COOKIES

Analytics runs only after you consent

Google Analytics and its cookies do not load before consent. Kostira stores only the analytics choice needed to apply the preference across kostira.com and app.kostira.com.

Open beta · no card · the app interface is in English

Status of this page

This is a starter information page for the open beta and should receive legal review before wider commercial operation. Questions can be sent to [email protected].

The preference cookie

After a visitor responds to the banner, Kostira stores kostira_analytics_consent with the value granted or denied. Its sole purpose is to remember the choice for one year. On Kostira’s production hosts it uses Domain=.kostira.com, Path=/, SameSite=Lax and Secure, allowing the same preference to be read on kostira.com and app.kostira.com.

Browser-storage inventory

NameMechanism and durationWhen it is createdPurpose
kostira_analytics_consentcookie, up to 365 daysafter selecting “Allow analytics” or “Decline”remember and synchronize the analytics preference across Kostira subdomains
kostira_attribution_sourcecookie, up to 90 daysonly after consent and when utm_source has an allowed valueretain the original source, such as chatgpt.com, without storing the full URL; deleted when consent is withdrawn
kostira.analytics.consent-synclocalStorage, until site data is clearedafter a consent changenotify other tabs on the same origin; the technical value is not sent to GA
kostira.analytics.once.*localStorage, until site data is clearedafter an activation event is sent in the applicationprevent duplicate sends of the same event; the key uses a browser-local hash of the user ID and is not sent to GA
sb-*-auth-tokenlocalStorage, until sign-out, session expiry or site-data removalafter signing in to the applicationmaintain the Supabase session on app.kostira.com; this storage is origin-bound and is not shared with the marketing site

In production, both Kostira cookies use Domain=.kostira.com, Path=/, SameSite=Lax and Secure. Local development omits the shared-domain attribute and, without HTTPS, Secure.

Google Analytics

GA4 may load only after the visitor selects “Allow analytics” and only when the operator has configured a valid measurement ID. Google can then set analytics cookies, including cookies in the _ga family; exact names and durations depend on the configured stream. Before production launch, the operator must inspect the cookies actually set in a browser and update this inventory.

Kostira intends to measure a limited funnel from a site visit to initial product use. Analytics should not receive email addresses, company names, CAD filenames, quote identifiers, quote values or CAD data.

Changing the choice

Use “Analytics preferences” in the site footer. Withdrawing consent prevents future measurement and starts removal of recognized GA cookies to the extent handled by the site. Browser settings can also remove stored cookies.

Withdrawing consent deletes the attribution cookie and recognized GA cookies accessible to the page. It does not remove the denied preference or storage required for sign-in. The complete inventory must be checked again in the production environment and approved during legal review.

Read the privacy notice for the broader categories of data.