction matters for the consent rules described in section 4. Tregr sets only strictly-necessary cookies.

2. Strictly necessary cookies

These are required to sign in and keep your session secure. They cannot be switched off through Tregr, because the app would not work without them. They are set as HttpOnly, Secure, and SameSite=Lax. (On a non-HTTPS local development host the same cookies appear without the __Host-/__Secure- prefix, e.g. authjs.session-token.)

CookiePurposeLasts
__Secure-authjs.session-tokenKeeps you signed in — identifies your logged-in session. Set only after you sign in.~30 days
__Host-authjs.csrf-tokenSecurity token that protects the sign-in flow against cross-site request forgery (CSRF).Session (until browser closes)
__Secure-authjs.callback-urlRemembers which page to return you to after you finish signing in.Session (until browser closes)

3. Third-party cookies (payments)

When you open the checkout window to start a paid subscription, our payments provider Razorpay loads its secure checkout from checkout.razorpay.com and may set its own cookies for payment processing and fraud prevention. These are controlled by Razorpay under its own privacy and cookie policies, not by Tregr, and are only involved if you choose to subscribe. Tregr itself embeds no advertising pixels, social-media trackers, or analytics SDKs anywhere in the app.

4. EU / UK visitors: your rights (GDPR & ePrivacy)

If you are in the European Economic Area or the United Kingdom, the GDPR and the ePrivacy rules (the “cookie law”) apply. Those rules require prior consent before storing non-essential cookies, but strictly necessary cookies (section 2) are exempt because they are essential to a service you have requested. Since Tregr sets only strictly-necessary cookies, no cookie-consent banner is required for our own cookies; any third-party payment cookies (section 3) are only ever set when you actively choose to begin a checkout you requested.

Cookies that identify you (such as your session cookie) are still personal data, so your broader GDPR/UK-GDPR rights — access, erasure, objection, and the rest — apply as described in our Privacy Policy. Residents of other regions (for example California under the CCPA/CPRA) have the rights set out there too.

5. How to control cookies

You can delete or block cookies through your browser settings, and set your browser to warn you before storing them. Because Tregr only uses strictly necessary cookies, blocking them will stop you from signing in and using the dashboard; the rest of the app has no optional cookies to turn off. Most browsers also offer a “clear cookies” option that removes everything Tregr has stored.

6. Changes and contact

We will update this page if the cookies we use change, and revise the “last updated” date above. Questions about this policy: email help@tregr.io.