New: the coverage agent now explains every pick

Legal

Cookie policy

Last updated July 2026 · Draft. Review by counsel before you rely on it

Why you have not seen a cookie banner

Because there is nothing to ask you about. Formclock sets no analytics cookies, no advertising cookies, and no third-party tracking of any kind. Every cookie below exists to keep you signed in, keep you in the right workspace, or remember whether you collapsed the sidebar.

Consent banners exist so that you can refuse tracking. We do not track you, so a banner would be theatre: a click you have to make in order to be told nothing is happening.

If we ever add product analytics, this page changes and you will be asked properly. That is a promise about a future decision, and it is the only kind of promise on this page.

Cookies we set

fc_org. Which workspace you are working in. Necessary. Server-set, not readable by scripts, expires after a year.

fc_actor. Which employee you are acting as. This exists for demos and development, and in production it is only honoured alongside a real signed-in session, so it cannot be used to impersonate anyone. Necessary. Server-set, not readable by scripts, expires after a year.

fc_signup_intent. Remembers that you clicked sign up rather than sign in, so that returning from Google lands you in the right place. Necessary. Server-set, not readable by scripts, expires after ten minutes.

sidebar_state. Remembers whether you collapsed the navigation. A preference, not a necessity, and the one cookie on this list that is readable by scripts, because the interface reads it. Expires after a week.

Cookies our sign-in library sets

Formclock uses Auth.js for sign-in, which sets a session cookie, a CSRF token and a callback URL. These are strictly necessary: without them you cannot sign in, and the CSRF token is part of how we stop somebody else submitting a form as you. The session cookie expires after 7 days.

Things stored in your browser that are not cookies

Your email address, if you have signed in before, so the sign-in screen can offer it back to you instead of making you type it again. It never leaves your browser except when you sign in.

A random device identifier on a shared clock-in tablet, which lets us rate-limit PIN attempts per device rather than per workspace. It identifies the tablet, not the person.

Your theme preference, and whether you dismissed the setup checklist.

All of these are held in your browser's local storage, and clearing your browser data removes them.

What we do not use

No Google Analytics. No Google Tag Manager. No advertising or remarketing pixels. No Facebook, LinkedIn or X tracking. No session recording or heatmaps. No PostHog, Plausible, Mixpanel or Segment. No support chat widget.

This is not aspiration. There is no such code in the product, and the browser is prevented from calling third-party servers by our content security policy, so one could not be added quietly by accident.

Contact

privacy@formclock.com

© 2026 Formclock. All rights reserved.