Legal
Cookie Policy
What www.nylon.dev stores in your browser, why, and how to turn it off.
Last updated September 1, 2026
Cookies are small text files a site stores in your browser. Similar technologies — local storage, session storage and pixels — do comparable things, and everything below applies to them too. This policy covers https://www.nylon.dev and the Nylon dashboard. It does not cover the Nylon API itself, which is authenticated with API keys and sets no cookies.
1. The categories we use
- Strictly necessary — sign-in, session integrity and security. These cannot be switched off without breaking the dashboard, and we set them under our legitimate interest in operating a secure service rather than under consent.
- Preference — remembering choices so you do not have to make them again.
We do not use analytics or advertising cookies. We measure visits with Vercel Web Analytics, which sets no cookies and does not identify you across sites. We do not sell what we measure.
2. The cookies we set
| Name | Category | Purpose | Duration |
|---|---|---|---|
| better-auth.session_token | Strictly necessary | Keeps you signed in to the dashboard. | 7 days, renewed while you use the dashboard |
| better-auth.last_used_login_method | Preference | Remembers how you last signed in so the sign-in page can highlight it. | 30 days |
| nylon-web-invitation-flow | Strictly necessary | Marks that you are signing in to accept a team invitation, so you join that team. | 1 hour |
| nylon_<network>_oauth_state | Strictly necessary | Protects the connect-a-social-account flow against cross-site request forgery. | 10 minutes |
On secure connections, sign-in cookie names may carry a __Secure- prefix. The dashboard also keeps a few non-identifying values in your browser’s local storage, such as whether the sidebar is collapsed and the email address you are mid-way through signing in with.
3. Third-party cookies
We set no third-party cookies. When you sign in with Google, connect a social account, or pay on our payment processor’s checkout page, you are on that provider’s site and its own cookie policy applies there.
4. Managing your choices
Because we only set strictly necessary and preference cookies, there is no consent banner. You can block or delete cookies in your browser settings — every major browser documents this under “Privacy” or “Site data”.
Blocking strictly necessary cookies will prevent you from signing in to the dashboard and connecting social accounts. None of this affects the API.
5. Changes
If we add or remove a cookie we will update the table above and the “last updated” date. Questions go to support@nylon.dev.