Cookies & browser storage
Notice version: 2026-09-19. Operator review pending.
Draft — operator review required. The operator’s public business address, retention schedule, international-transfer arrangements and final legal review are still pending. These pages describe the implementation and proposed terms; they are not a completed compliance assessment or an effective new contract.
Current choices
No optional advertising or visitor-analytics tracker is enabled in the audited application source. The notice therefore offers necessary storage only. It does not collect blanket consent for future tracking. Hosting-level analytics or injected tags are outside this source audit and must remain disabled until separately assessed. A future nonessential tracker must be blocked until valid purpose-specific opt-in, with equally easy rejection and withdrawal.
Authentication and security
Hosted authentication can store session and refresh credentials in browser storage. Community editing holds its session for authenticated requests. Visual review uses an HttpOnly, Secure, SameSite=Strict cookie named visual_review_session scoped to the review run; its expiry follows that run’s configured lifetime, normally seven days and bounded to thirty days. These items support access you request and are not advertising identifiers.
Requested interface state
The applications retain selected theme, workspace, project, editor location and related preferences in local or session storage. Exact keys vary by feature and deployment, including octonode-theme and octonode.code-file. Local storage normally persists until cleared; session storage ends with the browser session. Sign-out does not necessarily erase every saved interface preference. Browser controls can remove it; doing so may sign you out or reset settings.
Storage notice preference
octonode.storage-notice stores only the notice version, acknowledgement time and necessary-only choice on this origin. It is reconsidered after 180 days or a notice-version change. It contains no advertising ID and is not shared across subdomains. Storage settings in the footer reopen the notice. If browser storage is unavailable, optional tracking remains off and the notice may reappear.
Browser privacy signals
The notice recognizes Global Privacy Control. Optional tracking remains off with or without that signal. This is not a claim that all hosting-provider or customer-installed integrations implement every privacy signal. Browser Do Not Track has no universal implementation here; contact the operator about practices outside the application code.
Other external requests
An external image, integration, payment page or AI provider may receive request information when used even without setting a cookie. The Tasks site no longer requests Google Fonts. Remote content and third-party checkout still require a live network and vendor review; cookie settings alone do not control every data transfer.