Last updated: August 12, 2026
Cookie Policy
This page explains exactly what Cerno stores on your device. The short version: one cookie, only after you sign in, and nothing else.
Cerno is a product of Aubora. The controller is Arthur Franco, acting on behalf of Aubora, a company in formation (société en formation), Paris, France. Our Privacy Policy explains the rest of what we do with personal data.
What a cookie is
A cookie is a small text file a site asks your browser to keep and to send back on later visits. Similar technologies — local storage, session storage, device identifiers, tracking pixels — do the same job by other means. Where this page says "cookie", it covers all of them.
The cookies we actually set
rocket_session. This is the only cookie Cerno sets in ordinary use, and it is set only once you sign in. It keeps you signed in. It holds a signed token identifying your account, and it lasts seven days. It is flagged HttpOnly, so scripts running in the page cannot read it; SameSite=Lax, which stops it being sent along with requests originating from other sites; and Secure in production, so it is only ever transmitted over HTTPS.
Be aware of one detail, because the honest description matters more than a reassuring one: that token is signed rather than encrypted, and alongside your account identifier it carries your name and your email address. Anyone able to read the cookie value off your device could read those. It is not a tracking identifier and it is never sent to a third party, but it is not opaque either.
cerno_oauth_nonce. If we later enable the optional mail and calendar connections, this cookie will exist for ten minutes while you complete the connection, purely to protect that step against cross-site request forgery. The feature is not active today, so in practice this cookie is not set.
Both are strictly necessary to deliver a service you have expressly asked for — being signed in, and being signed in safely. They are therefore exempt from the consent requirement under article 82 of the loi Informatique et Libertés, which is why Cerno does not show you a cookie banner.
What we do not set
We do not use functional or preference cookies. Your settings — onboarding progress, language, tone, the roles and locations you are interested in — are stored in your account in our database, not on your device, so they follow you between browsers rather than living in a cookie.
We do not use advertising cookies, tracking cookies, or third-party cookies of any kind. Nothing on this site profiles you, follows you to other sites, or is shared with an advertising network. There is nothing to opt out of, because there is nothing running.
Analytics without cookies
We measure how many people visit which pages using Vercel Web Analytics, which is cookieless: it stores nothing on your device and reads nothing stored there. It records the page URL and the referring URL, and derives a short-lived hash from the incoming request to distinguish a returning visitor from a new one; that hash is discarded after twenty-four hours. What we get is aggregate statistics, never an individual profile. The Privacy Policy sets out why this narrow form of audience measurement is exempt from the consent requirement under article 82 of the loi Informatique et Libertés and the CNIL's deliberation n° 2020-091 of 17 September 2020.
Managing cookies
You can view, block, and delete cookies in your browser's settings, and Cerno will keep working — you will simply be signed out when you delete the session cookie, and you will need to sign in again. There is no in-product cookie setting because there is no optional cookie to switch off.
Contact
For questions about cookies, or any other data protection matter, write to privacy@aubora.co.
For help with the product, write to contact@cerno.me.