1. Summary#
Mentoring @ Invespire uses only cookies that are strictly necessary to sign you in and keep sign-in secure. We do not use analytics, advertising, social-media or tracking cookies, and we do not use similar technologies such as tracking pixels, fingerprinting or browser local storage for tracking. Two display settings you choose are remembered in your browser's local storage (section 4).
Because every cookie we set is strictly necessary for a service you ask for, the law does not require us to ask for your consent to them, so we do not show a cookie consent banner. This page tells you what they are.
3. Cookies we set#
All of these are set by our own site, are not readable by page scripts (http-only), are sent only over HTTPS, and are only sent back to our site.
- __Secure-authjs.session-token: keeps you signed in. It holds an encrypted record of your account ID, name, email address, access level, default view, time zone, whether your email is confirmed, which version of our Terms you last accepted, and a session version used to sign you out after a password reset, an email change or when you sign out everywhere. It may be split into parts named with .0, .1 and so on. It expires 30 days after it was last issued, and is deleted when you sign out.
- __Host-authjs.csrf-token: a security token set by our sign-in system on your first visit, on any page, whether or not you sign in. It protects the sign-in and sign-out forms against cross-site request forgery. It contains a random value, not personal data, and is deleted when you close your browser.
- __Secure-authjs.callback-url: set at the same time, on your first visit, by our sign-in system. It remembers which page to return to after signing in. It is deleted when you close your browser.
- __Secure-authjs.pkce.code_verifier, __Secure-authjs.state and __Secure-authjs.nonce: set only while you sign in with Google, to check that the reply really comes from Google and belongs to your sign-in attempt. They last up to 15 minutes.
4. Settings saved in your browser#
Your browser's local storage keeps these two settings, only after you choose them. They never leave your device, are not sent to us or anyone else, and contain no personal data. You can remove them by clearing your browser's site data.
- mc-theme: the colour theme you picked (system, light or dark).
- mc-tz-dismissed: that you chose to keep your current time zone when the dashboard suggested a different one, so the suggestion is not shown again.
5. Third-party content#
Our pages do not load third-party scripts. Fonts are served from our own site.
Some mentor profile photos are loaded from Google (for photos taken from a Google account) and Cloudinary (our image provider). When your browser fetches such a photo, that provider receives your IP address and browser details under its own privacy policy. Our pages tell your browser not to send the address of the page you are on with these requests.
The video-call services mentors use for sessions are separate websites with their own cookie policies.
6. Controlling cookies#
You can delete or block cookies in your browser settings. If you block our cookies, you will not be able to sign in, but you can still browse public mentor profiles.
7. Changes#
If we ever want to use cookies that are not strictly necessary (for example for analytics), we will update this policy first and ask for your consent before setting them.
Questions: info@invespire.com
Questions about this page? Contact us