Cookie and local storage policy
Our commitment to privacy and transparency. Learn how we utilize cookies and local storage across our platform to ensure security, performance, and offline capabilities.
Essential security & session cookies
Essential platform requirementStrictly necessary for user authentication, zero-knowledge session key management, and security verifications.
| Item / Technology | Purpose | Duration |
|---|---|---|
| reminda_session | Encrypted user authentication session state | Session / 24 hours |
| cf_clearance / cf_turnstile | Security clearance & bot mitigation | Up to 30 days |
| locale_pref | Stores active language and locale preferences | 1 year |
Client local storage & IndexedDB
Essential platform requirementUtilizes browser IndexedDB and local storage to securely store encrypted data locally for offline access and performance.
| Item / Technology | Purpose | Duration |
|---|---|---|
| dexie_reminda_vault | Local offline encrypted database cache | Persistent until cleared |
| e2ee_device_keypair | Local device cryptographic key storage | Persistent local device |
Zero third-party advertising policy
Zero advertising trackersWe do not utilize cross-site advertising networks or data broker trackers.
| Item / Technology | Purpose | Duration |
|---|---|---|
| Ad trackers | Not installed — zero cross-site advertising tracking | N/A |
| Data brokers | Not installed — personal data is not sold | N/A |
1. Introduction and scope
This Cookie policy explains how Reminda ("we," "us," or "our") uses cookies, local storage, and similar tracking technologies when you interact with our services. This includes our primary website, web application, iOS application, and Android application (collectively, the "Platform").
We aim to maintain transparency regarding the data we store on your devices. This policy is intended to generally align with applicable global privacy standards, including the General Data Protection Regulation (GDPR), the UK GDPR, the ePrivacy Directive, and the California Consumer Privacy Act (CCPA) as amended by the CPRA, where operationally applicable.
2. Definitions
• Cookies: Small text files placed on your device by websites you visit. They are widely used to make platforms function efficiently and to provide information to the service operators.
• Similar technologies: Includes local storage, session storage, IndexedDB, software development kits (SDKs), mobile advertising IDs, web beacons, and pixels.
• First-party cookies: Technologies set directly by Reminda when you use our Platform.
• Third-party cookies: Technologies set by domains or service providers other than Reminda (e.g., analytics or security providers).
3. Types of technologies we use
We restrict our use of local storage and cookies primarily to those necessary for the core functionality of our SaaS Platform:
• Strictly necessary cookies: Essential for you to browse the Platform and use its features, such as accessing secure areas, maintaining zero-knowledge session key management, fraud prevention, API security, and load balancing. Without these, core services cannot be provided.
• Functional cookies: Allow the Platform to remember choices you make (such as language preferences, time zone preferences, or remember-me functionality) to provide a localized, personalized experience.
• Performance and analytics cookies: Used to monitor platform stability, feature flags, crash reporting, and general performance metrics. We utilize industry-standard analytics providers (such as Google Analytics or Vercel Analytics) to understand how users interact with our web and mobile applications to improve the service.
• Advertising / marketing cookies: Reminda strictly limits or prohibits the use of cross-site tracking pixels and third-party advertising cookies. We do not sell your data to data brokers.
4. Legal basis and purposes of processing
Where required by applicable law, we rely on legitimate interest or contractual necessity to place strictly necessary cookies (e.g., GDPR Art. 6(1)(b) and 6(1)(f)). These technologies are critical for SaaS session management, End-to-End Encryption (E2EE) cryptographic key generation, authentication, and security mitigation (e.g., Cloudflare Turnstile).
For non-essential cookies (such as analytics), we rely on your explicit consent, which may be withdrawn at any time via our preference center.
5. Cross-platform tracking and third-party services
Our technologies may operate across the web application and our mobile applications (iOS and Android) to ensure continuous synchronization of your encrypted data via IndexedDB and local storage.
We may integrate select third-party services for critical infrastructure. These providers may set their own necessary cookies:
• Cloud hosting & security: Providers like Cloudflare or Google Cloud for rate limiting, CDN delivery, and bot mitigation.
• Payment providers: Paddle, RevenueCat, Apple, Google, and MoMo to securely process subscription payments.
6. Cookie duration and data retention
The lifespan of the technologies we use falls into two categories:
• Session cookies: Temporary and expire once you close your browser or your active session concludes.
• Persistent cookies / local storage: Remain on your device for a predetermined period or until manually deleted. For instance, our offline IndexedDB databases remain on your device persistently to enable offline functionality until you clear your browser cache or log out of the mobile application.
7. Managing your preferences and controls
You retain the right to control how cookies are utilized on your devices:
• Consent management: Where applicable, you may adjust your optional cookie preferences via our in-app cookie banner or preference center.
• Browser controls: Most web browsers allow you to control cookies through their settings. Note that disabling strictly necessary cookies or local storage will severely impact functionality, including your ability to log in and sync offline data.
• Mobile device controls: On iOS and Android, you can utilize system-level settings to limit tracking or reset device identifiers.
• Global Privacy Control (GPC) & Do Not Track (DNT): We respect GPC signals where legally required. While we acknowledge DNT headers, our strict limitation on third-party tracking means your experience remains inherently private regardless of the DNT status.
8. International data transfers & children's privacy
Information collected via cookies and local storage may be processed in jurisdictions outside of your country of residence. When such transfers occur, we implement appropriate technical and legal safeguards in alignment with standard contractual clauses or equivalent legal frameworks.
Our Platform is not directed at children under the age of 13 (or 16 in certain jurisdictions), and we do not knowingly place cookies on devices operated by such individuals without valid parental consent.
Questions concerning privacy & cookies?
Contact our compliance and privacy team anytime.