PANOpeak uses one cookie, and it exists only to keep you signed in. We run no advertising cookies, no tracking pixels, no social-media embeds and no cross-site profiling, and our analytics do not use cookies at all. That is why you are not being asked to click a consent banner: there is nothing here that requires your consent.
1. The cookie we set
| Name | Where | Purpose | Lifetime |
|---|---|---|---|
pano_refresh |
app.panopeak.app | Keeps you signed in to your workspace and lets your session be renewed without re-entering your password. | Deleted when you close the browser, or 30 days if you chose "remember me" |
It is set only after you log in, so it never exists for a visitor who is just reading the marketing site. It is HttpOnly, so page scripts cannot read it, and SameSite=Lax, so it is not sent along with requests started by other sites. It is strictly necessary: without it you would be signed out on every page load, so it is exempt from the consent requirement under Art. 5(3) of the ePrivacy Directive.
2. Browser storage that is not a cookie
The marketing site stores one value in your browser's localStorage, under the key pano_lang. It records the language you picked from the language switcher, so the site is in that language next time instead of resetting to English. It is written only when you actively choose a language, holds nothing but a two-letter code, is never sent to our servers, and is not used to identify you.
Light and dark mode are not stored at all: the site reads your operating system's appearance setting each time and follows it.
3. Analytics, without cookies
We measure traffic with Plausible Analytics, which we chose specifically because it sets no cookies and uses no persistent identifiers. It does not follow you across other websites, it does not build a profile of you, and it cannot tell us who you are. It reports aggregates: how many people viewed a page, which site referred them, which country the traffic came from. The data is processed in the EU and is not sold or shared for advertising. Because there is no identifier and no cross-site tracking, this processing needs neither a cookie nor your consent.
4. Anti-bot protection on the waitlist form
When it is switched on, the waitlist form is protected by Cloudflare Turnstile, which checks that a submission comes from a real browser rather than a bot. Turnstile is used here instead of a CAPTCHA because it does not make you solve puzzles and does not use cookies for advertising or cross-site tracking. It runs only on the page containing that form, and only as a security measure, which is the narrow purpose the ePrivacy consent exemption covers.
5. Why there is no cookie banner
Consent is required for storage that is not necessary to deliver the service you asked for, typically advertising, tracking and profiling cookies. We use none of those. Everything listed above is either strictly necessary, set only at your own request, or cookieless. Putting a consent dialog in front of you anyway would be asking permission for something that does not need it, and we would rather not train people to dismiss a box that changes nothing. If we ever add storage that genuinely requires consent, we will ask for it properly, before setting it, and update this page in the same change.
6. Controlling what is stored
Every browser lets you view and delete cookies and site data, and block them per site. Because we only use the one sign-in cookie, blocking or deleting it has a single visible effect: you are signed out of the app and will have to log in again. The marketing site works fully with cookies and local storage blocked; you will just be asked to pick your language again each visit.
7. Changes and contact
This page is updated whenever what we store changes, in the same change that alters it, not afterwards. Questions about anything here: email [email protected]. Our full Privacy Policy covers the personal data behind these entries, including the sub-processors involved.