Legal

Cookie Policy

Three cookies, all needed to sign you in, and a handful of preferences kept in your own browser. Analytics — Google Tag Manager, and Analytics 4 through it — is off until you switch it on, and Cookie settings at the bottom of any page takes it back.

Last updated

1The short version

This site can measure how it is used, and asks before it does. Nothing measures you in the dashboard or on the documentation sites we host for our customers, and there is no advertising pixel and no third-party chat widget on any of them.

Here, allowing analytics loads Google Tag Manager, and through it Google Analytics 4. Refuse and neither is on the page at all — not in a reduced mode, not waiting for a signal; the request is never made. Refusing takes the same single click as accepting, and switching the category off afterwards deletes what it set. The necessary cookies and the browser storage listed below sit outside that choice entirely: each is either required to sign you in or a preference held in your own browser, and neither needs your permission under the ePrivacy Directive or the UK PECR.

2Cookies we set

Three, all strictly necessary. Each is HTTP-only, signed, and scoped to the narrowest path that works.

Cookies set by Octri
NameWhereWhat it doesLifetime
access_tokenDashboardKeeps you signed in. HTTP-only and signed, so page scripts cannot read it and a tampered value is rejected.Session
refresh_tokenDashboardIssues a new access token when yours expires, without making you sign in again. Scoped to the refresh endpoint alone.Up to 30 days
docs_access_tokenPassword or SSO protected documentation sitesRemembers that you unlocked a gated documentation site, so you are not asked on every page.Session

Blocking these means you cannot sign in to the dashboard, and gated documentation sites will ask you to unlock on every page.

Two more are set only if you allow analytics, by the Google Analytics 4 tag that Tag Manager loads. Both carry a random identifier and nothing that names you.

Cookies set only after you allow analytics
NameWhereWhat it doesLifetime
_gaThis site, if you allow analyticsTells one browser apart from another, so a second visit is not counted as a new person. A random identifier, not linked to a name or an email address.2 years, or until you switch analytics off
_ga_<id>This site, if you allow analyticsHolds the state of the current visit — when it began, and whether it is still the same one — for the one Analytics property this site reports to.2 years, or until you switch analytics off

3Browser storage

Some preferences are kept in your browser’s local or session storage rather than in a cookie. Storage is not sent with every request the way a cookie is, so these values stay on your machine unless a feature explicitly needs them.

Local and session storage keys
NameWhereWhat it doesLifetime
octri:cookie-consentThis siteYour answer to the cookie banner, with the date you gave it, so we can honour it and know when to ask again.6 months, then we ask again
docs_visitor_idDocumentation sitesA random identifier that holds an Ask-the-docs conversation together across messages. Not linked to a name or an email address.Until you clear site data
docs:sidebar-widthDocumentation sitesRemembers how wide you dragged the sidebar.Until you clear site data
nav-tree-collapsedDocumentation sitesRemembers which navigation sections you collapsed.Until you clear site data
docs-playground-left, docs-playground-midAPI playgroundRemembers your panel layout in the request builder.Until you clear site data
Feedback and banner markersDocumentation sitesRecords that you already voted on a page, or dismissed a status banner, so you are not asked twice in the same visit.Until you close the tab

The only one of these that reaches our servers is the Ask-the-docs visitor id, and only when you send a chat message. It lets a conversation keep its thread. Chat sessions are deleted after 7 days, as described in the Privacy Policy.

4What you get to choose

The banner covers three groups. Only two of them are yours to decide, because the third is what makes the site work at all.

  • Necessary. Signing you in, keeping that session safe, and remembering how you left a page. Always on, and listed in full in the two tables above.
  • Analytics. Which pages get read and how people found them, so we know what to write next. Google Analytics 4, loaded through Google Tag Manager. Off until you turn it on.
  • Marketing. Whether a campaign or an ad is what brought you here. Off until you turn it on.

A choice stands for six months, after which we ask again. Change it whenever you like from Cookie settings at the bottom of any page: switching a category off deletes the cookies it had set. If your browser sends a Global Privacy Control signal we read that as a refusal and do not ask, unless you overrule it yourself from that same panel.

5Third parties

Three places a third party’s cookie can appear. The first is on this site and needs your permission; the other two happen only when you go to them:

  • Google, through Tag Manager and Analytics 4, if you allow the analytics category. The two cookies that sets are in the table above, and what Google may do with them is governed by its own policy. Your choice is passed on with Consent Mode, so a refusal reaches the tag itself rather than stopping at our door.
  • Paddle, our merchant of record, during checkout and in the billing portal. Their cookies are governed by their own policy.
  • Google or GitHub, if you choose to sign in with one of them. That happens on their domain, under their policy.

Nothing else. The full list of vendors that process any data for us is on the subprocessors page.

6How to control them

Every browser lets you view, block and delete cookies and site data, usually under privacy settings. Clearing site data for an Octri domain signs you out and resets the preferences above.

Site data aside, the categories above are the faster route: Cookie settings at the bottom of any page reopens the banner, and a category switched off there is gone without touching your browser at all.

If you host documentation on Octri and add your own scripts through custom code, those scripts are yours. Any cookies they set are your responsibility to disclose to your readers.

7Contact

Questions about this policy: support@octri.dev. We update this page whenever we add or remove anything listed on it.