Effective date: 1 October 2026

This Cookie Policy explains how drop/expired (dropexpired.net, “we”) uses cookies and similar technologies on dropexpired.net, app.dropexpired.net and api.dropexpired.net. It complements our Privacy Policy.

1. What cookies and local storage are

Cookies are small text files a website stores in your browser. Local storage, session storage and IndexedDB are similar browser features that keep data on your device. We refer to all of them as “cookies” in this policy.

2. The cookies we use

We use only strictly necessary cookies — those needed to provide the Service you ask for. They do not require consent under EU and UK law, and they cannot be switched off without breaking the Service.

Name Type Purpose Duration
dx_refresh First-party cookie (.dropexpired.net), HTTP-only, Secure, SameSite=Lax Keeps you signed in to the web app by renewing your short-lived session. It contains a random token, not your password. Until you sign out or the session expires; replaced on each renewal
dx.theme Local storage Remembers the light or dark theme you chose on the website Until you clear it
Language, theme and interface settings Local / session storage Remember your language and display preferences in the web app Until you clear them or sign out
Push notification registration IndexedDB / service worker (Firebase Cloud Messaging) Delivers browser push notifications, only if you turn them on Until you turn push off or clear site data
Security cookies Cookies set by Cloudflare Protect the Service against attacks and abusive traffic Short-lived, typically up to 30 minutes

The mobile and desktop apps store your session securely on the device instead of in cookies.

3. What we do not use

We do not use advertising, retargeting or cross-site tracking cookies, and we do not use analytics cookies. We do not let third parties place cookies on our pages to track you. If we ever add optional cookies, such as analytics, we will update this policy first and ask for your consent where the law requires it.

When you pay on the web, you are taken to Stripe’s checkout and billing pages, which are governed by Stripe’s own cookie and privacy policies.

4. Managing cookies

You can view and delete cookies and site data in your browser settings at any time, and block cookies for our sites. If you delete or block dx_refresh, you will be signed out of the web app and will not be able to stay signed in. Deleting local storage resets your theme and language preferences. Your browser’s help pages explain how to manage cookies.

5. Changes and contact

We may update this policy; the date at the top shows when it last changed. Questions: [email protected].