Cookie Policy
What the website and the console store in your browser, what each item is for, and how to remove it.
Last updated 11 September 2026
The short version. waymail.app sets no cookies and runs no analytics. The console keeps three values in your browser's session storage until you close the tab, and Clerk, which signs you in, sets the cookies that keep you signed in. Nothing is used for advertising or to follow you across sites, so there is no cookie banner to click.
1. What this policy covers
This policy covers cookies and similar browser storage — session storage and local storage — set by waymail.app, including the documentation, and by the Waymail console at console.waymail.app. It supplements the Privacy Policy, which says what we do with the data these items hold.
It does not cover the email our customers send through Waymail. Section 6 says where that is covered instead.
2. The website: waymail.app
The website and the documentation are static pages. They set no cookies, use no analytics, and load no scripts, fonts or other content from third parties. The web host, Amazon CloudFront, keeps no access log of your visit.
The only thing a page does in your browser is note, for its own styling, that scripts are running and whether you have asked your operating system for reduced motion. Neither is stored anywhere.
3. The console: console.waymail.app
The console needs to remember a few things to work at all. Everything it stores is listed here. The first three live in your browser's session storage, which belongs to one tab and is emptied when that tab closes.
waymail.console.token |
Session storage. The credential you pasted to sign in — an API key, or a session token when running the console locally — so it is available on each request and no longer than the tab. If you sign in with a Clerk account, this entry is not used: the console asks Clerk for a short-lived token on every request. |
|---|---|
waymail.console.region |
Session storage. Which region your workspace lives in, so the console talks to that region's API and your data does not cross to another. An API key carries its own region, so it is only needed for account sign-in. |
waymail.console.workspace |
Session storage. Which workspace you are acting in, when you belong to more than one. |
__session |
Cookie, set by Clerk. Your signed-in session, for as long as you are signed in. |
__client_uat |
Cookie, set by Clerk. Notes when your sign-in state last changed, so the console knows whether to check with Clerk before showing you a page. |
| Cloudflare Turnstile | During sign-up and sign-in, Clerk's bot check runs in a frame from challenges.cloudflare.com, which may set a cookie of its own for the duration of the check. It tells people from automated sign-ups; it is not used for anything else. |
All of these are strictly necessary: without them you cannot sign in, or the console cannot tell which workspace and region you mean. None is used to track you, and none is shared with an advertiser or an analytics service.
4. Why there is no consent banner
The EU ePrivacy rules, and Norway's implementation of them, require consent before storing something in your browser — except when the storage is strictly necessary to provide a service you asked for. Everything on this page is in that category. There are no advertising cookies, no analytics cookies and no third-party tracking, so there is nothing to ask consent for and no banner.
If that ever changes, we will update this policy first and ask you before setting anything new.
5. How to clear them
- Close the tab. Session storage is emptied with it, so your pasted credential, region and workspace choice are gone. Signing out clears them straight away as well.
- Sign out. Signing out of the console ends your session with Clerk. Clerk's cookies can also be removed through your browser's settings, under the site data for console.waymail.app.
- Block them. You can block cookies or storage for console.waymail.app in your browser. Blocking Clerk's cookies means you cannot stay signed in; blocking session storage means the console forgets your region and workspace on every reload, and asks for your credential again.
6. Email you receive from our customers
If a Waymail customer emails you, their message may contain an open-tracking image or click-tracking links. Those belong to the sender, are off unless the sender switches them on, and set nothing in your browser through this site. They are described in the Privacy Policy under Email sent through Waymail, which is the policy that covers them — not this one. The organisation that sent the email is the one to ask about it.
7. Changes
When this policy changes, we update the date at the top. If we ever add a cookie or storage item that is not strictly necessary, we tell you here and ask for consent before it is set.
8. Contact
Questions about cookies or browser storage: hello@waymail.app. Our legal identity and postal address are on the Company Details page.