Skip to main content

Legal

Cookies and local storage

Which cookies and browser storage Nisaba uses, what each one is for and how long it is kept, and how you can change or withdraw your choice at any time.

Last updated:

The German version of this document is legally binding. This English text is provided for convenience. Deutsche Fassung (rechtsverbindlich)

Contents

Overview

Nisaba stores only what is needed for sign-in, security and your settings. This strictly necessary storage is allowed without consent (§ 165(3) TKG 2021). Usage measurement with PostHog is optional and runs only if you agree. Before you decide it is neither loaded nor does it send data.

We do not use advertising or marketing storage.

Strictly necessary

NamePurposeTypeDuration
authjs.session-token (prefixed __Secure- on HTTPS)Keeps you signed inCookieUntil you sign out, at most 7 days
authjs.csrf-token (prefixed __Host- on HTTPS)Protection against forged form requestsCookieSession
authjs.callback-url (prefixed __Secure- on HTTPS)Return to the right page after sign-inCookieSession
nisaba_connectProtects connecting an account on GitHub, Mastodon, Bluesky or YouTube (encrypted check value of the request)Cookie (set by your choice)10 minutes, deleted on return
nisaba-consent-v1Remembers your cookie choiceLocal storageUntil you clear or change it
nisaba-ui-language, nisaba-guest-ui-language, nisaba-ai-output-languageYour language settingsLocal storageUntil you clear it
theme, nisaba-theme-modeLight or dark appearanceLocal storageUntil you clear it
nisaba-langYour chosen website languageCookie (set by your choice)1 year
nisaba_sidebarRemembers whether the app sidebar is expanded or collapsedCookie (set by your choice)1 year
nisaba-library-layout, nisaba-nav-disclosure, nisaba-tab-dock-openLibrary view, expanded navigation groups and tab dockLocal storageUntil you clear it
nisaba-reader-font-scale, nisaba-reader-serif, nisaba-reader-colorFont size, typeface and colour of the reader viewLocal storageUntil you clear it
nisaba-mindmap-group, nisaba-mindmap-view, nisaba-mindmap-pulsesMind map view settingsLocal storageUntil you clear it
App cache (service worker)Loads static files fasterBrowser cacheUntil the next version

The browser extension stores the server address, your access token and settings in the extension's storage in the browser. You can delete it by removing the extension or resetting it in its settings.

On the sign-up form, Cloudflare Turnstile checks whether a person is filling in the form. For this, Turnstile reads technical characteristics of your browser; it sets no cookies on nisaba.site for this. The check protects the account you asked for against automated abuse and is strictly necessary for that. More in section 11 of the privacy policy.

Usage measurement (only with consent)

ProviderPurposeStorageDuration
PostHog (EU cloud)Counting pages viewed without query strings, device and browser type, approximate location; for this a random identifier of your browserLocal storage (entries start with “ph_” or “__ph_”) and session storage (ph_<project key>_window_id, ph_<project key>_primary_window_exists)Local storage until you withdraw, withdrawing deletes the entries; session storage until you close the tab

No person profiles are built, no sessions are recorded and no input is captured. Nothing is recorded on sign-in and password pages.

Changing your choice

You can change or withdraw your choice at any time with “Cookie settings” in the website footer or, when signed in, in the app under Settings → Account. Rejecting is as easy as agreeing. You can also delete or block cookies and site data in your browser. Without the necessary cookies you cannot sign in.

More about how we process data is in the privacy policy.