This policy is published in English and in German. The German version is the binding version; the English text is a translation provided for convenience.
This Cookie and Storage Policy explains the cookies and browser storage that Finalform GmbH uses on its own websites, autopage.dev and app.autopage.dev. It supplements, and should be read together with, our Privacy Policy and our Impressum.
Controller. Finalform GmbH, Theodor-Heuss-Str. 106, 26129 Oldenburg, Germany, registered in the commercial register of the Amtsgericht Oldenburg under HRB 222780, USt-IdNr. DE457693089, Managing Director (Geschäftsführer) Robin Schröder, is the controller for the storage and processing described here.
Contents
-
- What this policy covers
-
- How German law applies
-
- Strictly necessary cookies (no consent required)
-
- Functional and preference storage
-
- On-site optimization
-
- Your choices
-
- Changes and contact
1. What this policy covers
This policy covers only the cookies and browser storage that we set on our own properties: the marketing site at autopage.dev and the dashboard at app.autopage.dev.
It does not cover pages that our customers connect to Autopage. When the Autopage snippet runs on a customer’s own landing page, it operates on that customer’s behalf and under that customer’s instructions. For that snippet storage the customer is the controller, and the disclosure of, and any consent for, that storage toward the visitors of those pages is the customer’s responsibility, as set out in our Terms of Service and our Data Processing Agreement. The two storage items the snippet sets on a customer page (a 30-day first-party cookie ap_session, a pseudonymous session identifier, and a session-storage key ap_traffic_source) are therefore out of scope for those customer pages and are documented to the customer, not in this notice.
We also run the Autopage snippet on autopage.dev itself, to test and improve our own marketing pages. On our own site we are the controller for that storage, so it is in scope here: it is disclosed in Section 5, and we ask for your consent before it is set, through the cookie banner described there and in Section 6.
2. How German law applies
Two distinct legal layers govern cookies and equivalent browser storage in Germany, and we treat them separately:
- Device layer (access and storage): Section 25 TDDDG. Section 25(1) TDDDG requires consent before information is stored on, or read from, a user’s device, unless the storage or access is strictly necessary to provide a service the user has expressly requested (the exemption in Section 25(2)). This layer applies regardless of whether the stored information is personal data.
- Processing layer (use of the data): Art 6 GDPR. Once stored information is read and used, that processing needs a legal basis under Art 6(1) GDPR. Section 25 consent and the Art 6 basis are two separate requirements.
Web Storage technologies (localStorage and sessionStorage) carry the same Section 25 duty as cookies. We therefore disclose every browser-storage key below alongside the cookies, with the same level of detail: name, type, purpose, duration, Section 25 status, and Art 6 basis.
3. Strictly necessary cookies (no consent required)
This cookie is required to sign you in and keep your session secure. It is strictly necessary for a service you have expressly requested (signing in to the dashboard) and is therefore exempt from consent under Section 25(2) TDDDG.
| Name | Type | Purpose | Duration | Section 25 status | Art 6 basis |
|---|---|---|---|---|---|
better-auth.session_token (prod: __Secure-…) |
Cookie (httpOnly) | Keeps you signed in to the dashboard and keeps your session secure | 7 days | Essential, consent-exempt under Section 25(2) | Art 6(1)(b) contract |
We set no other strictly necessary cookies on our own sites: there is no separate CSRF, load-balancer, or CDN cookie configured in our application. The one consent record we keep, ap_consent, is browser storage rather than a cookie, and is listed in Section 4.
4. Functional and preference storage
These cookies and storage keys remember choices you made so the interface behaves the way you set it. They are first-party, are set in response to your own actions, and are not used to track you or to build a profile.
| Name | Type | Purpose | Duration | Section 25 status | Art 6 basis |
|---|---|---|---|---|---|
better-auth.last_used_login_method |
Cookie (not httpOnly) | Pre-selects the sign-in method you used last | 30 days | Preference, consent question (see Section 6) | Art 6(1)(f) legitimate interest, or consent if reclassified |
theme |
Cookie | Remembers your light or dark theme choice so pages render correctly on the server | 1 year | Preference, consent question (see Section 6) | Art 6(1)(f) legitimate interest, or consent if reclassified |
theme |
localStorage | Mirrors your light or dark theme choice on the client | Until you clear it | Preference, consent question (see Section 6) | Art 6(1)(f) legitimate interest, or consent if reclassified |
sidebar_state |
Cookie | Remembers whether the dashboard sidebar is expanded or collapsed | 7 days | Preference | Art 6(1)(f) legitimate interest |
NEXT_LOCALE |
Cookie | Remembers your interface language for the duration of your browser session | Session (no max-age) | Preference | Art 6(1)(f) legitimate interest |
ap:updates-last-seen |
localStorage | Stores the timestamp of when you last opened the “What’s new” drawer, to show the unread indicator | Until you clear it | Preference | Art 6(1)(f) legitimate interest |
ap_consent |
localStorage | Remembers whether you accepted or declined the optimization storage on autopage.dev (Section 5), so we honor your choice and do not ask again | Until you clear it | Strictly necessary to record and honor your consent choice, consent-exempt under Section 25(2) | Art 6(1)(f) legitimate interest, recording your choice |
The theme choice is held in two places: a cookie, so the correct theme can be rendered on the server on first load, and a mirrored localStorage key, so the choice persists on the client. Both are listed above so each storage item is disclosed in its own right.
5. On-site optimization
We run our own product, Autopage, on autopage.dev to test and improve our marketing pages: it shows different versions of a page and measures which one performs better. This is first-party optimization on our own site, not third-party analytics or advertising. There are no third-party trackers, advertising pixels, or advertising cookies on autopage.dev or app.autopage.dev, and no cross-site tracking.
We set the two storage items below only after you consent, through the cookie banner on autopage.dev. Until you accept they are not set; if you decline they are never set. You can withdraw at any time (Section 6).
| Name | Type | Purpose | Duration | Section 25 status | Art 6 basis |
|---|---|---|---|---|---|
ap_session |
Cookie (first-party, SameSite=Lax) | A pseudonymous session identifier used to measure which version of a page performs better | 30 days | Non-essential, consent required under Section 25(1) | Art 6(1)(a) consent |
ap_traffic_source |
sessionStorage | Records how you arrived at the page (for example the referrer) so a test result can be attributed correctly | Until the browser session ends | Non-essential, consent required under Section 25(1) | Art 6(1)(a) consent |
We do not sell this data and we do not use it to build a profile of you. Both items are first-party storage on your own device: there is no third-party storage provider and no transfer of this optimization storage outside the EEA.
On app.autopage.dev (the dashboard) we run no analytics, marketing, or optimization storage of this kind; our internal analytics interface there is a no-op stub that stores nothing.
Stripe (our payment provider) sets no cookies on our domains: payment is handled on Stripe-hosted pages, and any Stripe cookies are set on Stripe’s own domain, outside the scope of this policy.
6. Your choices
Delete or block in your browser. You can delete or block cookies and clear browser storage at any time in your browser settings. If you block the strictly necessary better-auth.session_token cookie (production: __Secure-…), you will not be able to stay signed in to the dashboard. Clearing the preference storage simply resets your theme, sidebar, language, sign-in-method, and “What’s new” defaults; nothing else is affected.
Managing and withdrawing consent. On autopage.dev, the optimization storage in Section 5 is set only if you accept it in our cookie banner. You can change your choice at any time: select “Cookie settings” in the site footer to reopen the banner. Declining withdraws your consent as easily as you gave it: it deletes the ap_session cookie, clears ap_traffic_source, and no further optimization storage is set. If the classification of theme or last_used_login_method is ever reclassified as consent-requiring (see the classification in Section 4), we will add an equivalent control on app.autopage.dev and update this policy accordingly.
7. Changes and contact
We may update this policy when our storage practices change or when the law requires it. Each version carries an effective date at the top of this document. Where a change introduces new non-essential storage, we will act as described in Section 5.
For questions about this policy or about the storage we use, contact us at support@autopage.dev. You can also read our Privacy Policy for the full account of how we process personal data.