1. This website stores almost nothing
The Cofleet marketing site runs no analytics and no advertising pixels, which is why there is no banner on it. The demo form asks for your email address, a company-size selection, and an optional description of your needs. These are sent to us only when you submit the final step, and are not saved to browser storage. What we do with it is in the Privacy Policy. A few things still touch your browser here, and none of them needs your permission:
- If you switch these pages to the dark version, we remember which one you chose so the next page you open matches. Until you press that switch nothing is written at all — the site simply follows your device's own light or dark setting.
- If you unlock the private preview, we remember it for the rest of the tab so the next preview page does not ask again. Closing the tab forgets it.
- Our network provider, Cloudflare, may set a security cookie when it checks whether traffic is automated. We do not control when that happens, and at the time of writing no such cookie is issued on this site.
The site also loads fonts from Google's font service, which means Google receives your IP address and user agent as part of that request. That sets no cookie, but it is a transfer, so it is named on the trust page.
Everything else below is about the Cofleet web app.
2. The full register
Local and session storage do the same job as a cookie and the law treats them the same way, so they are listed alongside them. Where a family of keys shares a prefix it gets one row; the prefix is exact, so you can find every member in your browser's developer tools. This table is meant to be complete — if Cofleet set something it does not describe, that is a bug in this page, and we would like to hear about it.
| Name | Kind | Purpose | Category | Retention |
|---|---|---|---|---|
| cofleet-theme | Local storage | Set by this website. Remembers whether you chose the light or the dark version of these pages. It is written only if you press the switch — until then the site follows your device's own setting and stores nothing. It holds one word, light or dark, and nothing about you. | Strictly necessary | Until you clear your browser storage |
| cofleet-preview-unlocked | Session storage | Set by this website. Remembers that you entered the access code for the private preview pages, so the next one does not ask again. Closing the tab forgets it, and it holds nothing about you. | Strictly necessary | Until you close the tab |
| cofleet_session | Cookie | Keeps you signed in. Without it every page load would log you out. Named velocity_session before August 2026; a leftover cookie under the old name still signs you in until it is cleared at your next sign-in or sign-out. | Strictly necessary | 30 days |
| cofleet_oauth_csrf | Cookie | Protects the integration connect flow against cross-site request forgery. | Strictly necessary | 10 minutes |
| google_oauth_state | Cookie | Carries the anti-forgery state for a Google sign-in that is in flight. | Strictly necessary | 10 minutes |
| pending_google | Cookie | Holds your verified Google identity for the moment between signing in and entering an invite code. | Strictly necessary | 10 minutes; the identity inside it expires after 5 |
| cofleet_board_share | Cookie | Lets a shared-board link keep working as you view the board, without putting the link's token in any URL. | Strictly necessary | Up to 12 hours, never longer than the link itself |
| cofleet:*, cofleet.*, cofleet-*, cofleet_* | Local storage | Interface preferences, so the app looks the way you left it: light or dark, sidebar and section states, table sorting and columns, which lane or view you had open, how far you got in onboarding. | Strictly necessary | Until you clear it |
| graph.* | Local storage | Board editor preferences: pen settings and toolbar position. | Strictly necessary | Until you clear it |
| __cf_bm, cf_clearance, _cfuvid | Cookie | Cloudflare, our network provider, telling automated traffic apart from people. Set only if a security check runs, so you may never see one. | Strictly necessary | Up to 30 minutes (__cf_bm); up to 1 year (cf_clearance) |
Strictly necessary means it exists to deliver something you asked for: staying signed in, not being asked the same question twice, keeping the interface the way you left it, or letting a security check tell you apart from a bot. Under the ePrivacy rules these do not need your consent. You should still know they exist, which is why they are listed.
There is no second category. Every row above is strictly necessary: this site and the app set no analytics cookie, run no session replay, and load no third-party analytics script, which is why neither surface shows a banner. Our servers separately record which features ran and what our AI calls cost, using identifiers and counts and no browser storage at all. Section 3 and the Privacy Policy cover that.
3. What our servers record, without touching your browser
Our servers separately record which features ran for your account: identifiers and counts, no cookies involved. They use no analytics cookie or other browser storage, so there is no analytics consent banner. These records are still covered by the Privacy Policy.
Our servers send product usage events, AI call metadata and daily model-cost totals per workspace to PostHog's EU cloud (eu.i.posthog.com). They describe which features ran, which model was used, token counts, latency and USD spend, with identifiers and fixed category labels. They contain no message text, memory content, names, email addresses, URLs or window titles. There is no browser analytics SDK or session replay.
Organizations can opt out of PostHog telemetry by contacting us. This covers product usage events, AI call metadata and daily model-cost totals. There is no per-user switch for this telemetry, and clearing browser storage does not stop it. Account-linked events are personal data. The Privacy Policy sets out what we collect, our legitimate interests and your right to object.
4. Changing your mind
Every entry in the table above is strictly necessary, so there is nothing here to consent to and nothing to withdraw. That is why the app shows no cookie banner: we set no analytics cookie to ask about.
Your browser can still block or delete cookies and storage for a site. That works, though clearing the strictly necessary ones will sign you out and forget how you had the interface set up.
The server-side records in section 3 sit outside browser controls. Your rights over them, including the right to object, are in the Privacy Policy.