Legal
Cookie & Tracking Disclosure
Transparent breakdown of cookies and local storage used on inboxdays.com and the InboxDays app.
This disclosure explains how InboxDays uses cookies, local storage, and similar technologies. It supports ePrivacy Directive and GDPR transparency expectations.
1. Essential cookies & storage (always on)
These are required to provide secure login and core functionality. They do not require consent under typical essential-use exceptions, but we disclose them for transparency.
- Keycloak session state — identity provider cookies such as
KEYCLOAK_IDENTITY/ session cookies set by the auth host (e.g.auth.*.inboxdays.com) to maintain authenticated sessions. - OAuth anti-CSRF / PKCE — short-lived values in
sessionStorage/localStorageand a first-party cookieinboxdays_kc_pkce(SameSite=Lax, ~15 minutes) protecting authorization-code flows across identity-provider redirects. - App session token storage — InboxDays may store access/refresh session material in
localStorage(e.g.inboxdays_session_v1) to keep you signed in within the browser app. - UI preferences — pane widths and similar settings in
localStorage(e.g.inboxdays_ui_prefs_v1). - Cookie notice acknowledgment —
inboxdays_cookie_notice_v1inlocalStorageso we do not re-show the banner every visit.
2. Analytics cookies
InboxDays does not currently set non-essential analytics or advertising cookies by default. If we introduce analytics in the future, we will:
- Update this disclosure with vendor names and purposes
- Present an opt-in / opt-out consent control where required
- Honor withdrawal of consent as easily as it was given
3. Managing storage
You can clear site data via your browser settings. Clearing storage will sign you out and reset local preferences. Blocking essential auth cookies may prevent login from working.