Scriboflow Cookie Information

Cookie Information

Version 1.0Effective 21 August 2026

The cookies and similar browser storage used by Scriboflow, including purpose, provider, mechanism, and duration.

1About this information

Scriboflow ApS
Denmark
Legal: legal@scriboflow.com
Privacy: privacy@scriboflow.com

This page explains the cookies, local storage, scripts, and comparable technologies used by the Scriboflow website and application. It supplements the Privacy Policy. A cookie is a small browser record; local storage is browser storage that normally remains until the application or user clears it.

This information describes the implementation observed in the Scriboflow source and the cited provider defaults as of the effective date. Browser limits, provider configuration, and future releases can shorten or change a stated duration.

2Necessary storage

The following storage supports a requested language, account session, active organisation, or request security. Blocking it can prevent the application from working correctly.

Name or patternProviderPurpose and categoryMechanismDuration
NEXT_LOCALEScriboflowRemembers the selected language. Necessary preference.First-party cookie1 year
sb-<project>-auth-token*Scriboflow / SupabaseMaintains and refreshes the authenticated session. Strictly necessary authentication.First-party, HTTP-accessible auth cookies managed by the Supabase SSR clientUp to 400 days as the client maximum; refreshed or removed with the session
SF_ACTIVE_ORGScriboflowRemembers the active organisation. Necessary application preference.First-party cookie1 year
scriboflow.active_org_idScriboflowKeeps the active organisation in sync in the browser. Necessary application preference.Local storageUntil changed, removed on sign-out/application action, or cleared by the user
__Host-csrf (scriboflow-csrf in development)ScriboflowProtects state-changing requests against cross-site request forgery. Strictly necessary security.Secure, HTTP-only, first-party cookie in production24 hours

3Analytics

The current public-site implementation loads Google Analytics and Umami after the page becomes interactive. The PostHog browser client is initialised application-wide for product analytics and error diagnostics. These technologies are not classified as strictly necessary.

Name or serviceProviderPurpose and categoryMechanismVerified duration
_ga, _ga_<container-id>Google AnalyticsDistinguishes users and preserves session state for website analytics. Analytics.First-party cookies set by the Google tag; network requests to GoogleGoogle documents a 2-year default, subject to browser limits and configuration
ph_<project>_posthog and related PostHog persistencePostHogProduct usage measurement, configured events, and error diagnostics. Analytics.First-party cookie and local storage through the PostHog browser SDKThe installed SDK defaults to 365 days for cookie persistence; local storage remains until cleared or reset
Umami Cloud trackerUmamiMeasures page views, referrers, device/browser categories, approximate location, and configured business-page events. Analytics.Cookieless script and network requests; Umami documents server-side anonymous session calculationNo browser cookie duration; server retention is provider/account configuration and is not determinable from the public source configuration

Google documents its GA4 cookie defaults in its cookie usage information. PostHog's installed browser SDK documents a 365-day default. Umami states that its tracker does not use cookies in its documentation.

4Security and third-party functionality

ServiceProviderPurpose and categoryMechanismDuration
TurnstileCloudflareBot and abuse protection on the public contact form when configured. Necessary security for that form.Third-party challenge script and a one-time token sent for server verification; Cloudflare may use challenge storageThe application does not set a duration. If Cloudflare pre-clearance is enabled, Cloudflare documents a configurable cf_clearance duration with a 30-minute default
Google MapsGoogleDisplays the location map on the contact page when configured. Third-party functionality.Third-party script, map requests, and provider-controlled browser storageProvider-controlled and not determinable from the Scriboflow source configuration

Third-party resources can receive technical request information such as IP address, browser headers, the page requested, and request time. Provider roles, processing locations, and safeguards are described in the public provider register.

5Controls and consent status

Browser settings can block or delete cookies and local storage. Extensions can block analytics or third-party scripts, but doing so may affect sign-in, organisation selection, security checks, contact forms, or maps.

Scriboflow does not currently provide a complete consent-management interface, and the current public implementation loads analytics without waiting for a recorded consent choice. This is a separate launch and legal-compliance issue that must be resolved or expressly approved where consent is required. Publishing this page supplies information only; it does not itself obtain or record consent.

6Changes and contact

We update this page when the relevant storage, providers, purposes, or verified durations materially change. The version and effective date above identify this text. Cookie Information is not included in the organisation legal-acceptance revision unless a later release expressly says otherwise.

Privacy questions: privacy@scriboflow.com. Legal notices: legal@scriboflow.com.

Scriboflow ApS · Cookie Informationlegal@scriboflow.com