Cookies
Oat uses cookies to keep you signed in and to protect an account connection while it happens. That is the whole list.
Last updated 23 September 2026
What is set
| Cookie | Set by | Purpose | Lasts |
|---|---|---|---|
| Session cookies (names beginning __session and __client_uat) | Clerk | Keeps you signed in and lets the server verify who is making a request | Your session; refreshed while you use the desk |
| oat_oauth_<provider> | Oat | Holds a one-time nonce while you connect an outside account, so a replayed or cross-workspace callback is rejected | 15 minutes, deleted when the connection completes |
Both are strictly necessary for the service to work, so they are set without a consent banner. They are httpOnly where the browser allows it and are never readable by scripts on the page.
What is not set
There are no analytics tags, no advertising pixels, no social-media embeds and no marketing cookies on this site or on the desk. We do not fingerprint browsers and we do not use local storage to track you. If that changes, this page changes first and a consent choice appears before any such technology runs.
Third-party services you connect
When you sign in to a provider to connect an account, that provider sets its own cookies on its own domain during the sign-in. Those are governed by the provider's policy, not this one.
Controls
Your browser lets you view and delete cookies at any time. Deleting the session cookie signs you out. Blocking cookies entirely stops the desk from working, because it cannot tell who you are without one.
Questions go through the contact page. The privacy notice covers everything else we collect.

