Devoku Legal Official document

Devoku Cookie and Local Storage Notice

Effective: 18 September 2026

This Notice supplements the Privacy Policy and covers cookies, browser storage, mobile/desktop device storage, and similar technologies used by Devoku.

Necessary storage

Devoku uses storage needed to authenticate, secure, route, encrypt, and operate the app. Depending on deployment and feature, this includes:

Storage Examples Purpose Typical duration
Identity/session cookie Ory Kratos session cookie Sign-in and account security Session or configured authentication lifetime
Local storage access/refresh token, user ID, email, display name, avatar, profile color, device ID/name, account scope Maintain identity and app state Until sign-out, replacement, deletion, or site-data clearing
Local cryptographic state identity key, secret key, path key Encryption, identity, and authorized routing Until sign-out, replacement, deletion, or site-data clearing
Session storage account-home URL/token, home refresh token, runtime origin Route account/runtime requests for the current tab/session Browser-tab session
Routing/team state active team and customer-cloud/Coded-managed plane URLs Select organization and deployment Until changed or cleared
Feature state preferences, onboarding, pending checkout, diagnostics and upload state Complete requested flows and restore UI state Feature-dependent
Native secure/app storage session, push, bridge, and device values used by iOS, Android, or desktop wrappers Authentication, notifications, and native features Until sign-out, app-data clearing, or uninstall, subject to OS behavior

Some tokens and cryptographic keys are sensitive. Use a locked device and separate OS/browser profile, and clear app/site data before transferring a device. Blocking necessary storage can prevent sign-in or core operation.

Optional analytics and advertising

The source code reviewed for this notice did not include a conventional third-party advertising SDK or cross-context advertising feature. Operational, security, upload, health, provider, and agent-runtime telemetry still exists and is not the same as “no telemetry.”

An analytics consent category exists, but the current product does not consistently expose or enforce it. Coded must not deploy non-essential analytics storage until prior consent is obtained where required, withdrawal is honored, and this inventory names the vendor, purpose, and duration.

Devoku does not use device storage for cross-context behavioral advertising. If that changes, Coded will update this Notice and provide any legally required consent or opt-out before use.

Managing storage

Browser or operating-system controls let you inspect or clear cookies and app data. Signing out should remove account credentials controlled by Devoku, but you should clear site/app data on a shared device. Clearing storage can remove unsynchronized state or require account recovery.

Contact privacy@devoku.com with questions.