Version 1.5
Effective 23 August 2026
Cookies & browser storage
Inventory of mechanisms used for sessions, security, preferences and optional measurement.
Portuguese is the controlling version. This English text is a faithful translation.
Audience measurement is optional and starts off. No analytics event is sent without an affirmative choice for the published purpose; advertising and behavioural marketing remain absent.
Necessary authentication cookie
When authentication is configured and a user signs in, Supabase may create one or more first-party cookies whose name starts with sb-gnextd-auth-token. The value can be split across technical cookie chunks.
- Purpose: maintain and refresh the authenticated session and enforce the private account boundary.
- Basis: strictly necessary for the account service requested by the user.
- Technical maximum lifetime: 400 days; the session is refreshed during use and cookies are removed or invalidated on sign-out or expiry.
- Current settings: path / and SameSite=Lax.
Cloudflare Zaraz privacy choice
When the Cloudflare Zaraz CMP is configured, the first-party cf_consent cookie remembers whether the optional purpose was accepted or rejected. It is necessary to honour the choice, is not itself an analytics cookie and does not authorise another purpose. If the CMP or published purpose identifier is unavailable, measurement fails closed and remains off.
Assistant improvement choice
The necessary first-party gnextd_assistant_choice cookie stores a random 256-bit token so a guest choice can be remembered and its data exported, withdrawn or erased. PostgreSQL receives only the token’s SHA-256 hash; the cookie contains no question, answer or analytics choice.
In production the cookie uses Secure, HttpOnly, SameSite=Lax, path / and a maximum technical lifetime of one year. A new consent-text version or hash invalidates the earlier choice and asks again. The choice is independent of the Zaraz CMP and does not change the answer or quota.
Optional audience measurement
Only after affirmative consent, the native Google Analytics 4 integration through Zaraz can create the first-party cookies _ga and _ga_* and technical Zaraz cookies whose names start with cfz_google-analytics_v4 or cfzs_google-analytics_v4. It receives only the manual allowlisted event for a public page, never a search, fragment, coordinates, property, account or private route. There are no automatic page-view events, GTM or cookieless consent mode.
Rejecting or withdrawing the purpose blocks new events and deletes measurement cookies accessible on this domain. Google Analytics 4 event retention is limited to two months; each cookie’s technical lifetime can vary with provider configuration.
Guest-session counter
The gnextd.land.guest-checks.v1 key stores only a number from 0 to 2 in sessionStorage to enforce the guest limit in the tab. It is not a cookie, is not sent to the server and ends with that tab session.
Theme preference
The gnextd-theme key is written to browser localStorage after the user selects light or dark mode. It is not a cookie, is not automatically sent with every request and remains until changed or cleared in the browser.
Content feedback
The “Helpful/Not helpful” choice creates no cookie or browser storage. The API immediately aggregates the answer by day, content, revision and language, without keeping an individual event or browser identifier in the feedback table.
Maps and external services
Loading a map or using place search can make technical requests to a configured supplier, including IP address, browser agent, map area and zoom level or search text. This is not GnextD first-party browser storage, but it is processing described in the privacy notice and source page.
No behavioural advertising
No advertising pixel, marketing cookie, behavioural personalisation, Google Signals or User-ID is integrated. The only planned measurement is the bounded optional purpose described above.
Browser controls
Users can clear cookies and local storage in browser settings. Blocking the authentication cookie prevents the session and private features from working, but public browsing and guest checks may remain available.
“Privacy / cookie settings” in the footer reopens the CMP; when measurement is active, the same control provides immediate withdrawal.
This inventory is version 1.5, effective 23 August 2026.