Cookie Policy
TrustHabitat uses only a handful of essential cookies: to keep you signed in, protect forms and remember your language. No advertising, tracking or analytics cookies.
Last updated: September 25, 2026
1. What cookies are
Cookies are small text files that a website stores in your browser so that it can remember information between pages or visits, such as the fact that you are signed in.
2. How we use cookies
We only use cookies that are strictly necessary for the Platform to work or that remember a choice you made. We do not use advertising cookies, cross-site tracking cookies or third-party analytics cookies, and we do not sell any information collected through cookies. Because of this, we do not need to ask for your consent through a cookie banner.
3. The cookies we set
- Cookie
- authjs.session-token (called __Secure-authjs.session-token on secure connections)
- Purpose
- Keeps you signed in. It contains an encrypted identifier of your session, not your password.
- Type
- Strictly necessary
- Duration
- 14 days, or until you sign out
- Cookie
- authjs.csrf-token (called __Host-authjs.csrf-token on secure connections)
- Purpose
- Protects sign-in forms against cross-site request forgery.
- Type
- Strictly necessary
- Duration
- Until you close your browser
- Cookie
- authjs.callback-url (called __Secure-authjs.callback-url on secure connections)
- Purpose
- Remembers which page to send you back to after signing in.
- Type
- Strictly necessary
- Duration
- Until you close your browser
- Cookie
- NEXT_LOCALE
- Purpose
- Remembers the language you chose so that pages open in that language.
- Type
- Preference
- Duration
- Up to 1 year
| Cookie | Purpose | Type | Duration |
|---|---|---|---|
| authjs.session-token (called __Secure-authjs.session-token on secure connections) | Keeps you signed in. It contains an encrypted identifier of your session, not your password. | Strictly necessary | 14 days, or until you sign out |
| authjs.csrf-token (called __Host-authjs.csrf-token on secure connections) | Protects sign-in forms against cross-site request forgery. | Strictly necessary | Until you close your browser |
| authjs.callback-url (called __Secure-authjs.callback-url on secure connections) | Remembers which page to send you back to after signing in. | Strictly necessary | Until you close your browser |
| NEXT_LOCALE | Remembers the language you chose so that pages open in that language. | Preference | Up to 1 year |
4. Storage in your browser
To load faster on slow connections and to show an offline page when you lose your connection, the Platform installs a service worker that keeps a copy of its own files (code, styles and the offline page) in your browser. This storage contains no personal information and never keeps pages that show your account or listings. If you choose a light or dark theme, that choice is saved in your browser’s local storage under the name “theme”; it stays on your device and is never sent to us.
5. Third-party content
Maps are displayed with tiles loaded from OpenStreetMap servers, and some photos are loaded from image delivery networks. Your browser contacts these services directly, so they receive technical information such as your IP address, as with any web request. We do not allow them to place advertising or tracking cookies through the Platform. Their own privacy policies apply to the data they receive.
6. Managing cookies
You can view and delete cookies, or block them, in your browser settings. If you block strictly necessary cookies, you will not be able to sign in or publish listings, but you can still browse and contact advertisers. If you delete the NEXT_LOCALE cookie, the Platform will use your browser language again.
7. More information
For more about how we handle personal data, see our Privacy Policy. For any question, write to [email protected]. We will update this policy if we change the cookies we use; the date at the top of this page shows the latest version.