The short version
DNMS is a workplace application, not an ad-supported website. We set no advertising cookies, no cross-site tracking cookies, and no third-party analytics cookies. Every cookie below is either required to keep you signed in and safe, or remembers a preference you chose.
Strictly necessary
These cannot be switched off. Without them the application cannot authenticate you, and blocking them will prevent you signing in.
- authjs.session-token
- Your signed-in session. Encrypted, HTTP-only, and on HTTPS also marked Secure. It carries your identity, workspace and permissions. Expires 30 days after issue, sooner if you sign out.
- authjs.csrf-token
- Protects sign-in and form submissions against cross-site request forgery. Session-lifetime.
- authjs.callback-url
- Remembers the page you were heading to so you land there after signing in rather than on a generic screen. Session-lifetime.
Preferences
- theme
- Stores your light or dark appearance choice so the interface does not flash the wrong theme on load. Set only if you change it from the system default.
Local storage
Alongside cookies, the application uses your browser's local storage for interface state: collapsed panels, table filters, drafts you have not sent. This never leaves your browser and is not transmitted to us. Clearing site data removes it.
Third parties
If you sign in with Google, Google sets its own cookies on its own domain as part of that flow, governed by Google's policies rather than ours. Files served from Backblaze B2 are delivered through expiring signed links and set no cookies of ours.
- Backblaze B2
- Object storage for uploaded files - employee documents, project assets, gallery images and email artwork. Files are served through expiring signed URLs, never from a public bucket.
- Google (Sign-In)
- Optional single sign-on for staff accounts. We receive your name, email address and profile picture. We never receive your Google password.
Questions
Write to privacy@digitallynext.com.

