Legal
Cookie Policy
Effective 8 October 2026.
Sheet Reserve uses a handful of cookies, and every one of them is strictly necessary. They keep you signed in, protect forms and let Cloudflare block bots. We don't use analytics, advertising or tracking cookies, and no third-party scripts run on the site.
Cookies we use
| Name | Set by | Purpose | Duration | Type |
|---|---|---|---|---|
__Host-sr_session |
Sheet Reserve | Keeps you signed in. It holds a random token, and our server stores only a hash of it. Marked HttpOnly, Secure and SameSite=Lax | 30 days after your last visit, or until you sign out | Strictly necessary |
__Host-sr_csrf |
Sheet Reserve | Protects forms against cross-site request forgery | Until you close your browser (session cookie) | Strictly necessary |
__Host-sr_oauth |
Sheet Reserve | Holds the state and nonce of a Sign in with Google attempt, so the reply from Google can be checked. Set only when you use Sign in with Google | 10 minutes | Strictly necessary |
__cf_bm |
Cloudflare | Bot management: helps tell people apart from automated traffic | Expires after 30 minutes of inactivity | Strictly necessary |
cf_clearance |
Cloudflare | Set only if Cloudflare shows you a security challenge. Records that you passed it, so you aren't challenged again right away | 30 minutes by default | Strictly necessary |
Browsers accept a cookie whose name starts with __Host- only over HTTPS and only from sheetreserve.com itself, and never send it to any other domain or subdomain.
Cloudflare sits in front of the site and sets its cookies on sheetreserve.com. Cloudflare's cookie documentation describes them in more detail.
Browser storage
The library may remember your sort and filter choices in your browser's local storage (localStorage), so they're still set the next time you visit. This is stored only on your device and is never sent to us. You can remove it by clearing this site's data in your browser settings.
Why there's no cookie banner
Laws such as the EU ePrivacy Directive and the UK's Privacy and Electronic Communications Regulations require consent before a site stores or reads information on your device, unless that storage is strictly necessary to provide a service you've asked for. The cookies above are all strictly necessary, and local storage only remembers choices you make in the library, so there's nothing optional to accept or decline. That's why we don't show a cookie banner. If we ever add a cookie that isn't strictly necessary, we'll ask for your consent first and update this page.
Blocking or deleting cookies
Most browsers let you block or delete cookies in their privacy or site data settings. If you block ours:
- without
__Host-sr_session, you can't stay signed in, so you can't download files; - without
__Host-sr_csrf, forms such as sign-in and sign-up won't work; - without
__Host-sr_oauth, Sign in with Google won't work; and - without Cloudflare's cookies, you may see more security challenges, or be unable to get past them.
Public pages can generally be read without cookies.
Changes to this policy
When we change this policy, we'll post the new version here and update the effective date. We'll announce material changes on the site and by email to account holders at least 14 days before they take effect, where reasonable.
Contact
Questions about cookies can go to [email protected]. The Privacy Policy explains how we handle personal data more generally.