Cookie and Similar Technologies Policy

Polish version: Polityka Cookies. The Polish version is binding, without limiting mandatory consumer rights.

Pre-launch draft. Requires qualified-counsel review before publication; it has not entered into force.

1. Scope

Cookies, localStorage, IndexedDB, extension and app storage are subject to device-access rules even when they are not cookies. Only storage or access genuinely necessary for transmission or a service expressly requested by the user is exempt from consent (Article 399 of Poland’s Electronic Communications Law). OS push permission is not marketing consent.

This inventory describes pre-production code. The extension, mobile and CLI are not yet public; analytics requires separate clearance. We do not claim that external providers never receive connection data or use their own technologies.

2. Necessary storage

Client and storage Data and purpose Duration or removal
Web: memory and localStorage palladin-auth access token in memory; refresh token and minimal account state in localStorage for sign-in continuity until logout, site-data removal or revocation; token expiry does not guarantee physical deletion from unopened site storage
Web: IndexedDB; mobile: SQLite; extension: IndexedDB encrypted Entries, packages and technical identifiers/versions for synchronization and reading after unlock; not analytics synchronization, profile change and local cleanup; clearing app data removes the local copy, not server data
Web/mobile/extension: settings chosen language, theme, server and other non-secret preferences until changed or cleared
Web: sessionStorage acknowledgement of the Benefit dialog, linked to account and period, without e-mail or secrets current tab session; earlier logout or clearing
Landing: palladin-landing-privacy consent/refusal choice, time and notice version; no analytics identifier valid for 180 days; invalid records removed at the next read, not automatically while the page is closed
Web: palladin-client-analytics:<userId>; mobile: consent activation file local choice version and revision; the record does not replace account consent until withdrawal or clearing; loss or mismatch requires reactivation
Web/mobile: FCM registration, Service Worker and system storage push token and state for requested notifications until deregistration, expiry or clearing; controlled in OS/app settings
Extension: palladin.session.sealed.v1 encrypted token/session envelope; restart restores only a locked state, without a persistent Vault key at most 365 days from creation; earlier logout, server change, definitive refresh rejection, mismatch, reset or uninstall
Extension: RAM and separate storage.session decrypted values and last-filled Entry choice only in unlocked-process RAM; storage.session contains only non-secret transport metadata, including reconnect delay values until lock or process termination; delay until browser-session end or successful connection/stop
Mobile: OS-protected storage session tokens; the current biometric variant also persists the master key clearing the biometric marker currently leaves the stored key blob. This release blocker requires a fix or approved design change, not an ordinary cookie preference
Local Agent runtime system identity and installation authorization; local value-free form-map cache explicit identity reset/removal through the relevant runtime command; uninstalling the npm package alone does not remove it. Cache also by removal. Device identity key is separate from the Vault key

Synchronization caches do not persist plaintext Entries. The Master Password and Vault keys are not stored in panel or extension cookies or localStorage. The mobile exception above prevents a blanket “all keys only in RAM” claim. Server data and rights: Privacy Policy.

Surface Intended data after clearance and consent
Landing EN/PL page view, waitlist click, language and fixed path; random page-memory identifiers, reset on navigation/reload, session also after 30 minutes’ inactivity
Web and mobile selected interactions and screen templates, account identifier and random memory-only session; the account identifier remains personal data
Extension telemetry disabled; another client’s consent does not activate it

Nonessential client analytics requires prior voluntary consent. Absence of cookies or a persistent identifier does not replace consent. The EU transport uses no PostHog SDK, autocapture, replay, person profiles or offline queue; it sends no form or Entry contents, e-mail, secrets, query strings or full referrer. The connection recipient still sees IP and technical request data; their retention is governed by the Privacy Policy. Test preview sends no events. The ordinary website may use analytics after your consent even before the app launches; draft document status alone does not mean analytics is disabled.

On the website you can accept or reject analytics; it is off by default. You can revisit your choice through the privacy settings button; rejecting analytics again withdraws consent. This choice does not cover the account or marketing. Web/mobile require both current account consent and local activation for that installation. Refusal does not restrict the service. Analytics and marketing are separate purposes; both are to remain disabled for under-18s once age controls are implemented.

Landing settings can be reopened through a permanent button. Withdrawal stops new events; web/mobile also save it for the account. If saving fails, the app reports the error: local stopping does not yet confirm withdrawal on other devices.

Withdrawal does not erase the account or affect prior lawfulness. Historical erasure is a separate process that must be implemented before launch. Backend event measurement is a separate purpose with its own basis assessment and objection right in the Privacy Policy; it must not bypass client refusal.

4. External connections

The informational website and legal pages serve fonts from their own hosting, without connecting to Google Fonts. The app panel still downloads fonts from Google Fonts, which receives request data including IP. Google sign-in and Have I Been Pwned checking are separate flows, not PostHog analytics. HIBP receives only a five-character hash prefix, not the password. The Privacy Policy explains purposes and legal bases. The recipient list states verification status.

5. Controls and contact

You can clear site data in the browser, app data in the OS and push permission in settings. This removes local choices and copies, not the account itself. Locking the extension retains its encrypted envelope. Logout removes it, but a locked client after restart may lack the token needed to revoke the server session; deleting the envelope does not guarantee immediate remote revocation.

Contact: patryk.roguszewski@palladin.io. A new nonessential purpose requires information and appropriate consent before activation. Material expansion of storage/access will be notified at least 14 days in advance; elapsed notice does not replace consent.