Skip to content
MonoDuty
  • Features
  • Integrations
  • Pricing
  • Documentation
  • Contact
🌐 EN
  • English
  • Türkçe
  • Deutsch
  • Eesti
  • Nederlands
Log inGet Started
  • Features
  • Integrations
  • Pricing
  • Documentation
  • Contact
Get StartedLog in
ENTRDEETNL

Legal

Cookie and Browser Storage Policy

The cookies and local-storage keys used by the current MonoDuty website and application.

Last updated: August 26, 2026

Contents

  1. 1. Scope
  2. 2. Current Uses
  3. 3. Categories
  4. 4. MonoDuty Storage Keys
  5. 5. Third-Party Storage
  6. 6. Application Local Storage
  7. 7. Controls
  8. 8. Analytics Choice
  9. 9. Changes
  10. 10. Contact

1. Scope

Cookies are small values a website asks a browser to store and send with later requests. Local storage is browser storage scoped to an origin; unlike a cookie, it is not automatically sent with every HTTP request.

This policy covers the current MonoDuty marketing origin and application origin. Third-party features may use their own cookies or storage under their own notices.

2. Current Uses

The marketing site uses local storage to remember whether a visitor accepted optional analytics. It loads Google Tag Manager only after acceptance. Authentication pages do not load marketing analytics.

The API uses necessary cookies for a server-side browser session, CSRF protection, and the short cross-origin sign-in handoff. The application uses local storage only for active-workspace selection, display theme, and a temporary return path used during email verification. The current marketing site does not use advertising cookies.

3. Categories

3.1 Necessary storage

Storage needed for sign-in, security, navigation continuity, and a visitor’s privacy choice. Blocking application storage can prevent sign-in or remove saved settings.

3.2 Optional analytics

Google Tag Manager and analytics tags are optional on the marketing site and are not loaded until the visitor accepts analytics.

3.3 User-invoked third-party features

Google sign-in and reCAPTCHA may use Google-controlled storage when their scripts load. Google sign-in can be avoided by using email/password. The contact form requires reCAPTCHA; an alternative support channel is available by email.

4. MonoDuty Storage Keys

Origin and keyTypePurposeCurrent lifetime
monoduty.com: monoduty_cookie_preferences_v1Local storageStores policy version, analytics choice, and save timeUntil cleared or replaced
api.monoduty.com: __Host-monoduty_sessionSecure, HttpOnly necessary cookieAuthenticates the server-side browser session; it is not readable by application JavaScriptShort server-defined idle and absolute lifetime, or earlier logout/revocation
api.monoduty.com: monoduty_handoff_bindingSecure, HttpOnly necessary cookieBinds a one-time landing-to-dashboard sign-in code to the initiating browserAbout two minutes or until exchange
app.monoduty.com: active_organization_idLocal storageRemembers the active workspaceUntil changed or cleared
app.monoduty.com: themeLocal storageRemembers display themeUntil changed or cleared
app.monoduty.com: post_verification_return_toLocal storageTemporary safe navigation path during email verificationRemoved when consumed; otherwise until cleared

The CSRF synchronizer value is kept only in page memory and is not a reusable authentication credential. These are current first-party keys, not a promise that no technical key will ever change.

5. Third-Party Storage

After analytics acceptance, Google Tag Manager may load configured analytics tags that set Google-controlled identifiers. Exact Google names and lifetimes can change under Google’s configuration and notices.

Google Identity Services and reCAPTCHA may also set or read Google-controlled cookies or browser storage when those features load. Stripe’s hosted Checkout and billing portal may use Stripe-controlled storage when you open those services. MonoDuty does not claim that its first-party settings erase storage controlled on another domain.

6. Application Local Storage

The application does not persist its browser authentication credential in local storage. Authentication uses an API-origin cookie that application scripts cannot read. Local storage holds display and navigation preferences only.

The active workspace, theme, and verification return path do not replace server-side authorization; the API independently validates the session, role, membership, and resource scope.

7. Controls

Use “Cookie settings” in the site footer to accept analytics or choose only necessary storage. Choosing only necessary storage prevents analytics scripts from loading on the next page load. Browser settings can inspect or delete first-party storage and block third-party cookies.

Using the application’s logout control invalidates the server-side session. Deleting or blocking the necessary API cookie signs the browser out; blocking local storage removes saved workspace and display preferences but does not expose a credential. Blocking reCAPTCHA can prevent contact-form submission; email support remains available.

8. Analytics Choice

On a first visit, optional analytics remain off until “Accept analytics” is selected. “Only necessary” records a refusal without loading Google Tag Manager. The saved choice can be reopened through the footer.

Withdrawing analytics takes effect for new page loads and future collection. MonoDuty also requests denial from any already loaded analytics code and removes known first-party Google Analytics cookies where the browser permits it, but cannot erase provider-side data already collected.

9. Changes

This policy and the stored policy version are updated when first-party storage or analytics behavior materially changes. A new choice may be requested after such a change.

10. Contact

Questions about cookies or browser storage can be sent to [email protected] or through the contact form.

Company details

Legal entity
monoduty OÜ
Legal structure
Limited company (OÜ)
Registry code
17418117 (Estonia)
Address
Sepapaja tn 6, 15551 Tallinn, Harju maakond, Estonia
Contact
[email protected]
MonoDuty

Focused incident alerting with on-call ownership and testable delivery routes.

Product

  • Features
  • Integrations
  • MonoDuty MCP
  • How it works
  • Pricing
  • Documentation
  • System status
  • Comparisons
  • vs PagerDuty
  • vs OpsGenie
  • Support

Company

  • Team
  • Careers
  • Contact

Legal

  • Terms of Service
  • Privacy Policy
  • Security
  • GDPR information
  • Data Processing Terms
  • Cookie Policy

Contact

  • [email protected]
  • Open a support ticket

monoduty OÜ
Sepapaja tn 6, 15551 Tallinn, Harju maakond, Estonia
Reg. 17418117

© 2026 monoduty OÜ. All rights reserved.🇪🇺 Made in EU

Your analytics choice

We use necessary browser storage for this choice. Optional analytics load only if you accept them. Cookie and storage details.