📖 Trust Center Navigation

Cookie and Storage Notice

1. Introduction

This notice explains how NotiCord ("we", "us", or "our") uses cookies, localStorage, sessionStorage, and similar technologies on our website and application. This notice should be read together with our Privacy Policy and Terms of Use.

This notice covers NotiCord properties. External websites linked from NotiCord (for example Stripe Checkout pages or Atlassian support portal pages opened in a separate tab) apply their own cookie and privacy notices.

Capitalized terms not defined in this notice have the meanings given in the Terms of Use and/or the DPA (as applicable). If documents conflict, the DPA prevails for Customer Data processing as Processor.

2. What are cookies and browser storage?

Cookies are small text files stored on your device when you visit a website.

localStorage and sessionStorage are browser storage mechanisms that allow websites to store data locally on your device. Unlike cookies, this data is not automatically sent to the server with each request. localStorage persists until explicitly cleared, while sessionStorage is deleted when you close your browser tab.

NotiCord uses localStorage and sessionStorage in addition to cookies where needed.

Consent requirements can apply not only to cookies, but also to similar technologies (including localStorage/sessionStorage) where they store or access information on your device.

3. How we use browser storage

We use cookies and similar technologies for the following purposes:

3.1. Strictly Necessary Technologies

These technologies are essential for the Application to function properly and cannot be disabled. They enable core functionality such as:

Technology / Storage Purpose Provider
Auth0 browser localStorage, session cookies, and non-secret session hints Authentication and session management across refresh and new tabs until logout or session expiry Auth0, Inc.
Application localStorage and session storage Application state and sign-in status hints NotiCord
Sentry storage (sessionStorage and/or similar) Error monitoring and debugging for service reliability/security (configured to minimize personal data) Functional Software, Inc.

Auth0 access/refresh tokens are kept in browser localStorage by the Auth0 SDK. Some essential cookies, localStorage entries, session storage, or non-secret session hints may persist until logout, session expiry, or until cleared, while others may last only for the current browser session. You can manage storage using your browser settings.

Legal basis / consent model: Under GDPR, we rely on Art. 6(1)(b) and/or Art. 6(1)(f) for strictly necessary technologies used to provide the service and maintain security. Where non-essential technologies store information on your device or access information stored on your device, we rely on consent (Art. 6(1)(a)) and obtain it in advance where required under Polish electronic communications law (Prawo komunikacji elektronicznej). Consent must meet applicable GDPR standards.

Privacy note: We configure error monitoring to minimize personal data collection (for example by avoiding sensitive content/secrets where feasible). Technical fields captured can depend on configuration and error context. Error monitoring is not used for advertising.

3.2. Public website analytics and Application analytics

Public marketing and documentation pages: optional PostHog collection remains off until you choose Allow analytics. We use PostHog's EU service to measure public page paths, selected link actions, source labels and random browser/session identifiers. Public session recordings and automatic click capture are disabled. If you choose Reject, we stop collecting new analytics and clear this tracker's local identifiers and source context. Information collected before you changed your choice may still reach our analytics provider. A local preference records your choice. Public analytics does not connect the browser to an Application subscription or account. See the Website analytics notice for the complete public fields, current event retention and withdrawal details.

Application analytics: the Application separately uses limited usage events, feature tracking and minimized session recordings in memory-only mode without persistent analytics cookies or localStorage identifiers. The public website choice does not turn Application analytics or necessary operations on or off. Application analytics is not used for advertising.

Technology / Storage Purpose Provider
Local public preference Remember allow/reject choice without a visitor identifier NotiCord
PostHog public localStorage, only after permission Optional public visit and selected-link measurement across visits on that origin PostHog, Inc. (EU Cloud)
PostHog Application memory mode Application usage and minimized recordings without persistent analytics identifiers PostHog, Inc. (EU Cloud)

Legal basis: public website analytics and its optional storage use consent (GDPR Art. 6(1)(a)). For the separately described Application analytics without non-essential storage/access on the device, Service Provider relies on GDPR Art. 6(1)(f) (legitimate interests) for service analytics and improvement.

IP addresses: we do not use IP addresses as analytics identifiers. They may be processed in network communications. The public tracker does not enable IP-based location enrichment.

Third-party privacy notice: PostHog Privacy Policy

4. How to manage cookies

4.1. Public analytics choice

On public marketing and documentation pages you can choose:

  • Allow analytics: enable optional public visit and selected-link measurement and origin-local analytics storage.
  • Reject: keep that optional public tracker off. Necessary service technologies and separately described Application analytics follow Section 3.2.

Use Analytics settings in the public-page footer to reopen the same controls without signing in. Rejecting later stops new public collection and clears this public tracker's local identifiers and source context. Information collected before you changed your choice may still reach our analytics provider. Clearing browser data or rejecting future collection does not itself delete provider records received earlier; contact contact@firnity.com about those records. Do not clear essential sign-in storage merely to change the public choice.

This choice applies to the public origin you are visiting. It does not transfer a browser identifier to the Application or alter Application account settings.

4.2. Browser Settings

You can clear cookies, localStorage, and sessionStorage in your browser settings, browser developer tools, or by clearing site data. Clearing essential storage may log you out and affect the Application's functionality.

For more information about browser storage, visit MDN Web Docs.

5. Third-party storage

Some storage is managed by third-party services we use:

  • Auth0: Authentication/session management storage (strictly necessary)
  • Sentry: Error monitoring storage used for reliability/security (strictly necessary)
  • PostHog: optional public analytics with origin-local storage only after Allow analytics, with no public recordings; separate Application analytics and minimized recordings in memory-only mode as described in Section 3.2
  • Atlassian Jira Service Management support portal: if you open the support portal in a separate tab, Atlassian applies its own cookies/storage under its own notices

These third parties may use storage mechanisms in accordance with their own privacy policies. We use these providers to operate and improve our own service (controller-side vendors) and configure EU data regions where available.

6. What data is stored

Essential storage (no consent required):

  • Authentication/session state data and non-secret session hints (Auth0)
  • Application state and navigation history
  • Error context for debugging and service reliability (Sentry)
  • Consent preferences

Public analytics storage (only after Allow analytics):

  • Random browser/session identifiers
  • Consented first and latest observed public source context
  • Recognized campaign labels and timestamps

A preference separately remembers your public choice. Public page/link events are received by PostHog; they are not a local copy of page content or form entries. You can clear this public tracker’s local identifiers and source context with Analytics settings. Browser controls can also clear site storage, which may affect necessary sign-in state. Application memory-only analytics is described separately in Section 3.2.

7. Changes to this Cookie Notice

We may update this Cookie Notice from time to time to reflect changes in technology, legal requirements, or our practices. Any changes will be posted on this page with an updated "Last updated" date.

Significant changes will be communicated via email to registered users.

8. Contact us

If you have questions about our use of cookies, please contact us:

  • Email: contact@firnity.com
  • Address: ul. Zamknięta 10, lok. 1.5, 30-554 Kraków, Poland

For data protection inquiries, you may also contact the Polish supervisory authority:


Last updated: April 28, 2026

Support