This policy is published in English and in German. The German version is the binding version; the English text is a translation provided for convenience.
This Cookie and Storage Policy explains the cookies and browser storage that Finalform GmbH uses on its own websites, autopage.dev and app.autopage.dev. It supplements, and should be read together with, our Privacy Policy and our Impressum.
Controller. Finalform GmbH, Theodor-Heuss-Str. 106, 26129 Oldenburg, Germany, registered in the commercial register of the Amtsgericht Oldenburg under HRB 222780, USt-IdNr. DE457693089, Managing Director (Geschäftsführer) Robin Schröder, is the controller for the storage and processing described here.
Contents
-
- What this policy covers
-
- How German law applies
-
- Strictly necessary cookies (no consent required)
-
- Functional and preference storage
-
- Analytics and marketing
-
- Your choices
-
- Changes and contact
1. What this policy covers
This policy covers only the cookies and browser storage that we set on our own properties: the marketing site at autopage.dev and the dashboard at app.autopage.dev.
It does not cover pages that our customers connect to Autopage. When the Autopage snippet runs on a customer’s own landing page, it operates on that customer’s behalf and under that customer’s instructions. For that snippet storage the customer is the controller, and the disclosure of, and any consent for, that storage toward the visitors of those pages is the customer’s responsibility, as set out in our Terms of Service and our Data Processing Agreement. The two storage items the snippet sets on a customer page (a 30-day first-party cookie ap_session, a pseudonymous session identifier, and a session-storage key ap_traffic_source) are therefore out of scope here and are documented to the customer, not in this notice.
2. How German law applies
Two distinct legal layers govern cookies and equivalent browser storage in Germany, and we treat them separately:
- Device layer (access and storage): Section 25 TDDDG. Section 25(1) TDDDG requires consent before information is stored on, or read from, a user’s device, unless the storage or access is strictly necessary to provide a service the user has expressly requested (the exemption in Section 25(2)). This layer applies regardless of whether the stored information is personal data.
- Processing layer (use of the data): Art 6 GDPR. Once stored information is read and used, that processing needs a legal basis under Art 6(1) GDPR. Section 25 consent and the Art 6 basis are two separate requirements.
Web Storage technologies (localStorage and sessionStorage) carry the same Section 25 duty as cookies. We therefore disclose every browser-storage key below alongside the cookies, with the same level of detail: name, type, purpose, duration, Section 25 status, and Art 6 basis.
3. Strictly necessary cookies (no consent required)
This cookie is required to sign you in and keep your session secure. It is strictly necessary for a service you have expressly requested (signing in to the dashboard) and is therefore exempt from consent under Section 25(2) TDDDG.
| Name | Type | Purpose | Duration | Section 25 status | Art 6 basis |
|---|---|---|---|---|---|
better-auth.session_token (prod: __Secure-…) |
Cookie (httpOnly) | Keeps you signed in to the dashboard and keeps your session secure | 7 days | Essential, consent-exempt under Section 25(2) | Art 6(1)(b) contract |
We set no other strictly necessary cookies on our own sites: there is no separate CSRF, consent-store, load-balancer, or CDN cookie configured in our application.
4. Functional and preference storage
These cookies and storage keys remember choices you made so the interface behaves the way you set it. They are first-party, are set in response to your own actions, and are not used to track you or to build a profile.
| Name | Type | Purpose | Duration | Section 25 status | Art 6 basis |
|---|---|---|---|---|---|
better-auth.last_used_login_method |
Cookie (not httpOnly) | Pre-selects the sign-in method you used last | 30 days | Preference, consent question (see Section 6) | Art 6(1)(f) legitimate interest, or consent if reclassified |
theme |
Cookie | Remembers your light or dark theme choice so pages render correctly on the server | 1 year | Preference, consent question (see Section 6) | Art 6(1)(f) legitimate interest, or consent if reclassified |
theme |
localStorage | Mirrors your light or dark theme choice on the client | Until you clear it | Preference, consent question (see Section 6) | Art 6(1)(f) legitimate interest, or consent if reclassified |
sidebar_state |
Cookie | Remembers whether the dashboard sidebar is expanded or collapsed | 7 days | Preference | Art 6(1)(f) legitimate interest |
NEXT_LOCALE |
Cookie | Remembers your interface language for the duration of your browser session | Session (no max-age) | Preference | Art 6(1)(f) legitimate interest |
ap:updates-last-seen |
localStorage | Stores the timestamp of when you last opened the “What’s new” drawer, to show the unread indicator | Until you clear it | Preference | Art 6(1)(f) legitimate interest |
The theme choice is held in two places: a cookie, so the correct theme can be rendered on the server on first load, and a mirrored localStorage key, so the choice persists on the client. Both are listed above so each storage item is disclosed in its own right.
5. Analytics and marketing
We currently use no analytics or marketing cookies on our own properties. There are no third-party trackers, advertising pixels, or analytics scripts on autopage.dev or app.autopage.dev, and there is no consent-management platform or cookie banner, because none is needed for the storage above. Our internal analytics interface is a no-op stub that stores nothing.
Stripe (our payment provider) sets no cookies on our domains: payment is handled on Stripe-hosted pages, and any Stripe cookies are set on Stripe’s own domain, outside the scope of this policy.
Third-country storage: none. All of the cookies and storage keys above are first-party storage on your own device. We use no third-party storage provider that places cookies or storage outside the EEA for our own sites.
If this ever changes, that is, if we introduce any new non-essential storage such as analytics or marketing technology, we will update this policy first and, where the law requires it, obtain your prior consent before that storage is set.
6. Your choices
Delete or block in your browser. You can delete or block cookies and clear browser storage at any time in your browser settings. If you block the strictly necessary better-auth.session_token cookie (production: __Secure-…), you will not be able to stay signed in to the dashboard. Clearing the preference storage simply resets your theme, sidebar, language, sign-in-method, and “What’s new” defaults; nothing else is affected.
Withdrawing consent. Today we set no storage that depends on your consent, so there is no consent to withdraw and no consent banner to manage. If the classification of theme or last_used_login_method is reclassified as consent-requiring (see the classification in Section 4), we will add a control on app.autopage.dev that lets you withdraw consent as easily as you gave it, and we will update this policy accordingly.
7. Changes and contact
We may update this policy when our storage practices change or when the law requires it. Each version carries an effective date at the top of this document. Where a change introduces new non-essential storage, we will act as described in Section 5.
For questions about this policy or about the storage we use, contact us at support@autopage.dev. You can also read our Privacy Policy for the full account of how we process personal data.