Cookies
Cookie policy
How we use cookies, local storage, and tracking technologies.
Last updated: June 7, 2026 | Effective February 19, 2026
We use browser storage (localStorage and sessionStorage) only for secure login, session management, and core functionality. We do not use advertising cookies or cross-site tracking. Because all storage entries listed below are strictly necessary for the platform to function, no cookie consent banner is required under the EU ePrivacy Directive. We use cookie-free analytics (Cloudflare Web Analytics) that does not place any cookies on your device.
Strictly Necessary Storage
All storage entries we use are required for login, security, or core product functionality. None are used for advertising, profiling, or cross-site tracking. These cannot be disabled without breaking the platform.
| Key name | Type | Purpose | Expiry |
|---|---|---|---|
| sb-nautillo-session | localStorage | Stores your authentication session (JWT access token and refresh token) so you stay logged in across page loads.First-party (Supabase, EU-hosted) | Until sign-out or token expiry (~1 hour access / ~7 days refresh) |
| password_reset_mode | localStorage + sessionStorage | Temporary flag set during password reset to prevent storing a new session before the reset is complete. Cleared after reset.First-party | Session / cleared immediately after reset |
| subscription_info_cache_{userId} | localStorage | Caches your current subscription plan to avoid repeated database lookups on every page load. Contains plan type and seat count only — no personal data.First-party | 5 minutes (auto-expires) or until sign-out |
| np_motion_profile | localStorage | Stores your UI animation preference (off / subtle / standard / expressive) so the setting persists across sessions. Contains no personal data.First-party | Persistent (until you clear browser storage or change the setting) |
| np_surface_profile | localStorage | Stores your UI surface appearance preference (glass / crisp). Contains no personal data.First-party | Persistent (until you clear browser storage or change the setting) |
| pendingInvite | sessionStorage | Temporarily holds a team invitation ID during the sign-up or login flow so you are added to the right team after authentication.First-party | Browser session (cleared on tab close or after join) |
| nautillo-pro:prefill-domain | sessionStorage | Carries a domain value from the dashboard to the scan interface when you click 'Scan this domain'. Cleared after use.First-party | Browser session |
| np_cookie_notice_dismissed | localStorage | Records that you have dismissed the cookie notice so it is not shown again.First-party | Persistent (until you clear browser storage) |
Analytics — No Cookies
We use Cloudflare Web Analytics to understand website usage. It operates in cookie-free mode — no cookies are placed on your device. Cloudflare collects aggregated, anonymised page view data including the referring URL, page visited, browser type, operating system, and country derived from IP address. IP addresses are not stored by Cloudflare beyond the instant of processing.
Cloudflare is listed as a sub-processor in our Data Processing Addendum. International transfers to Cloudflare are governed by Standard Contractual Clauses (SCCs).
We do not use advertising pixels, cross-site tracking cookies, or share simulation data, targets, payloads, or results with any analytics or advertising platform.
What We Do Not Do
We do not use advertising or retargeting cookies.
We do not sell, share, or rent personal data to third parties for marketing purposes.
We do not use cross-site tracking technologies.
We do not build user profiles for advertising.
Any internal usage telemetry is limited to aggregated product events and excludes all customer content (scan targets, payloads, results).
Controlling storage from your browser
Because all storage listed above is strictly necessary for the platform to function, there is no opt-out toggle — disabling it would break login and core features. You can inspect or delete any localStorage or sessionStorage entry at any time using your browser's developer tools (Application → Local Storage / Session Storage). Clearing browser storage will sign you out and reset your UI preferences. Signing out via the platform removes all auth tokens automatically.
Data controller
The data controller for the processing described in this policy is NØRTH HŪMAN OÜ, operating Nautillo Pro at nautillo.pro. For all data protection enquiries, including GDPR Article 15–22 data subject rights (access, rectification, erasure, portability, restriction, objection), email support@nautillo.pro with subject "Privacy Request". We respond within 30 days in accordance with GDPR Article 12.
Questions about cookies?
Email support@nautillo.pro with subject "Privacy Request". For GDPR data subject requests (access, deletion, portability), we respond within 30 days in accordance with GDPR Article 12. Our full privacy commitments are described in the Privacy Policy and Data Processing Addendum.