1. What this notice covers
This notice describes cookies and similar storage used by the Tallpine website and authenticated workspace. It supplements our Privacy Policy.
2. Essential sign-in and security storage
Tallpine and its authentication library use cookies to maintain a signed-in session, complete the Google OAuth flow, protect requests, apply rate limits, and prevent unauthorized access. These cookies are required for account access and expire or rotate according to the authentication configuration. Stripe may use its own cookies or similar technology when you visit Stripe-hosted Checkout or the Customer Portal.
3. Workspace browser storage
- Session continuity: browser-tab storage remembers recently started jobs and guards against repeated reloads after a stale application asset. It normally clears when the tab session ends.
- Workspace preferences: local storage remembers dismissed onboarding guidance and optional steps for a Site until you clear the data or change the preference.
- Flow continuity: bounded session or local storage may preserve Checkout source context long enough to connect a return navigation with the action that started it. Authentication sessions use the essential cookies described above. This flow storage does not contain Article or Source text. Pending authentication and Checkout attribution context is designed to expire after no more than two hours.
4. Analytics
When a complete analytics configuration is present, Tallpine uses Umami for privacy-bounded page views and product events. Umami does not set analytics cookies or follow visitors across websites. Tallpine removes dynamic workspace identifiers from routes and does not include names, emails, account IDs, payment details, customer-entered text, Article content, or Source content in analytics events.
5. Your controls
You can block or delete cookies and browser storage through your browser settings. Blocking essential cookies will prevent sign-in. Clearing local or session storage may reset onboarding choices, remove remembered job state, or interrupt an authentication or Checkout return flow, but it does not delete server-side account or workspace data.
6. Changes and contact
We may update this notice when storage practices change and will post a new effective date. Contact [email protected] with questions.