# Cookies and local storage

Source: https://listme.name/cookies


listme.name sets no cookies when you only read pages. Cookies appear only when you sign in, fill a form, or ask for a particular color theme. All of them are strictly necessary for what you asked for, so no consent banner is shown.

| Name | Purpose | Lifetime |
|---|---|---|
| `__Host-lm_session` | Keeps you signed in (random token, stored hashed on the server) | 30 days since last use, or until the browser closes on a shared computer |
| `__Host-lm_in` | Tells the page script that a session probably exists, so it can show "Account" and your saved items. Contains no secret | Same as the session |
| `__Host-lm_dev` | Marks a browser you have signed in from and trusted, so it needs no emailed code next time | 180 days |
| `__Host-lm_ch` | Binds a pending sign-in code to the browser that asked for it | Until the browser closes |
| `__Host-lm_csrf` | Protects forms from cross-site requests when you are signed out | Until the browser closes |
| `__Host-lm_next` | Remembers where to send you after confirming your email | 24 hours |
| `__Host-lm_goog` | Binds a "Sign in with Google" attempt to the browser that started it (a random value, valid once). Only set when you press the Google button | 10 minutes |

Browser storage: `localStorage` item `lm-theme` remembers a light or dark theme you choose with the theme button, `lm-motion` that you paused animation, and `lm-pwa` whether you dismissed or used the "add to home screen" reminder. They never leave your device. The service worker keeps copies of public pages and of the site's files in the browser's cache storage so the site opens faster and works offline; clear the site's data in your browser to remove them.

Cloudflare, which delivers and protects the site, may set its own security cookies to detect abuse. We do not use them for anything else.

You can delete these cookies in your browser at any time; you will be signed out and the device will need a new emailed code on its next sign-in.
