Cookie policy
Last updated: 3 August 2026
This marketing site sets no cookies of its own. The app sets the ones it needs to keep you signed in. There is no advertising and no cross-site tracking on either. This page lists what is set, by whom, for how long, and what happens if you block it.
The website
Applies to This website — timemellow.com
timemellow.com sets no cookies of its own. Nothing on these pages stores an identifier in your browser. It can read one existing cookie — the app's sign-in marker, solely to word links appropriately, unless you turn that off below. Two other things involve limited information without any cookie at all:
- Analytics is a self-hosted Umami instance we run ourselves, not a third-party network. It sets no cookies and stores nothing in your browser. To tell visits apart it computes a short-lived identifier on our server by hashing your IP address and browser details with a key that rotates daily — it can distinguish visits within a day, but cannot recognise you tomorrow, follow you to another site, or connect a visit to an account. The privacy policy lists what it records and for how long. It never receives anything you type, and you can turn it off below.
- Prices in your currency come from the country Cloudflare has already attached to your request by the time it reaches us. We read that, return a country code, and store nothing — no cookie, no profile, and the IP address itself is not stored or logged.
Links for existing users
If the timemellow app has left a sign-in marker in this browser, this website checks whether it is present so that links can use more appropriate wording — "Open timemellow" rather than asking you to start again, because being told to sign up for something you are already signed into is confusing.
We check only whether Clerk's __client_uat marker has a non-zero value. We do not read your
session, identify your account, or learn your name or email. The result is used once, to present the
appropriate links on the page: it is not retained, logged, included in analytics, or used to choose any
content beyond that wording — both versions of every link go to exactly the same place.
This is on by default, and turning it off stops the website checking the marker entirely — everyone gets the same wording. Your choice is stored in this browser's local storage, not in a cookie, so clearing this site's data clears the choice and restores the default.
Turning analytics off
Analytics runs without consent under the statistical-purposes rules, which require that we make objecting simple and free. Two ways, either is enough:
- The switch. Use the control below to turn analytics off for this website in this browser. The app has its own copy of the switch in Settings — the two are separate on purpose, so each controls exactly what it says. Turning either off stops the analytics script loading at all on that surface; nothing further is recorded from that browser.
- Global Privacy Control. If your browser sends the GPC signal (or the older "do not track" setting), we treat it as an objection and do not load analytics — no switch needed.
The off switch is itself stored in your browser — a single flag recording your choice, which is what makes it stick. Clearing site data clears the flag, and analytics resumes on your next visit unless your browser sends GPC.
Cookies you may still see here
These are not set by this site, but they can appear while you are on it.
| Cookie | Set by | Lifetime | What it does |
|---|---|---|---|
__cf_bm |
Cloudflare | Up to 30 minutes | Bot management, set by the network in front of this site rather than by the site itself. It holds a value Cloudflare uses to tell browsers from bots; Cloudflare documents it as not being used to identify or track individual people across sites. |
__client_uat |
Clerk, through the timemellow app | See the app table below | The app's sign-in marker, set for the whole domain, so it is visible here too. Unless you have turned existing-user links off, this website checks only whether it has a non-zero value, to word links appropriately — nothing is retained or sent anywhere. Its full description and lifetime are in the app's table below. |
| Turnstile challenge storage | Cloudflare | Duration of the check | Only if you open the Teams waitlist form. Turnstile is the anti-spam check that replaces a CAPTCHA; it may hold temporary values in your browser while the check runs. It exists to tell a person from a script. |
The app
Applies to The app — app.timemellow.com
The app needs cookies to know you are signed in. Everything below is strictly necessary in the ordinary sense of
the phrase — block it and the feature stops rather than degrades. Clerk sets some of these twice, once plainly
named and once with a key-specific suffix (e.g. __session_…) — same cookie, same purpose, listed
once here.
| Cookie | Set by | Lifetime | What it does |
|---|---|---|---|
__session |
Clerk, our sign-in provider | Up to 12 months in the browser | The session itself: a signed token proving you are you, refreshed continuously while you use the app. Every request that reads or writes your synced data is authorised from it. The cookie can live up to a year, but how long you actually stay signed in is governed by the session settings on our sign-in provider's side, not by the cookie's lifetime. It relates to your account, so it is personal data, handled as the privacy policy describes. Blocked, you cannot sign in — so sync, backups and overview emails are all unavailable. |
__client_uat |
Clerk | Up to 12 months | A timestamp marking that a session exists, so the page can render the right state before the session has finished loading. It is set for the whole timemellow.com domain, and this website reads it for exactly one thing: the existing-user links described above, which you can turn off. Beyond that non-zero check the value is not inspected, stored, or copied into analytics or anything else. It carries no name or email, though as a marker tied to a signed-in browser it is still treated as personal data. |
clerk_active_context |
Clerk | Until the tab or browser closes | Clerk's internal record of which session is active in this browser. Housekeeping for the sign-in system, nothing more. |
| Sign-in infrastructure cookies | Cloudflare, via Clerk's servers | __cf_bm ~30 minutes; _cfuvid until the browser closes |
Clerk's own infrastructure sits behind Cloudflare, which sets bot-management and rate-limiting cookies against the sign-in domain during sign-up and sign-in. Security for the account system, not analytics. |
| Checkout cookies and storage | Paddle, and payment providers inside its checkout | Varies — see description | Only during a purchase, when Paddle's checkout opens. Paddle is the seller of record and an independent data controller for what it collects, so its privacy notice governs these, not this policy. We never see your card details. Observed at the checkout: a short-lived Cloudflare bot-management cookie on Paddle's own domain (~30 minutes), and functional checkout state — display settings, language, a checkout reference — kept in browser storage on Paddle's domain. The payment methods inside the checkout also set their own cookies under their own policies. Because we offer Google Pay, Google sets a cookie on google.com lasting around six months. |
The app's analytics is the same cookieless Umami instance as this site's, with the same off switch in Settings, and it never receives your account id or email — the only account-adjacent thing on an event is which plan you are on. Error monitoring is separate and also sets no cookies: no session replay, no tracing, and there you are identified only by an opaque id that means nothing outside our own systems.
Local storage in the app
Applies to The app — app.timemellow.com
Your browser's "clear cookies and site data" control also clears local storage. In the app, local storage holds three kinds of thing:
| What | What clearing it does |
|---|---|
| Your time log, on the Free plan. Everything you have entered — clients, projects, areas, entries, tags, settings — lives in local storage and nowhere else, because on the free plan your time data never reaches us | Deletes it permanently. This is why the app treats JSON export as a habit rather than a feature. On the Sync plan the same storage is a mirror of the copy on our servers, so clearing it costs you nothing |
| Device state: your last-used view, collapsed panels, a running timer, unfiled side timers, a half-finished entry draft, and the analytics off switch | Resets preferences on that device, discards a running timer, and clears the analytics choice |
| A copy of the internal account id, so a signed-in page can load your data without waiting on a round trip. The server re-checks your session on every request regardless | Nothing visible — it is refetched on next sign-in |
Why there is no cookie banner
Applies to The website and the app
UK law (PECR, as amended in 2026) requires consent for storage and access technologies unless an exception applies, and everything here sits inside one. The sign-in session, security checks and the app's local storage are strictly necessary — the service you asked for does not work without them. Analytics runs under the statistical-purposes exception, whose conditions are that it is used solely to produce statistics about the service, that this page tells you about it clearly, and that objecting is simple and free — the switch and the GPC signal above. Existing-user link adaptation runs under the appearance-and-functionality exception on the same terms: described plainly above, used for that wording and nothing else, with its own switch. A checkout you deliberately open is governed by Paddle. None of these uses requires prior consent because each meets the conditions of the exception described above.
Controlling all of this
Applies to The website and the app
Every browser lets you block or delete cookies and site data, per site or across the board. What to expect: this website carries on as before; the app signs you out and cannot sign you back in until session cookies are allowed; and on the Free plan, clearing site data for the app deletes your entries — export first, one click, on every plan. Analytics has its own switch above and in the app's Settings, and we honour the Global Privacy Control signal, so turning analytics off does not require touching cookies at all.
Contact
Applies to The website and the app
Questions about anything on this page: privacy@timemellow.com. See also the privacy policy, which covers what we hold rather than what your browser holds. The app keeps no legal pages of its own — it links back to these.