Cookie Policy
Last updated: 27 September 2026
This policy lists every cookie and every entry in browser storage that Jein (jein.dev) uses, on this website (https://jein.dev), in the dashboard (https://app.jein.dev) and during login at our identity provider Auth0. A German version is available at https://jein.dev/cookie-richtlinie/. The English version is binding; the German version is a courtesy translation. How we process personal data in general is described in the privacy policy at https://jein.dev/privacy/.
Legal basis
Storing information on your device, or reading it from there, requires your consent under § 25(1) of the German Telecommunications Digital Services Data Protection Act (TDDDG), unless it is strictly necessary to provide a service you have expressly requested (§ 25(2) No. 2 TDDDG).
- Strictly necessary cookies and storage keep you signed in, protect forms against forgery, carry a one-time message to the next page, or remember a choice you made (your cookie choice, colour theme, code-sample language). They need no consent. Where they involve personal data, the legal basis is Article 6(1)(b) GDPR (contract) or Article 6(1)(f) GDPR (our legitimate interest in a secure, usable service).
- Statistics (website analytics with Plausible) run only with your consent, § 25(1) TDDDG and Article 6(1)(a) GDPR.
We use no advertising or marketing cookies and no cookies from social networks.
This website
| Name | Type | Provider | Purpose | Lifetime | Category |
|---|---|---|---|---|---|
jein-consent |
Local storage | Jein | Remembers whether you accepted or rejected statistics, and when. Contains only the choice and a date | Until you delete it; we ask again after 12 months or when we add a purpose that needs consent | Strictly necessary |
__cf_bm |
Cookie | Cloudflare, Inc., for our host DigitalOcean | Bot protection at the edge network: distinguishes automated traffic from people | 30 minutes | Strictly necessary |
Statistics (only with consent): if you accept statistics, the website loads the Plausible Analytics script from plausible.io. Plausible sets no cookies and writes nothing to your browser's storage; its script only reads one local-storage entry (plausible_ignore) that lets site owners exclude their own browser. It sends a request for each page view and each custom event: "Signup CTA" (signup-button clicks), "Docs link" (documentation-link clicks) and "Sandbox run" (successful sandbox runs, without text, question, options or answer). It also sends, when you leave or hide a page, one request with how far you scrolled and how long the page was in view. What it measures is described in the privacy policy at https://jein.dev/privacy/.
Without your consent, the website loads no analytics, and the only cookie is the bot-protection cookie __cf_bm.
Dashboard and API (https://app.jein.dev)
All cookies of the dashboard are first-party cookies. Those set by our own server are HttpOnly (not readable by scripts), SameSite=Lax, sent only over HTTPS, and their content is encrypted and authenticated (AES-256-GCM).
| Name | Type | Provider | Purpose | Lifetime | Category |
|---|---|---|---|---|---|
__Host-jn_session |
Cookie | Jein | Keeps you signed in. Contains internal account and user ids and a security token against cross-site request forgery; no e-mail address | 12 hours, or until you sign out | Strictly necessary |
jn_login |
Cookie (path /auth) |
Jein | Protects the login in progress (state, nonce and verifier of the login flow) | 10 minutes; deleted when the login completes | Strictly necessary |
jn_pending |
Cookie | Jein | Carries your verified e-mail address and Auth0 user id from login to the signup page, where you accept the Terms | 10 minutes | Strictly necessary |
jn_key_flash |
Cookie (path of one key page) | Jein | Shows a newly created API key once, on the page after creation | 60 seconds; deleted when read | Strictly necessary |
jn_goodbye |
Cookie (path /goodbye) |
Jein | Shows the confirmation of what was deleted after you delete your account | 5 minutes; deleted when read | Strictly necessary |
jein_theme |
Cookie (set by script) | Jein | Remembers the colour theme you picked (light, dark or system) | 1 year | Strictly necessary (your setting) |
jein.lang |
Local storage | Jein | Remembers the language you picked for code samples in the docs | Until you delete it | Strictly necessary (your setting) |
__cf_bm |
Cookie | Cloudflare, Inc., for our host DigitalOcean | Bot protection at the edge network: distinguishes automated traffic from people | 30 minutes | Strictly necessary |
Apart from __cf_bm, the API (/v1/…) sets no cookies; it is authenticated with API keys.
Login at Auth0
When you sign up or sign in, you are sent to the login page of our identity provider Auth0 (Okta, Inc.), which sets its own cookies on its login domain. They are strictly necessary for the login you requested.
| Name | Provider | Purpose | Lifetime | Category |
|---|---|---|---|---|
auth0, auth0_compat |
Auth0 | Login session at Auth0, so you are not asked for your password again right away (_compat is a fallback for older browsers) |
Set by Auth0 according to our login session settings | Strictly necessary |
did, did_compat |
Auth0 | Device identifier used for attack protection (for example against credential stuffing and brute-force attacks) | Set by Auth0 | Strictly necessary |
auth0-mf, auth0-mf_compat |
Auth0 | Only if you use multi-factor authentication and choose to remember this browser | Set by Auth0 | Strictly necessary |
More information: https://auth0.com/docs/manage-users/cookies/authentication-api-cookies.
Changing or withdrawing your consent
Use the "Cookie settings" link at the bottom of every page of this website to change your choice at any time. Withdrawing consent is as easy as giving it and has effect for the future.
If your browser sends a Global Privacy Control (GPC) signal, we treat it as a refusal of statistics and do not show the banner. We do not treat the older "Do Not Track" setting as a signal, as it has been abandoned by browsers.
You can also delete cookies and local storage in your browser settings. If you delete the dashboard cookies, you are signed out; if you delete jein-consent, we ask for your choice again.
Changes
We update this policy when we add, change or remove a cookie or storage entry. The date at the top shows the latest version. If we add a new purpose that needs consent, we ask for your consent again.