Cookie policy
We run no analytics and no advertising, so this is a short policy. It covers everything this site and the product behind it store in your browser, and what each of them is for.
- Version
- 3.0
- Last updated
- 19 September 2026
- Effective
- 19 September 2026
What changed
Version 3.0 replaces version 2.0.
- Disclosed, having been missed: inside the product we set one cookie of our own, which remembers the site whose rota you last had open so that the rota opens on it. Version 2.0 said cookies were set for one purpose, keeping you signed in, and that was wrong from the day the memory shipped.
- Section 4 now makes the case for having no banner in two parts, because the answer is not the same for both: the sign-in cookies, and the site memory, which only ever reaches a browser that has already signed in.
- Section 2 describes what the sign-in cookies do by purpose rather than tabulating them. Version 2.0’s table read as a complete list of Clerk’s cookies and was not one. Names and lifetimes are still not printed, and section 2 says why.
- Section 3 states that the claim about local and session storage is re-checked at each release. Version 1.0 of this policy was wrong about exactly that.
- New section 5: what the public pages load from anybody else. Clerk’s sign-in script is loaded on every page so that signing in works from anywhere on the site, and that is the whole list — no analytics tag, no advertisement, no embedded content, and typefaces served from rotaaa.app rather than fetched from a font service.
- New section 7: how a change to this policy reaches you, and that storage which is not strictly necessary is published, and consent asked for, before it runs rather than after.
1. The whole of it, in one paragraph
We store two things in your browser and each has one job. The cookies that keep you signed in, which are Clerk’s; and, once you are signed in, one cookie of ours that remembers which of your sites you last had a rota open for, so that it opens on that one. There are no analytics cookies, no advertising cookies, no third-party trackers, no pixels and no fingerprinting. Nothing we set reaches the browser of somebody who has not signed in. Clerk’s sign-in script is loaded on the public pages as well, so that signing in works from wherever you are when you decide to, and section 5 says what that means.
2. What is set, and what each thing is for
The sign-in cookies. Authentication is handled by Clerk, our authentication provider, and these are Clerk’s. They are set in the course of the sign-in exchange between your browser, rotaaa.app and Clerk, and what they do is carry that exchange and keep you signed in afterwards, so that every page you open knows who you are without asking again.
They are strictly necessary in the sense the law uses: without them there is no way to stay signed in from one page to the next, which is the entire product. They cannot be switched off without signing out, and there is nothing to consent to, because refusing them is refusing the service you asked for.
How many there are, what they are called and how long each lasts are Clerk’s to set, and they differ between a development instance and a production one, so they are not printed here — a list that is wrong is worse than a description that is right. The current list is published in Clerk’s own documentation at clerk.com.
The site memory. Inside the product we set one cookie of our own. It holds the identifier of the site whose rota you last had open, under a name that includes your organisation’s address on rotaaa.app, and it lasts a year. It is there because a planner who runs the fourth of your sites should not have to start at the first one every morning.
It is a default, not a permission. The identifier in it is re-checked against the sites you are actually allowed to open on every request, so one left behind in a shared browser can never show anybody something they could not already reach. It holds nothing about you — no name, no account, no address — and it is written by your browser after a page has loaded, only when you are signed in, and never on the public pages. Clearing this site’s cookies removes it, and the rota opens at your first site until you pick another.
3. Storage that is not a cookie
The law treats anything stored on or read from your device the same way, whether or not it is a cookie, so this covers the rest of it.
Rotaaa writes nothing to your browser’s local or session storage. A theming script reads a theme value before the page paints, but nothing ever sets one: the product renders in light mode only and has no theme switch. If a value is there, it is left over from an earlier visit, and it is never sent anywhere.
That is the one claim on this page a single careless import could falsify, and version 1.0 of this policy did get it wrong — it said a theme preference was remembered when nothing was writing one. So it is re-checked at each release rather than assumed, and if it ever stops being true this page is revised before the storage starts.
Clerk’s own script may use browser storage as part of maintaining your session. That is part of the sign-in described above, and is covered by the same necessity.
5. What the public pages load
One thing, and it is the sign-in. Clerk’s script is loaded on every page of the site, including this one, so that signing in works from wherever you happen to be when you decide to. Loading it means your browser contacts Clerk.
Nothing else. There is no embedded video, no map, no social button, no comment widget, no advertisement and no analytics tag anywhere on this site, and the typefaces are served from rotaaa.app rather than fetched from a font service — they are downloaded once when the site is built, not once by every reader.
That matters beyond cookies: a request to a third party hands that third party your address and the page you were reading, with or without a cookie attached. The sign-in script is the only such request a public page here makes.
7. If this ever changes
Adding anything that is not strictly necessary — a product analytics tool, a chat widget, an error reporter that runs in your browser — means revising this page first and asking for your consent before it runs, not after. That is the order the law requires and the order we hold ourselves to. As of version 3.0, nothing of the kind is present.
Every revision carries a version number, an effective date and a list of what moved, at the top of this page. That is how you would see it had happened. What is held about you more broadly, and the rights you have over it, are set out in the privacy notice.
Questions about this document
Rotaaa is built and run by one person, and questions about the cookie policy go to them directly. The routes are on the contact page, and support answers the questions that come up most often.