Cookie and Similar Technologies Policy
Polish version: Polityka Cookies — the Polish version is legally binding; this English version is provided for convenience.
1. Does Palladin use cookies?
The Palladin web panel does not use cookies for authentication or tracking. The access token is held only in browser memory. The refresh token and minimal session state are stored in localStorage under palladin-auth to preserve the session when the panel is reopened. LocalStorage is a technology similar to cookies under Polish electronic-communications law.
2. Strictly necessary technologies (no consent required)
| Where | Key / category | Contents | Purpose | Lifetime |
|---|---|---|---|---|
| browser memory | current-session state | access token | operating the authenticated session | until the tab closes, expiry or logout |
| localStorage (web) | palladin-auth | refresh token, user identifier, onboarding status and permissions | preserving the session between visits | until logout, token expiry or revocation, account deletion or clearing site data |
| localStorage (web) | UI preferences | theme, language and interface settings | remembering User choices | until site data are cleared |
| localStorage (web) | palladin-analytics-consent | decision, date and notice version | remembering consent or refusal | 12 months or until changed or withdrawn |
| IndexedDB and Service Worker registration (web) | storage managed by Firebase Cloud Messaging and firebase-messaging-sw.js | push token, SDK registration state and public delivery configuration | delivering web notifications after system permission | until deregistration, token expiry or clearing site data |
| secure storage (mobile) | session token | opaque authentication token; no encryption keys | keeping the mobile session | until logout, expiry or account deletion |
| secure storage (mobile) | push registration | FCM/APNs token | delivering notifications after system permission | until deregistration, expiry or uninstall |
Encryption keys (Master Password, master key, private keys) are never written to cookies, localStorage or any persistent browser storage — they exist only in tab memory and vanish when the tab closes.
3. Analytics (consent only)
With your prior, freely given consent (Polish Electronic Communications Law; Art. 6(1)(a) GDPR) we use PostHog for product analytics: which features are used and where users hit problems.
- Events carry a user identifier and technical properties (event type, entry type, flags) — never Entry contents, passwords, keys or any other secrets.
- Content autocapture and session recording are disabled; secret-bearing fields are additionally masked.
- You may withdraw consent at any time in settings — this stops the collection of new events and further use of data for consent-based analytics, with no effect on the Service.
Until consent is given, analytics stays off.
| Where | Key / category | Data | Activation | Deletion |
|---|---|---|---|---|
| localStorage (web) | ph_<project_token>_posthog | pseudonymous identifier, session state and technical properties | consent only; PostHog is configured without cookies | immediately on withdrawal or clearing site data |
| SDK storage (mobile) | PostHog keys for the released SDK version | pseudonymous identifier and analytics state | consent only | immediately on withdrawal or uninstall |
You may withdraw consent at any time in the settings. Withdrawal stops the collection of new events and further use of data for consent-based analytics and removes the local PostHog identifier. It does not affect the lawfulness of processing carried out before withdrawal.
Withdrawing consent is not the same as deleting the account. Independently, you may exercise your right to erasure under Article 17 GDPR by contacting patryk.roguszewski@palladin.io. Historical events remain subject to the retention periods and data-subject-rights procedure described in the Privacy Policy. The web key includes the environment’s project token and contains no User secret.
4. Push notifications
After you grant the system-level notification permission, your device receives a push token (Firebase Cloud Messaging / APNs) used solely to deliver Service notifications (e.g. an Agent’s access request). Withdraw via system or app settings.
5. Managing
Clear site data in your browser to remove localStorage entries. Analytics consent controls live in the Service; withdrawal stops analytics and removes the local PostHog identifier. The change history is available in the public legal changelog.
6. Contact and changes
Send questions about cookies, similar technologies and analytics consent to patryk.roguszewski@palladin.io. We will announce material changes in the Service or by e-mail at least 14 days in advance where a change affects optional storage of or access to data on your device.