1About this information
Scriboflow ApS
Denmark
Legal: legal@scriboflow.com
Privacy: privacy@scriboflow.com
This page explains the cookies, local storage, scripts, and comparable technologies used by the Scriboflow website and application. It supplements the Privacy Policy. A cookie is a small browser record; local storage is browser storage that normally remains until the application or user clears it.
This information describes the implementation observed in the Scriboflow source and the cited provider defaults as of the effective date. Browser limits, provider configuration, and future releases can shorten or change a stated duration.
2Necessary storage
The following storage supports a requested language, account session, active organisation, or request security. Blocking it can prevent the application from working correctly.
| Name or pattern | Provider | Purpose and category | Mechanism | Duration |
|---|---|---|---|---|
NEXT_LOCALE | Scriboflow | Remembers the selected language. Necessary preference. | First-party cookie | 1 year |
sb-<project>-auth-token* | Scriboflow / Supabase | Maintains and refreshes the authenticated session. Strictly necessary authentication. | First-party, HTTP-accessible auth cookies managed by the Supabase SSR client | Up to 400 days as the client maximum; refreshed or removed with the session |
SF_ACTIVE_ORG | Scriboflow | Remembers the active organisation. Necessary application preference. | First-party cookie | 1 year |
scriboflow.active_org_id | Scriboflow | Keeps the active organisation in sync in the browser. Necessary application preference. | Local storage | Until changed, removed on sign-out/application action, or cleared by the user |
__Host-csrf (scriboflow-csrf in development) | Scriboflow | Protects state-changing requests against cross-site request forgery. Strictly necessary security. | Secure, HTTP-only, first-party cookie in production | 24 hours |
3Analytics
The current public-site implementation loads Google Analytics and Umami after the page becomes interactive. The PostHog browser client is initialised application-wide for product analytics and error diagnostics. These technologies are not classified as strictly necessary.
| Name or service | Provider | Purpose and category | Mechanism | Verified duration |
|---|---|---|---|---|
_ga, _ga_<container-id> | Google Analytics | Distinguishes users and preserves session state for website analytics. Analytics. | First-party cookies set by the Google tag; network requests to Google | Google documents a 2-year default, subject to browser limits and configuration |
ph_<project>_posthog and related PostHog persistence | PostHog | Product usage measurement, configured events, and error diagnostics. Analytics. | First-party cookie and local storage through the PostHog browser SDK | The installed SDK defaults to 365 days for cookie persistence; local storage remains until cleared or reset |
| Umami Cloud tracker | Umami | Measures page views, referrers, device/browser categories, approximate location, and configured business-page events. Analytics. | Cookieless script and network requests; Umami documents server-side anonymous session calculation | No browser cookie duration; server retention is provider/account configuration and is not determinable from the public source configuration |
Google documents its GA4 cookie defaults in its cookie usage information. PostHog's installed browser SDK documents a 365-day default. Umami states that its tracker does not use cookies in its documentation.
4Security and third-party functionality
| Service | Provider | Purpose and category | Mechanism | Duration |
|---|---|---|---|---|
| Turnstile | Cloudflare | Bot and abuse protection on the public contact form when configured. Necessary security for that form. | Third-party challenge script and a one-time token sent for server verification; Cloudflare may use challenge storage | The application does not set a duration. If Cloudflare pre-clearance is enabled, Cloudflare documents a configurable cf_clearance duration with a 30-minute default |
| Google Maps | Displays the location map on the contact page when configured. Third-party functionality. | Third-party script, map requests, and provider-controlled browser storage | Provider-controlled and not determinable from the Scriboflow source configuration |
Third-party resources can receive technical request information such as IP address, browser headers, the page requested, and request time. Provider roles, processing locations, and safeguards are described in the public provider register.
5Controls and consent status
Browser settings can block or delete cookies and local storage. Extensions can block analytics or third-party scripts, but doing so may affect sign-in, organisation selection, security checks, contact forms, or maps.
Scriboflow does not currently provide a complete consent-management interface, and the current public implementation loads analytics without waiting for a recorded consent choice. This is a separate launch and legal-compliance issue that must be resolved or expressly approved where consent is required. Publishing this page supplies information only; it does not itself obtain or record consent.
6Changes and contact
We update this page when the relevant storage, providers, purposes, or verified durations materially change. The version and effective date above identify this text. Cookie Information is not included in the organisation legal-acceptance revision unless a later release expressly says otherwise.
Privacy questions: privacy@scriboflow.com. Legal notices: legal@scriboflow.com.