Legal
Cookie and Browser Storage Notice
The current RenderBoard web application does not set nonessential browser cookies. It uses one essential HttpOnly refresh cookie plus limited browser storage for workflow and theme preferences.
- Operator
- RenderBoard operator (preview configuration)
- Effective date
- Not configured for this preview build
Current web-app storage
| Storage | Purpose | Lifecycle |
|---|---|---|
| renderboard_refresh cookie | Allows the API to rotate a session and issue a short-lived access token. It is host-only, HttpOnly, path-scoped to authentication routes, and Secure in production. | Rotated on refresh and deleted on logout. Its maximum age follows the deployment’s configured refresh-token lifetime. |
| memory | Keeps the short-lived access token for API requests and the first WebSocket authentication frame. | Lost on page reload or tab close; restored through the refresh cookie when the session remains valid. |
| sessionStorage | Keeps limited plan-intake working metadata, such as document names and extraction state, within the current tab. | Ordinarily cleared when the tab’s session ends. Authentication tokens are not stored here. |
| localStorage | Remembers the optional light or dark theme under renderboard-theme. | Persists until you clear it or change browser/site storage. |
The refresh credential is never returned to web JavaScript. The access token remains in memory rather than localStorage or sessionStorage. Security and request logs are server-side records, not cookies.
Linked services
If hosted payment checkout is configured, following that link leaves the RenderBoard app for the payment provider’s site. That provider may use its own essential or optional storage under its own notice. The active payment provider, if any, is declared on the Subprocessors page.
Changes and controls
If nonessential cookies or browser tracking are added, this notice and any legally required consent control must be updated before public enablement. Clearing the refresh cookie ends the recoverable sign-in session; clearing session storage resets tab-scoped workflow metadata; clearing local storage resets the saved theme.
Send browser-storage questions to privacy@example.invalid.