This notice explains the cookies and similar technologies the Diligence Forge platform uses.
1. Strictly-necessary (no consent required)
| Name | Purpose | Type | Retention |
|---|---|---|---|
sb-<project>-auth-token (and chunked .0/.1) |
httpOnly authentication session — required to stay signed in and to protect against token theft | First-party, httpOnly, Secure, SameSite=Lax | Session / token lifetime (~1h, refreshed) |
Theme preference (localStorage df-theme) |
Remembers light/dark choice; prevents a flash of incorrect theme | First-party local storage | Until cleared |
These are essential to deliver a secure, authenticated service and are exempt from consent under PECR / ePrivacy (counsel to confirm classification).
2. Analytics (consent required — off by default)
| Name | Purpose | Provider |
|---|---|---|
| Vercel Speed Insights | Aggregate, privacy-friendly performance metrics (Core Web Vitals). No advertising, no cross-site tracking. | Vercel |
Analytics is disabled until you opt in via the cookie-consent banner (W3.13). You can withdraw consent at any time; withdrawal stops further analytics collection.
3. What we do not use
No advertising cookies, no cross-site tracking, no data brokers, no fingerprinting for marketing.
4. Managing cookies
Strictly-necessary cookies cannot be disabled without breaking sign-in. You
can clear cookies/local storage in your browser. Analytics consent is managed
via the in-app banner and recorded against the current POLICY_VERSION.
5. Changes
Material changes bump POLICY_VERSION. See also the
Privacy Policy and
Sub-processor register.
Questions: privacy@opsfi.co.
This document is view-only inside Diligence Forge and is not available for printing or download. Sign in and open Settings → Documentation to read it.