Cookie Policy
One cookie, and it is the one that keeps you signed in.
Last updated 31 July 2026.
The session cookie
Signing in with GitHub sets mergesmith_session — a random token that proves it is still you on the next request. The server stores only a SHA-256 hash of it, so the cookie in your browser is the only copy that exists. It is HttpOnly and Secure, and signing out ends it.
Analytics
Vercel’s analytics and performance measurements run on the site. They count visits and timing; they do not set advertising cookies or follow you across other sites.
Nothing else
No advertising cookies, no cross-site trackers, no fingerprinting. There is no cookie banner because there is nothing to opt out of — the one cookie is the sign-in itself.
MergeSmith