Public information

Cookie and browser-storage information

Last updated 7 September 2026

Essential sign-in storage

Elfar Bridge uses API-host-only, secure, HTTP-only refresh cookies to maintain an authenticated session. Access tokens and dashboard session state are held in the browser’s session storage and are removed at sign-out. These controls are necessary to provide an authenticated service.

Remembered email

If a person chooses the remember-email option, the normalized sign-in email is stored in local browser storage on that device. It can be removed with “Forget saved email.” Passwords are not stored by Elfar Bridge in browser storage.

Security services

Cloudflare Turnstile may set or read strictly necessary security data to distinguish legitimate requests from automated abuse. Elfar Bridge does not configure advertising or cross-site marketing cookies in its dashboards.

Your control

Signing out clears Elfar Bridge session storage. Browser settings can clear local storage and cookies, although blocking necessary security or session storage may prevent sign-in.