Legal
Cookie notice
Last updated 2026-08-11
01Signed-in session
Signing in sets one cookie, ufa_session, holding your account and workspace. It is signed so it cannot be edited or forged, marked HttpOnly so page scripts cannot read it, sent only over HTTPS in production, scoped SameSite=Lax, and expires after 30 days or immediately on sign-out. Session validity is also checked server-side on every request, not left to the cookie's own expiry alone.
02Public-page analytics
The public pages (not your signed-in workspace) can load Plausible, a self-hosted analytics tool, to count pageviews and CTA clicks. It runs without setting a cookie and without writing to local storage — there is no visitor identifier to opt out of.
03Referral attribution
On first visit, the public pages may capture UTM parameters and referrer into your browser's sessionStorage under the key mkt_attr, along with the landing page and a timestamp. This is not a cookie: it lives only for that browser tab and disappears when the tab closes.
04Push notification prompt
If you dismiss the in-product push notification prompt, we remember that in localStorage (key ufa.pushPromptDismissedAt) so we don't ask again right away. Turning on push notifications registers a browser service worker for delivery; neither is used for tracking.
05What we don't do
No third-party advertising or retargeting cookies, no cross-site tracking pixels, and no cookie or session data sold or shared for advertising.