Skip to content
autopageBeta
  • how it works
  • the loop
  • pricing
  • questions
  • start free

Operated by Finalform GmbH

EU company · GDPR

Cookie Policy

Last updated: 2026-06-25

This policy is published in English and in German. The German version is the binding version; the English text is a translation provided for convenience.

This Cookie and Storage Policy explains the cookies and browser storage that Finalform GmbH uses on its own websites, autopage.dev and app.autopage.dev. It supplements, and should be read together with, our Privacy Policy and our Impressum.

Controller. Finalform GmbH, Theodor-Heuss-Str. 106, 26129 Oldenburg, Germany, registered in the commercial register of the Amtsgericht Oldenburg under HRB 222780, USt-IdNr. DE457693089, Managing Director (Geschäftsführer) Robin Schröder, is the controller for the storage and processing described here.

Contents

    1. What this policy covers
    1. How German law applies
    1. Strictly necessary cookies (no consent required)
    1. Functional and preference storage
    1. Analytics and marketing
    1. Your choices
    1. Changes and contact

1. What this policy covers

This policy covers only the cookies and browser storage that we set on our own properties: the marketing site at autopage.dev and the dashboard at app.autopage.dev.

It does not cover pages that our customers connect to Autopage. When the Autopage snippet runs on a customer’s own landing page, it operates on that customer’s behalf and under that customer’s instructions. For that snippet storage the customer is the controller, and the disclosure of, and any consent for, that storage toward the visitors of those pages is the customer’s responsibility, as set out in our Terms of Service and our Data Processing Agreement. The two storage items the snippet sets on a customer page (a 30-day first-party cookie ap_session, a pseudonymous session identifier, and a session-storage key ap_traffic_source) are therefore out of scope here and are documented to the customer, not in this notice.

2. How German law applies

Two distinct legal layers govern cookies and equivalent browser storage in Germany, and we treat them separately:

  • Device layer (access and storage): Section 25 TDDDG. Section 25(1) TDDDG requires consent before information is stored on, or read from, a user’s device, unless the storage or access is strictly necessary to provide a service the user has expressly requested (the exemption in Section 25(2)). This layer applies regardless of whether the stored information is personal data.
  • Processing layer (use of the data): Art 6 GDPR. Once stored information is read and used, that processing needs a legal basis under Art 6(1) GDPR. Section 25 consent and the Art 6 basis are two separate requirements.

Web Storage technologies (localStorage and sessionStorage) carry the same Section 25 duty as cookies. We therefore disclose every browser-storage key below alongside the cookies, with the same level of detail: name, type, purpose, duration, Section 25 status, and Art 6 basis.

3. Strictly necessary cookies (no consent required)

This cookie is required to sign you in and keep your session secure. It is strictly necessary for a service you have expressly requested (signing in to the dashboard) and is therefore exempt from consent under Section 25(2) TDDDG.

Name Type Purpose Duration Section 25 status Art 6 basis
better-auth.session_token (prod: __Secure-…) Cookie (httpOnly) Keeps you signed in to the dashboard and keeps your session secure 7 days Essential, consent-exempt under Section 25(2) Art 6(1)(b) contract

We set no other strictly necessary cookies on our own sites: there is no separate CSRF, consent-store, load-balancer, or CDN cookie configured in our application.

4. Functional and preference storage

These cookies and storage keys remember choices you made so the interface behaves the way you set it. They are first-party, are set in response to your own actions, and are not used to track you or to build a profile.

Name Type Purpose Duration Section 25 status Art 6 basis
better-auth.last_used_login_method Cookie (not httpOnly) Pre-selects the sign-in method you used last 30 days Preference, consent question (see Section 6) Art 6(1)(f) legitimate interest, or consent if reclassified
theme Cookie Remembers your light or dark theme choice so pages render correctly on the server 1 year Preference, consent question (see Section 6) Art 6(1)(f) legitimate interest, or consent if reclassified
theme localStorage Mirrors your light or dark theme choice on the client Until you clear it Preference, consent question (see Section 6) Art 6(1)(f) legitimate interest, or consent if reclassified
sidebar_state Cookie Remembers whether the dashboard sidebar is expanded or collapsed 7 days Preference Art 6(1)(f) legitimate interest
NEXT_LOCALE Cookie Remembers your interface language for the duration of your browser session Session (no max-age) Preference Art 6(1)(f) legitimate interest
ap:updates-last-seen localStorage Stores the timestamp of when you last opened the “What’s new” drawer, to show the unread indicator Until you clear it Preference Art 6(1)(f) legitimate interest

The theme choice is held in two places: a cookie, so the correct theme can be rendered on the server on first load, and a mirrored localStorage key, so the choice persists on the client. Both are listed above so each storage item is disclosed in its own right.

5. Analytics and marketing

We currently use no analytics or marketing cookies on our own properties. There are no third-party trackers, advertising pixels, or analytics scripts on autopage.dev or app.autopage.dev, and there is no consent-management platform or cookie banner, because none is needed for the storage above. Our internal analytics interface is a no-op stub that stores nothing.

Stripe (our payment provider) sets no cookies on our domains: payment is handled on Stripe-hosted pages, and any Stripe cookies are set on Stripe’s own domain, outside the scope of this policy.

Third-country storage: none. All of the cookies and storage keys above are first-party storage on your own device. We use no third-party storage provider that places cookies or storage outside the EEA for our own sites.

If this ever changes, that is, if we introduce any new non-essential storage such as analytics or marketing technology, we will update this policy first and, where the law requires it, obtain your prior consent before that storage is set.

6. Your choices

Delete or block in your browser. You can delete or block cookies and clear browser storage at any time in your browser settings. If you block the strictly necessary better-auth.session_token cookie (production: __Secure-…), you will not be able to stay signed in to the dashboard. Clearing the preference storage simply resets your theme, sidebar, language, sign-in-method, and “What’s new” defaults; nothing else is affected.

Withdrawing consent. Today we set no storage that depends on your consent, so there is no consent to withdraw and no consent banner to manage. If the classification of theme or last_used_login_method is reclassified as consent-requiring (see the classification in Section 4), we will add a control on app.autopage.dev that lets you withdraw consent as easily as you gave it, and we will update this policy accordingly.

7. Changes and contact

We may update this policy when our storage practices change or when the law requires it. Each version carries an effective date at the top of this document. Where a change introduces new non-essential storage, we will act as described in Section 5.

For questions about this policy or about the storage we use, contact us at support@autopage.dev. You can also read our Privacy Policy for the full account of how we process personal data.

autopage

Built and operated by Finalform, a studio that makes tools that run without the founder.

© 2026 Autopage, operated by Finalform GmbH.Business customers only. All rights reserved.

EU company · GDPR

Site
How it worksPricingStart free
Legal
Terms of ServiceDatenschutzCookie PolicyImpressumAcceptable Use PolicySub-processorsData Processing AgreementTechnical and Organizational MeasuresData Retention PolicyDPIA Assist Template
www.autopage.dev