Cookies
Last updated 9 October 2026.
within uses two cookies, both needed to keep you signed in and safe. Nothing for advertising, nothing for analytics, nothing from anyone else — which is why there’s no cookie banner to dismiss.
The cookies
- within-session — keeps you signed in on this browser. Set for this site only, not readable by scripts, and it expires when your session does.
- XSRF-TOKEN — proves a form was sent from within itself, so another site can’t act on your behalf.
What we keep on your device
A few things live in your browser’s own storage rather than in cookies. They never leave your device:
- Your microphone choice, if you pick one in Settings.
- That you dismissed the “add to home screen” hint, so it doesn’t come back.
- A short resend timer while you wait for a sign-in code.
- within’s own app files, cached so it opens quickly and can tell you when you’re offline. Never your voice lines.
Your choices
Because these are strictly necessary, there’s nothing to opt out of without within stopping working. You can clear them any time from your browser’s settings; you’ll just be signed out. Questions? Email [email protected].