Legal
Cookie and Browser Storage Policy
The cookies and local-storage keys used by the current MonoDuty website and application.
Last updated: August 26, 2026
2. Current Uses
The marketing site uses local storage to remember whether a visitor accepted optional analytics. It loads Google Tag Manager only after acceptance. Authentication pages do not load marketing analytics.
The API uses necessary cookies for a server-side browser session, CSRF protection, and the short cross-origin sign-in handoff. The application uses local storage only for active-workspace selection, display theme, and a temporary return path used during email verification. The current marketing site does not use advertising cookies.
5. Third-Party Storage
After analytics acceptance, Google Tag Manager may load configured analytics tags that set Google-controlled identifiers. Exact Google names and lifetimes can change under Google’s configuration and notices.
Google Identity Services and reCAPTCHA may also set or read Google-controlled cookies or browser storage when those features load. Stripe’s hosted Checkout and billing portal may use Stripe-controlled storage when you open those services. MonoDuty does not claim that its first-party settings erase storage controlled on another domain.
6. Application Local Storage
The application does not persist its browser authentication credential in local storage. Authentication uses an API-origin cookie that application scripts cannot read. Local storage holds display and navigation preferences only.
The active workspace, theme, and verification return path do not replace server-side authorization; the API independently validates the session, role, membership, and resource scope.
8. Analytics Choice
On a first visit, optional analytics remain off until “Accept analytics” is selected. “Only necessary” records a refusal without loading Google Tag Manager. The saved choice can be reopened through the footer.
Withdrawing analytics takes effect for new page loads and future collection. MonoDuty also requests denial from any already loaded analytics code and removes known first-party Google Analytics cookies where the browser permits it, but cannot erase provider-side data already collected.
9. Changes
This policy and the stored policy version are updated when first-party storage or analytics behavior materially changes. A new choice may be requested after such a change.
10. Contact
Questions about cookies or browser storage can be sent to [email protected] or through the contact form.