Pre-launch draft — Lexboard is not yet operating as a legal entity. These documents are drafts under legal review and are not yet in effect or binding.
Legal
Last updated: July 2, 2026. What cookies and similar technologies Lexboard uses, and how to manage them.
1
A cookie is a small text file a website stores on your device. Cookies let a site recognize your browser across page loads — so you stay signed in, your theme preference persists, and the session doesn't restart on every click. Lexboard also uses browser localStorage, which works similarly but stores data only in your browser (it never travels to our servers).
2
Lexboard sets only strictly-necessary cookies:
| Cookie | Purpose | Lifetime |
|---|---|---|
| sb-…-auth-token | Supabase auth session — keeps you signed in. | Up to 400 days; the session inside is refreshed and is revoked on sign-out |
| sb-…-auth-token-code-verifier | PKCE verifier for the OAuth login flow. | Session |
| sv_<id> | Remembers that this browser already opened a shared-document link so reloads don't consume the link's view limit. | Session |
| lex_provider | Provider-portal sign-in session. | 30 days |
| lexpv_<id> | Proves you completed identity verification on a client-portal link. | Limited lifetime |
| lexboard_platform_admin_step_up | Re-authentication proof for the Lexboard staff admin console. | Minutes |
| qbo_oauth_state | CSRF protection during the QuickBooks connect flow. | 10 minutes |
| __stripe_mid / __stripe_sid | Stripe fraud detection on payment pages. | 1 year / 30 minutes |
Feature-scoped, strictly-necessary cookies like these may be added from time to time; this table is updated with each release.
3
These items live in your browser only (no server round trip). Clearing your browser's site data removes them. They fall into four categories:
| Category | What it includes |
|---|---|
| Interface preferences | Keys prefixed lexboard.ui:, plus theme, sidebar mode, density, sort/view choices, and cached firm practice states for directory pickers. |
| Consent record | lexboard.cookie-consent.v1 — your acceptance/decline choice from the cookie banner. |
| Sign-in convenience | lexboard.rememberedEmail — your login email, stored only if you tick “Remember me.” |
| Unsent drafts and view caches | Intake and email drafts you haven't sent, a snapshot of your inbox list, and recently generated AI summaries — scoped to your user id so another account on the same browser cannot read them. |
Drafts and caches may contain case content. On shared or public computers, sign out and clear site data when you finish. None of these items are transmitted to us as tracking data.
4
Lexboard does not:
If we ever add an analytics or marketing cookie, the banner will prompt you again and the cookie will load only after explicit consent.
5
Two services set their own cookies when their features are used:
No other third party sets cookies through Lexboard.
6
You can manage cookies several ways:
7
We respect the spirit of Do Not Track but do not currently take automated action when a browser sends the DNT header — because Lexboard does not run advertising trackers in the first place, the signal would have no behavior to suppress. If this changes, this page and the cookie banner will be updated.
The same applies to the Global Privacy Control (GPC) signal: we do not sell or share personal information, so there is no sale to opt out of; we will honor GPC before ever introducing one.
8
We may update this Cookie Policy if we add or remove cookies, or if applicable law requires further disclosure. Material updates will be noted on this page and announced via in-app notice.
9
Questions about cookies or tracking: privacy@lexboard.net.