Cookies & browser storage

Storage supports sign-in, your preferences and recovery of unsaved work.

Sign-in cookies

pokedex_session — 30 days
Keeps you signed in. It is HttpOnly, SameSite=Lax and Secure on HTTPS. Signing out removes this browser’s session; deleting your account invalidates all sessions.
pokedex_signin — 10 minutes
Protects the sign-in exchange against forgery and mismatched responses. A successful sign-in removes it.

Local and session storage

The app uses keys beginning with pokemon_ir_, scoped to your account when signed in. They hold collection and inventory caches, selected prints, preferences, hidden/kept cards, cached card data, prices and pending-save recovery information. Local storage remains until cleared; session storage normally lasts for the tab’s session. Signing out does not erase these recovery caches.

Clear this site’s data in browser settings to remove stored data. Export or save pending work first. Account deletion attempts to clear only the deleted account’s keys in the browser making the request. It cannot erase other devices, downloaded files or copies already open in another tab.

Consent and external services

The app does not currently include advertising or analytics tracking scripts. The sign-in cookies are used to provide secure account access. A consent banner is not used for strictly necessary storage. Optional tracking must not be added without assessing consent requirements first.

Sign-in providers and external font/card-image services may process network information when your browser connects to them. See Privacy. Provider and browser behaviour must be checked again before launch.

Last updated 18 September 2026.