Skip to content
Gemma Gemma
Features Pricing Privacy
Sign in Get started
Features Pricing Privacy
Sign in Get started
Privacy Policy Terms of Service Cookie notice

Cookie notice

Last updated 8 September 2026

This notice describes the cookies and similar storage Gemma actually uses. We do not set advertising, social-media, or third-party analytics cookies on Gemma pages. Bracketed fields such as Gemma are placeholders for the operator to complete.

Operator: Gemma · TBC

Cookies Gemma sets

Name What it does How long
gemma_cookie_consent Records whether you accepted or rejected Gemma’s required cookies. First visit shows a consent modal. Accepting lets you use the site. Rejecting blocks Gemma until you reload and accept. Not HttpOnly so the consent gate can read it. SameSite is Lax. One year, or until you delete it.
sessionid Django session cookie. Keeps you signed in, and holds short-lived server-side state such as Agent chats, MFA pending login, email-verification return path, and flash prompts. Marked HttpOnly so page scripts cannot read it. SameSite is Lax (Django default). Until you sign out, or about two weeks of inactivity (Django default).
csrftoken Cross-site request forgery protection. Gemma’s JavaScript reads this cookie so category, spend-kind, and similar updates can send a valid X-CSRFToken header. It is not HttpOnly for that reason. About one year (Django default), refreshed as you use the app.
messages Optional flash-message cookie (Django’s default message storage). Used for short notices such as “Your Gemma account was deleted.” after you are sent to sign in. Until the message is shown, typically the next page.

Session, CSRF, and the consent cookie above are required for Gemma to work. A first-visit modal asks you to accept them. If you reject, the site stays blocked until you reload the page and accept. There is no way to use Gemma with those cookies turned off.

Storage that is not a cookie

  • localStorage gemma-sidebar-closed. Remembers whether you closed the sidebar. It stays in the browser until you clear site data. It is not sent to Gemma’s servers with requests.
  • Server-side session data. The sessionid cookie is only a key. Agent conversations, MFA-pending state, and similar values live in Gemma’s session store (database), not in extra cookies. Signing out or deleting the account drops that store for you.

Third parties when you leave Gemma

Gemma pages load the Inter font from Google Fonts (fonts.googleapis.com / fonts.gstatic.com). That is a third-party network request for the typeface. We do not use it as an advertising pixel, and we do not set marketing cookies for it.

If you start a Premium checkout or open the billing portal, you use Stripe’s hosted pages. Stripe may set cookies on its own domain under Stripe’s policies. If you connect a bank, you use TrueLayer (and your bank’s) pages; those sites may set their own cookies. Gemma does not read those cookies.

Amazon SES, AWS hosting, Gemini, and Frankfurter FX lookups run on the server. They do not drop cookies in your browser through Gemma.

How to control them

You can delete Gemma cookies in your browser settings or use private browsing. To see the consent modal again (for example in local testing), delete the gemma_cookie_consent cookie for this site and reload. Signing out clears the authenticated session. Deleting your account from Settings flushes stored sessions for that user. Blocking sessionid or csrftoken will stop sign-in and form submissions from working.

More on data we hold, export, and deletion: Privacy Policy. Product terms: Terms of Service.

Gemma Gemma

Personal budget manager.

Features Pricing Privacy Sign up Sign in Privacy Policy Terms Cookies

© 2026 Gemma.