Legal

Cookie and Browser Storage Notice

The current RenderBoard web application does not set nonessential browser cookies. It uses one essential HttpOnly refresh cookie plus limited browser storage for workflow and theme preferences.

Operator
RenderBoard operator (preview configuration)
Effective date
Not configured for this preview build

Current web-app storage

StoragePurposeLifecycle
renderboard_refresh cookieAllows the API to rotate a session and issue a short-lived access token. It is host-only, HttpOnly, path-scoped to authentication routes, and Secure in production.Rotated on refresh and deleted on logout. Its maximum age follows the deployment’s configured refresh-token lifetime.
memoryKeeps the short-lived access token for API requests and the first WebSocket authentication frame.Lost on page reload or tab close; restored through the refresh cookie when the session remains valid.
sessionStorageKeeps limited plan-intake working metadata, such as document names and extraction state, within the current tab.Ordinarily cleared when the tab’s session ends. Authentication tokens are not stored here.
localStorageRemembers the optional light or dark theme under renderboard-theme.Persists until you clear it or change browser/site storage.

The refresh credential is never returned to web JavaScript. The access token remains in memory rather than localStorage or sessionStorage. Security and request logs are server-side records, not cookies.

Linked services

If hosted payment checkout is configured, following that link leaves the RenderBoard app for the payment provider’s site. That provider may use its own essential or optional storage under its own notice. The active payment provider, if any, is declared on the Subprocessors page.

Changes and controls

If nonessential cookies or browser tracking are added, this notice and any legally required consent control must be updated before public enablement. Clearing the refresh cookie ends the recoverable sign-in session; clearing session storage resets tab-scoped workflow metadata; clearing local storage resets the saved theme.

Send browser-storage questions to privacy@example.invalid.