laces.

Laces.Social

Cookies and browser storage

Laces uses browser storage for sign-in, security, language and invitation continuity. This version does not include optional advertising or analytics trackers.

Laces.Auth — Sign-in
Keeps your account signed in. Its 14-day validity can renew with use. It is HttpOnly and SameSite=Lax, and requires HTTPS in production. Signing out ends this browser session.
Laces.Csrf — Request security
Helps prevent another website from sending actions on your behalf. It is an HttpOnly, SameSite=Strict session cookie, requiring HTTPS in production. Your browser controls session restoration when it is closed and reopened.
.AspNetCore.Culture — Language
Stores your choice of English or Portuguese for up to one year. It is HttpOnly and SameSite=Lax, and is sent over HTTPS when set on an HTTPS connection. You can change the language in the footer or Settings.
Pending invitation in this tab
A temporary invitation token is kept in sessionStorage while you sign in or create an account. It is removed after completion, handled invalidation or sign-out through Settings. Tab restoration may retain sessionStorage; you can also clear site data in your browser. The invitation token is not an advertising identifier.
Application files and private data
The browser can cache static application files to make loading faster. Fingerprinted files may be cached for up to one year. Private account and social API responses are marked no-store and are not public static assets. Page data is held in application memory.

Your browser controls

You can remove site data or restrict storage in your browser. Blocking security or authentication cookies may prevent sign-in and actions; blocking tab storage may interrupt an invitation. These controls do not delete data held on the server.

Privacy at Laces