DeepLeaf sets no advertising, analytics, or tracking cookies, and loads nothing from other websites. That is why there is no cookie banner: the only cookie is one the service cannot work without.
The sign-in cookie
When you sign in to the app with your organization key, DeepLeaf sets one cookie, deepleaf_key. It keeps you signed in so pages and walk images load without asking for the key again.
- Purpose: strictly necessary, to keep you signed in.
- Lifetime: 30 days, or until you sign out, which deletes it.
- HttpOnly: scripts on the page cannot read it.
- SameSite=Strict: your browser never sends it with requests started from another website.
- Secure: sent only over HTTPS.
The public pages (this site, the docs, pricing) set no cookie. DeepLeaf operators have a separate console sign-in cookie with the same protections and an 8-hour lifetime; customers never receive it.
Storage in your browser
The site and the app also keep a few values in your browser's own storage. They are not cookies, are never sent to DeepLeaf, and stay on your device:
- your chosen theme (light or dark) and language;
- in the app, your organization's name and role (never the key) and the crop cycles you last picked, so the app can open without a connection; cleared when you sign out;
- walks waiting to upload, and a copy of the app's own files, so it works offline.
You can clear all of this in your browser's settings. Clearing the sign-in cookie signs you out.
Changes and questions
If DeepLeaf ever adds a cookie that is not strictly necessary, this notice will say so first, and the site will ask for your consent before setting it.
Questions: write to hello@deepleaf.io.