Cookie Policy

Last updated 16 September 2026

A cookie is a small piece of text a website asks your browser to hold onto and send back on later requests. WS Ledger uses a small number of them, and none for advertising or tracking. Every one of them is strictly necessary — the site cannot function without them, so there is no cookie banner asking you to opt in: under Maldivian and most other privacy law, consent is not required for cookies that only make the service you asked for work.

The cookies we set

All of them are httpOnly (invisible to any script running on the page, including one injected by an attack) and, outside local development, Secure (sent only over https). None of them is readable by, or shared with, any other website.

  • wsl_session — keeps you signed in. Set when you sign in, removed when you sign out, and expires on its own after a period your organisation’s administrator configures (12 hours by default). Signing in again always replaces it, so it is never reused across devices or sessions.
  • wsl_2fa — set for the few minutes between entering your password and entering your two-factor code, so the second step knows which sign-in it belongs to. It holds a random token, never your password or your code, and expires after 10 minutes or as soon as you finish signing in, whichever comes first.
  • wsl_webauthn_reg, wsl_webauthn_pwless and wsl_webauthn_2fa — set only while a passkey prompt (Face ID, Touch ID, Windows Hello or a security key) is open, so your device’s answer can be checked against the question we asked it. Each expires after 5 minutes.

What we do not use

No advertising cookies, no analytics or behavioural-tracking cookies, and no cookies set by a third-party service embedded in the page — WS Ledger does not embed any. We do not use your browser’s local storage or session storage either; everything about your account lives on our servers, not in your browser.

Controlling cookies

Because every cookie here is necessary for signing in, blocking them means you cannot use WS Ledger — the same as any site that requires an account. You can still clear them at any time from your browser’s settings; you will simply be asked to sign in again. Signing out, or using “Sign out of all devices” from your profile, removes the session cookie immediately rather than waiting for it to expire.

Changes to this policy

If the cookies WS Ledger sets change — a new one is added, or an existing one’s purpose changes — this page is updated and the date at the top moves. It is part of our Privacy Policy, which explains how we handle the wider set of data behind your account.

Questions

Write to [email protected].