Cookie & Local Storage Policy
Effective date: 30 September 2026 · Operator: Danger Close Security Co, a for-profit business organized in New Jersey · Contact: support@certif.ly
This page is the complete inventory of everything Certifly stores in your browser. It was produced by auditing the actual code, and we keep it current when storage changes.
The short version: Certifly sets only essential cookies and preferences you choose yourself. There are no analytics cookies, no advertising trackers, and no third-party cookies of any kind. That is why you do not see a consent banner: EU/ePrivacy rules require consent only for storage that is not strictly necessary, and everything below is either strictly necessary to run the service or a setting you explicitly chose.
Cookies
Set by this service when you sign in or open an invitation. All are HttpOnly (invisible to page scripts), SameSite=Lax, and Secure over HTTPS. None are readable by, or sent to, any third party.
| Cookie | Purpose | Duration | Type |
|---|---|---|---|
hz_session |
Keeps you signed in | 7 days, or until you sign out | Strictly necessary |
hz_oauth_state |
Protects the sign-in round trip against forgery | 10 minutes | Strictly necessary |
hz_oauth_nonce |
Binds the sign-in response to this browser | 10 minutes | Strictly necessary |
hz_oauth_verifier |
One-time value securing the sign-in handshake (PKCE) | 10 minutes | Strictly necessary |
hz_invite |
Holds an invitation you opened, so it survives creating an account at the identity provider | 1 hour | Strictly necessary |
Signing in happens at our identity provider, Rocketbox ID (id.rocketbox.ai), which sets cookies of its own on its own domain. They are described in its cookie policy.
localStorage (persists in this browser until cleared)
| Key | Purpose | Duration | Type |
|---|---|---|---|
hz-theme |
Your light/dark theme choice | until you clear it | Preference (set by you) |
hz-rail-collapsed |
Whether you collapsed the navigation rail | until you clear it | Preference (set by you) |
hz-rules-sidebar-w |
The width you dragged the rules sidebar to | until you clear it | Preference (set by you) |
hz-features |
Preview features you switched on for yourself | until you clear it | Preference (set by you) |
hz-ai-banner-dismissed:* |
Remembers you dismissed the "AI features are off" notice, per organization | until you clear it | Preference (set by you) |
sessionStorage (this tab only; erased when the tab closes)
| Key | Purpose | Duration | Type |
|---|---|---|---|
hz-assistant-transcript |
Your conversation with the Assistant, so a page reload in this tab does not lose it | tab lifetime | Strictly necessary (functional) |
hz-help-transcript |
Your conversation with the docs help panel, for the same reason | tab lifetime | Strictly necessary (functional) |
hz-help-open |
Whether the help panel is open in this tab | tab lifetime | Preference (set by you) |
The two transcripts are the only entries that can contain text you wrote. They stay in this tab and are erased when you close it; they are not stored on our servers (see the Privacy Policy, section 11).
What we do not use
- No analytics cookies, SDKs, or telemetry in your browser (no Google Analytics, no product-analytics SDKs, no beacons).
- No advertising or cross-site tracking cookies.
- No third-party scripts, fonts, or CDNs. Every asset is served from our own domain, and the Content-Security-Policy refuses anything else.
- No fingerprinting.
Managing storage
Everything above can be cleared with your browser's normal "clear site data" controls; the service will simply sign you out and forget your display preferences. Because we set nothing that requires consent, there is no consent toggle to manage. If we ever introduce non-essential storage (for example analytics), we will ask for opt-in consent first and update this inventory.
Questions or rights requests: support@certif.ly. See the Privacy Policy for your rights, and the Terms of Service.