TillDevTillDev
Sign inStart free →
LEGAL
Privacy policyWhat we collect, and whyTerms of serviceThe contractSecurityControls + disclosureCookiesThe five we setData processingProcessor termsAcceptable useThe hard lines
The fine print, plainly

Every document here is written to be read. Questions: legal@tilldev.dev

LEGAL · COOKIES

Cookies

Updated May 2026

TillDev uses strictly necessary cookies only. We do not use third-party advertising or marketing cookies, and we do not sell tracking data.

§ 01#

What we set

NamePurposeLifetimeType
tp_accessShort-lived signed token used to authenticate API and dashboard requests.Short-livedhttpOnly · SameSite=Lax · Secure
tp_refreshRefresh token used to mint new tp_access cookies. Rotated on every use.PersistenthttpOnly · SameSite=Lax · Secure
tp_sso_pkceCarries the sign-in flow state across the SSO redirect.Brief (single-use)httpOnly · SameSite=Lax · Secure
tp_csrfCSRF-protection token for state-changing dashboard requests.SessionSameSite=Lax · Secure
tp_themeOptional, set when a user picks a non-default theme.1 yearSameSite=Lax · Secure
§ 02#

What we do not set

  • No third-party advertising cookies.
  • No tracking pixels or marketing trackers.
  • No cross-site fingerprinting.
§ 03#

Why we don't show a banner

Strictly necessary cookies under most regulations (GDPR, POPIA, NDPA) do not require consent — they are essential to deliver a service the user has asked for (signing in, staying signed in, completing an SSO flow). If we ever introduce non-essential cookies, we will gate them behind a real consent banner.

§ 04#

Disabling cookies

You can clear or block cookies in your browser settings, but the dashboard won’t function — sign-in won’t survive the redirect. SDKs do not use cookies; they use HTTP requests with header-based auth. Disabling browser cookies has no effect on TillDev SDK telemetry.

§ 05#

Third-party services in the dashboard

We load fonts from Google Fonts (preconnect to fonts.googleapis.com and fonts.gstatic.com) and the world map from a public TopoJSON CDN on the Field Map page. Neither sets cookies in our hosting context.

§ 06#

Questions

Email privacy@tilldev.dev.

Related reading: the Privacy policy and Terms of service.

‹ PreviousSecurityNext ›Data processing
TillDevTillDev

Seven pieces of the same idea: host the code, ship the thing, see what happened, sign people in, keep the data fast and safe, seal your secrets, and keep a way back.

System status →
PRODUCTS
  • TillPulse
  • TillAuth
  • TillShield
  • TillGate
  • TillCache
  • TillSecrets
  • TillArk
  • TillForge
  • TillStudio ↗
DEVELOPERS
  • Documentation
  • TillPulse docs
  • TillAuth docs
  • API reference
  • Changelog
COMPANY
  • About
  • Support
  • Status
  • hello@tilldev.dev
LEGAL
  • Privacy
  • Terms
  • Security
  • Cookies
  • Data processing
  • Acceptable use
© 2026 TillDev. Built honestly.tilldev.dev · tilldev.app