Devoku Cookie and Local Storage Notice
Effective: 18 September 2026
This Notice supplements the Privacy Policy and covers cookies, browser storage, mobile/desktop device storage, and similar technologies used by Devoku.
Necessary storage
Devoku uses storage needed to authenticate, secure, route, encrypt, and operate the app. Depending on deployment and feature, this includes:
| Storage | Examples | Purpose | Typical duration |
|---|---|---|---|
| Identity/session cookie | Ory Kratos session cookie | Sign-in and account security | Session or configured authentication lifetime |
| Local storage | access/refresh token, user ID, email, display name, avatar, profile color, device ID/name, account scope | Maintain identity and app state | Until sign-out, replacement, deletion, or site-data clearing |
| Local cryptographic state | identity key, secret key, path key | Encryption, identity, and authorized routing | Until sign-out, replacement, deletion, or site-data clearing |
| Session storage | account-home URL/token, home refresh token, runtime origin | Route account/runtime requests for the current tab/session | Browser-tab session |
| Routing/team state | active team and customer-cloud/Coded-managed plane URLs | Select organization and deployment | Until changed or cleared |
| Feature state | preferences, onboarding, pending checkout, diagnostics and upload state | Complete requested flows and restore UI state | Feature-dependent |
| Native secure/app storage | session, push, bridge, and device values used by iOS, Android, or desktop wrappers | Authentication, notifications, and native features | Until sign-out, app-data clearing, or uninstall, subject to OS behavior |
Some tokens and cryptographic keys are sensitive. Use a locked device and separate OS/browser profile, and clear app/site data before transferring a device. Blocking necessary storage can prevent sign-in or core operation.
Optional analytics and advertising
The source code reviewed for this notice did not include a conventional third-party advertising SDK or cross-context advertising feature. Operational, security, upload, health, provider, and agent-runtime telemetry still exists and is not the same as “no telemetry.”
An analytics consent category exists, but the current product does not consistently expose or enforce it. Coded must not deploy non-essential analytics storage until prior consent is obtained where required, withdrawal is honored, and this inventory names the vendor, purpose, and duration.
Devoku does not use device storage for cross-context behavioral advertising. If that changes, Coded will update this Notice and provide any legally required consent or opt-out before use.
Managing storage
Browser or operating-system controls let you inspect or clear cookies and app data. Signing out should remove account credentials controlled by Devoku, but you should clear site/app data on a shared device. Clearing storage can remove unsynchronized state or require account recovery.
Contact privacy@devoku.com with questions.