Cookie Policy

Effective date: 2026-08-09 00:00

Last updated: 2026-08-09 00:00

This Policy explains how Documira uses cookies and browser storage on its marketing websites and professional application. The controller is identified in the Legal Notice.

1. What these technologies are

Cookies are small values stored by a website in a browser. localStorage and sessionStorage are similar browser mechanisms. Necessary technologies support requested functions, security and consent records. Analytics technologies help measure website use and are activated only after consent on the marketing websites.

Rejecting analytics does not prevent ordinary use of the marketing website. The authenticated application needs session and security storage to work.

2. Marketing website storage

Analytics remains disabled until verified production identifiers are configured. If enabled, Google Analytics and PostHog use the consent-controlled storage below; necessary consent storage remains available independently.

Name or patternProviderPurposeCategoryDuration
documira_cookie_consentDocumiraStores accepted or declined status, policy version and expiryNecessary180 days
documira_attrDocumiraRemembers consented campaign and audience parameters between pagesAnalytics/attributionBrowser-tab session
_ga, _ga_*Google AnalyticsDistinguishes browsers and measures consented page useAnalyticsUp to 2 years, subject to Google configuration
ph_*_posthog and related ph_ local-storage keysPostHogPseudonymous, consented page analyticsAnalyticsUp to 180 days or until withdrawal

PostHog is configured for EU ingestion, basic page analytics, no session replay, no person profiles and no automatic element or input capture. Documira does not call analytics identity functions to attach website activity to an account.

Before analytics loads, the website removes organization, account, checkout and subscription identifiers from the page URL. The organization identifier needed for an upgrade checkout is kept only in page memory and forwarded directly to the application.

Normal hosting and Cloudflare security may also process request metadata and use strictly necessary measures to deliver and protect a requested page. The marketing contact form transmits information to Formspree only when you submit it.

3. Application cookies and storage

The authenticated application uses technologies including:

Name or typePurposeCategoryTypical duration
sessionidKeeps the user authenticated using a server-side sessionNecessaryApproximately 14 days or until invalidated
csrftokenProtects forms and state-changing requestsNecessary/securityUp to 1 year
Language cookieRemembers Romanian or English selectionPreferencesBrowser session
documira_tzDisplays dates and trial deadlines in the user’s timezonePreferences/necessary functionBrowser session
documira_trial_bannerRemembers a dismissed service noticeNecessary functionApproximately 12 hours
documira_attributionCarries source, campaign and landing information to account creationAttributionUp to 90 days or until signup
Server-side session dataSupports login, OAuth, checkout, selected records and generation flowNecessarySession expiry and operational cleanup
HTMX history storageMay cache recently navigated application fragments in the browserNecessary application behaviorUntil browser storage is cleared

The application attribution cookie records source or campaign information received in an acquisition link. It is an attribution technology, not an authentication requirement. Its activation must be aligned with the consent transmitted from the marketing journey before production launch.

Google and Meta may set their own cookies when you choose their login buttons or visit their services. Dodo Payments sets storage on its hosted checkout and billing portal under its own policy.

On a first marketing-site visit, the banner offers equally accessible choices to accept analytics or continue with necessary storage only. Analytics scripts are not loaded before acceptance.

When analytics is enabled, you can reopen the banner through Cookie preferences in the footer. Withdrawing consent records a declined choice, tells loaded providers to stop capture where supported, removes analytics cookies and local-storage identifiers accessible to this website, and reloads the page without analytics. Withdrawal does not affect processing that was lawful before withdrawal or information already aggregated by a provider.

Browser controls can also delete or block storage. Blocking necessary application cookies will prevent login and other requested functions.

Necessary storage is used to provide a service or communication expressly requested by the user and for service security. Analytics and marketing attribution storage on the marketing websites is based on consent under GDPR and applicable ePrivacy rules. Related personal-data processing is described in the Privacy Notice.

6. Providers

Google Analytics is provided by Google. PostHog provides EU-hosted analytics. Cloudflare delivers and protects the websites, and Formspree handles submitted contact forms. Details, transfer safeguards and data-rights information are in the Privacy Notice and the providers’ own notices.

7. Changes and contact

This Policy will be updated if technologies, purposes or retention periods change. Privacy questions and withdrawal issues may be sent to documira.contact [at] gmail.com. Ordinary support should use the website contact form.