Cookies
Cookie policy.
Last updated: 2026-08-19
This Cookie Policy explains how Tryst Link uses cookies and similar browser-storage technologies. The current service uses cookies for authentication and security. We do not intentionally use advertising cookies or cross-site analytics cookies.
Tryst Link is operated by Trystlink, located at Office 104, Lekorpouzier 12a, Limassol, 3075, Cyprus.
Short version
- You can browse the public website and use the browser-based QR generator without signing in.
- When you sign in to manage short links, Auth.js sets a first-party session cookie so the application can recognize your authenticated session.
- Auth.js may also use temporary first-party cookies during the sign-in flow for security and callback handling.
- We do not intentionally use cookies for advertising, remarketing, cross-site profiling, session replay, or behavioral analytics.
- The current application does not use
localStorageto store your authentication session.
Strictly necessary authentication cookies
The short-link dashboard requires authentication. When you sign in, Auth.js stores the session in a first-party cookie so authenticated requests can be associated with your account.
Session token cookie
The application uses Auth.js with a JWT session strategy. Auth.js stores an encrypted JSON Web Token in the session cookie. The token contains the minimum session information needed by the application, including the user identifier used to scope account data.
- Purpose: keep you signed in and authorize access to authenticated features such as the dashboard.
- Provider: first-party, set by the Tryst Link application through Auth.js.
- Typical name:
authjs.session-token. On HTTPS deployments Auth.js may use a secure-prefixed name such as__Secure-authjs.session-token. - HttpOnly: yes under the standard Auth.js cookie configuration, which prevents ordinary client-side JavaScript from reading the session cookie.
- SameSite: Lax under the standard Auth.js cookie configuration.
- Secure: enabled on HTTPS deployments under the standard Auth.js configuration.
- Path:
/. - Maximum session age: the current application does not override Auth.js's session maximum, so the default maximum age is 30 days. Session behavior may cause the expiry time to be refreshed while the session remains active.
Signing out causes the authentication session cookie to be cleared or invalidated by the authentication system.
Temporary authentication-support cookies
During authentication, Auth.js may set additional short-lived first-party cookies used for security or routing within the sign-in process, including cookies related to CSRF protection or callback handling.
Their exact names can include Auth.js prefixes and may differ between local HTTP development and the production HTTPS site. They are not used to build advertising profiles or track your activity across unrelated websites.
Why we do not ask for cookie consent for authentication
The authentication cookies described above are used only to provide and secure the sign-in functionality requested by the user. They are treated as strictly necessary for the authenticated service.
If we introduce non-essential cookies that require consent under applicable law, we will request that consent before using them and update this policy.
Cookies we do not intentionally use
- Google Analytics cookies.
- Plausible, Fathom, or similar analytics cookies.
- Google Ads or other advertising cookies.
- Meta/Facebook advertising or remarketing cookies.
- Cross-site advertising identifiers.
- Session-replay cookies such as Hotjar or FullStory.
- A/B-testing cookies.
- Social-media advertising or share-widget cookies.
Redirects and short links
Opening a Tryst Link short URL does not require a Tryst Link account and the redirect handler does not intentionally set an analytics or advertising cookie on the person following the short link.
The redirect service does record limited click-event information as described in our Privacy Policy. That measurement is server-side and should not be confused with browser-cookie tracking.
The QR generator
The QR generator does not require an account and does not need an authentication cookie to generate a QR code. The content entered into the generator is processed in the browser as described in our Privacy Policy.
Local storage and other browser storage
The current Tryst Link application does not intentionally use localStorage or sessionStorage to store authentication sessions or create tracking identifiers.
If browser-storage behavior changes in a future version of the service, we will update this policy to describe the purpose and retention of that storage.
Third-party infrastructure and resources
Vercel hosts and delivers the website, application routes, API requests, and short-link redirects. Vercel may process ordinary request and network information as part of providing hosting, security, and routing services. This does not mean Vercel sets advertising cookies on trystlink.io.
Managing cookies
You can inspect, block, or delete cookies through your browser settings. If you block or delete the Tryst Link authentication cookie, authenticated features may stop working and you may need to sign in again.
Public pages and the QR generator do not require you to remain signed in.
Changes to this policy
We may update this policy when authentication, browser storage, third-party resources, or applicable legal requirements change. The current version and last-updated date will remain available on this page.
If we introduce non-essential analytics, advertising, or other consent-based cookies, we will update this policy and implement the consent controls required by applicable law before using them.
Contact
Operator: Trystlink
Address: Office 104, Lekorpouzier 12a, Limassol, 3075, Cyprus
Email: hello@trystlink.io
For information about personal data, click-event records, service providers, retention, and your data-protection rights, see our Privacy Policy.