Cookie and Similar Technologies Policy

Polish version: Polityka Cookies — the Polish version is legally binding; this English version is provided for convenience.

1. Does Palladin use cookies?

The Palladin web panel does not use cookies for authentication or tracking. The access token is held only in browser memory. The refresh token and minimal session state are stored in localStorage under palladin-auth to preserve the session when the panel is reopened. LocalStorage is a technology similar to cookies under Polish electronic-communications law.

WhereKey / categoryContentsPurposeLifetime
browser memorycurrent-session stateaccess tokenoperating the authenticated sessionuntil the tab closes, expiry or logout
localStorage (web)palladin-authrefresh token, user identifier, onboarding status and permissionspreserving the session between visitsuntil logout, token expiry or revocation, account deletion or clearing site data
localStorage (web)UI preferencestheme, language and interface settingsremembering User choicesuntil site data are cleared
localStorage (web)palladin-analytics-consentdecision, date and notice versionremembering consent or refusal12 months or until changed or withdrawn
IndexedDB and Service Worker registration (web)storage managed by Firebase Cloud Messaging and firebase-messaging-sw.jspush token, SDK registration state and public delivery configurationdelivering web notifications after system permissionuntil deregistration, token expiry or clearing site data
secure storage (mobile)session tokenopaque authentication token; no encryption keyskeeping the mobile sessionuntil logout, expiry or account deletion
secure storage (mobile)push registrationFCM/APNs tokendelivering notifications after system permissionuntil deregistration, expiry or uninstall

Encryption keys (Master Password, master key, private keys) are never written to cookies, localStorage or any persistent browser storage — they exist only in tab memory and vanish when the tab closes.

With your prior, freely given consent (Polish Electronic Communications Law; Art. 6(1)(a) GDPR) we use PostHog for product analytics: which features are used and where users hit problems.

  • Events carry a user identifier and technical properties (event type, entry type, flags) — never Entry contents, passwords, keys or any other secrets.
  • Content autocapture and session recording are disabled; secret-bearing fields are additionally masked.
  • You may withdraw consent at any time in settings — this stops the collection of new events and further use of data for consent-based analytics, with no effect on the Service.

Until consent is given, analytics stays off.

WhereKey / categoryDataActivationDeletion
localStorage (web)ph_<project_token>_posthogpseudonymous identifier, session state and technical propertiesconsent only; PostHog is configured without cookiesimmediately on withdrawal or clearing site data
SDK storage (mobile)PostHog keys for the released SDK versionpseudonymous identifier and analytics stateconsent onlyimmediately on withdrawal or uninstall

You may withdraw consent at any time in the settings. Withdrawal stops the collection of new events and further use of data for consent-based analytics and removes the local PostHog identifier. It does not affect the lawfulness of processing carried out before withdrawal.

Withdrawing consent is not the same as deleting the account. Independently, you may exercise your right to erasure under Article 17 GDPR by contacting patryk.roguszewski@palladin.io. Historical events remain subject to the retention periods and data-subject-rights procedure described in the Privacy Policy. The web key includes the environment’s project token and contains no User secret.

4. Push notifications

After you grant the system-level notification permission, your device receives a push token (Firebase Cloud Messaging / APNs) used solely to deliver Service notifications (e.g. an Agent’s access request). Withdraw via system or app settings.

5. Managing

Clear site data in your browser to remove localStorage entries. Analytics consent controls live in the Service; withdrawal stops analytics and removes the local PostHog identifier. The change history is available in the public legal changelog.

6. Contact and changes

Send questions about cookies, similar technologies and analytics consent to patryk.roguszewski@palladin.io. We will announce material changes in the Service or by e-mail at least 14 days in advance where a change affects optional storage of or access to data on your device.