What the Harbor dashboard uses
| Storage | Purpose | Lifetime |
|---|---|---|
paas_sessionFirst-party cookie | Authenticates your signed-in session. HttpOnly and SameSite=Strict; Secure on HTTPS. | 24 hours from sign-in, or until sign-out expires the cookie. |
harbor-essential-noticeLocal storage | Remembers that you dismissed the essential-storage notice. It is not a tracking ID or marketing consent. | Until you clear site storage in your browser. |
Your controls
Use the persistent “Cookie settings” button to reopen the notice and “Dismiss notice” to hide it. These actions do not grant marketing consent or disable the sign-in cookie. No optional analytics or advertising trackers are installed by Harbor, so there is no pretend “accept all” or analytics preference.
Your browser can block or delete cookies and local storage. Blocking the session cookie prevents sign-in; clearing it signs you out in that browser but does not delete your account or necessarily revoke the server session before its expiration. Use Sign out to revoke the current session. Clearing local storage makes the notice appear again. Private browsing or storage restrictions may prevent a saved dismissal.
Other services
Stripe Checkout and its customer portal are separate pages and may use storage for payment, fraud prevention, and other purposes described in Stripe’s cookie policy. Harbor does not load Stripe JavaScript or an embedded payment widget on these pages. Hosted apps and services you connect have their own storage and privacy behavior; this inventory covers the Harbor dashboard, not every app instance.
See the privacy notice for server-side records and contact rights.