Cookie Policy

Last updated: May 21, 2026

1. What are cookies?

Cookies are small text files stored by your browser when you visit a website. They allow the website to remember information about your visit, such as your login session, theme preference, and language. We also describe similar technologies (local storage, session storage) in this policy as they serve the same purpose.

2. What cookies do we use?

We use only essential (strictly-necessary) cookies. We do not use third-party advertising cookies, retargeting pixels, behavioral analytics that profile users, or any cross-site tracking technology.

Cookie / StoragePurposeDurationCategory
__Secure-authjs.session-tokenMaintains your authenticated session8 hours or until logoutStrictly necessary
__Host-authjs.csrf-tokenCSRF protection for authentication formsSessionStrictly necessary
__Secure-authjs.callback-urlRemembers post-login destinationSessionStrictly necessary
theme (localStorage)Remembers light/dark mode preferenceUntil clearedFunctional
fontSize (localStorage)Remembers accessibility font-size preferenceUntil clearedFunctional
activeCallId (sessionStorage)Allows the call-in-progress indicator to persist across page navigationUntil tab closedFunctional

3. What we don't do

For clarity about what we don't use:

  • No third-party advertising or retargeting cookies (no Google Ads, Facebook Pixel, etc.)
  • No third-party behavioral analytics (no Mixpanel, Heap, Amplitude)
  • No cross-site tracking
  • No social media share-button trackers
  • No fingerprinting
  • No cookies on the marketing site (casemgmt.io homepage, pricing, features, etc.) beyond what's required for the contact form

This minimalism is intentional. As a HIPAA-eligible platform handling Protected Health Information, we are conservative about third-party data flows. Adding behavioral tracking would create additional data-flow risks we choose not to take.

4. Managing cookies

Because we use only strictly-necessary cookies, there is no cookie banner or consent prompt on casemgmt.io. The cookies we use are required for the Service to function — disabling them will prevent you from logging in or using the platform.

You can clear cookies or local storage at any time through your browser settings. Doing so will log you out and reset any preferences (theme, font size).

Browser cookie management

5. Do Not Track

We do not respond to Do Not Track (DNT) browser signals because we do not perform any cross-site tracking that DNT would affect. All cookies we use are essential to the Service.

6. Changes to this policy

We will update this Cookie Policy if we introduce any new cookies, change the purpose of existing cookies, or update durations. The "Last updated" date at the top of this page reflects the most recent revision. Material changes will be communicated via email to account holders.

7. Contact

Questions about this Cookie Policy: