Privacy PolicyTerms of ServiceCookie Policy

© 2026 Lyniti. All rights reserved.

Cookie Policy

Last updated: 10 August 2026

1. Overview

Lyniti uses cookies and similar browser storage that are required for authentication, security, preferences, encryption, drafts, and core service operation.

Optional analytics, strictly masked session replay, Google Ads conversion measurement, and Meta Pixel remain controlled by your cookie choices.

2. Essential and Preference Storage

The inventory below lists first-party cookies, localStorage, and sessionStorage currently written by Lyniti. The server stores OAuth provider refresh tokens in encrypted account records; Lyniti does not set a refresh_token browser cookie.

Required entries support a feature you request or protect the service. Preference entries remember settings you choose.

Current first-party inventory

Cookie or storage nameProviderPurpose and dataLifetimeCategory
__Host-session / session (cookie)LynitiAuthenticates the user and carries a signed session identifier and security state.7 daysEssential
csrf_token (cookie)LynitiStores an anti-forgery token used to validate state-changing requests.7 daysEssential
oauth_state, oauth_signup, oauth_return_to, oauth_mode, oauth_source, oauth_button, oauth_provider, oauth_legal_acceptance (cookies)LynitiCarries short-lived OAuth state, provider, flow, return path, analytics context, signup intent, and accepted legal-policy version. It contains no provider access token.10 minutesEssential
__Host-oauth_desktop_request / oauth_desktop_request (cookie)LynitiLinks the browser OAuth callback to a one-time desktop authorization request.10 minutesEssential
cookie_consent (localStorage)LynitiStores essential, preference, analytics, and marketing choices plus consent timestamp.180 daysEssential
theme (cookie + localStorage)LynitiRemembers selected visual theme.1 yearPreference
preferred-locale (cookie); lyniti-locale (localStorage)LynitiRemembers selected interface language. preferred-locale lasts 30 days; lyniti-locale remains until changed or cleared.30 days for cookie; until changed or cleared for localStoragePreference
selectedWorkspace (cookie + localStorage)LynitiRemembers selected workspace identifier and basic workspace selection data.1 yearEssential
encryptionKeys (localStorage)LynitiStores an encrypted local user key bundle needed for client-side encryption.Until the app or user clears itEssential
encryptionKeys_passphrase (localStorage)LynitiStores locally generated passphrase material used to unlock the encrypted local key bundle.Until the app or user clears itEssential
calendarWeekStart (localStorage)LynitiRemembers selected first day of calendar week.Until changed or clearedPreference
notificationVolume (localStorage)LynitiRemembers selected notification sound volume.Until changed or clearedPreference
lyniti.auth.navigation; lyniti.auth.oauth; pendingInviteCode (sessionStorage)LynitiTemporarily preserves login, signup, OAuth, return-path, and invitation navigation intent.Current browser tab/sessionEssential
localeReloadCount; lyniti-locale-sync-reload:* (sessionStorage)LynitiPrevents repeated locale synchronization reloads.Current browser tab/sessionEssential
sidepanelState, activeChatId, chatOverlayState, meetOverlayState, chatPullTabContactId, chatNavigationBehavior, pendingFileAttachment, ws_offline_queue, tracker and whiteboard preference keysLynitiPreserves active panels, overlays, pending attachments, offline operations, and user-selected tracker or whiteboard display state.Session or until changed/cleared, depending on keyEssential
lyniti_file_history_<workspaceId> (localStorage)LynitiStores up to 50 recent file identifiers and display metadata per workspace for local history.Until the app or user clears itEssential
chat_draft_<chatId>, chat_files_<chatId> (localStorage); lyniti:blog-edit-draft:<postId> (sessionStorage)LynitiPreserves unsent chat text and file references locally; blog editing drafts remain for the current browser tab session.Until sent/cleared; blog draft until tab session endsEssential

3. Optional Analytics and Advertising Storage

Umami analytics and session replay require Analytics consent. Google Ads and Meta Pixel storage require Marketing consent. Withdrawing consent stops Lyniti from loading those optional scripts again. Storage already set remains until its stated expiry or until you clear it in your browser.

Vendor scripts can be changed by their providers. The table names the cookies and lifetimes expected from Lyniti's present configuration. Browser privacy controls may shorten or block them.

Current optional inventory

Cookie or storage nameProviderPurpose and dataLifetimeCategory
lyniti.umami.cache:<websiteId> (sessionStorage)Lyniti / Custom Analytics SolutionsCaches the first-party analytics session payload used for privacy-focused page, feature, performance, and event measurement.Current browser tab/sessionAnalytics
_gcl_aw, _gcl_gs (first-party cookies)Google AdsStores Google ad-click information so a completed paid-workspace conversion can be attributed and deduplicated.90 daysMarketing
_gcl_ls (localStorage)Google AdsStores Google ad-click information so a completed paid-workspace conversion can be attributed and deduplicated.90 daysMarketing
_fbp, _fbc (first-party cookies)Meta PixelIdentifies a browser for consented Meta conversion measurement and advertising analytics.90 daysMarketing
fr (Meta third-party cookie where browser and Meta context permit)MetaIdentifies a browser for consented Meta conversion measurement and advertising analytics.90 daysMarketing
lyniti:meta-pixel:event:* (sessionStorage)LynitiMarks a conversion event identifier as sent in the current tab so it is not reported twice.Current browser tab/sessionMarketing

4. Session Replay

After Analytics consent, Lyniti randomly samples 15% of sessions that begin on the public homepage. The recorder is available only to logged-out visitors and each recording stops after at most 3 minutes.

Replay uses strict masking: all page text and every input or form value are masked before replay events are transmitted. The resulting footage is content-censored and anonymized from Lyniti account and workspace data. It shows censored geometry of visible page blocks plus pointer position and movement, clicks, scrolling, navigation, and masked form-interaction events.

The recorder is not loaded on authenticated routes and therefore does not record workspace files, messages, financial data, account settings, or typed form content. Replays are stored for 30 days in Lyniti-controlled analytics infrastructure and then expire.

5. Google and Meta Details

Google Ads loads only for Marketing consent and is configured for paid-workspace conversion measurement, restricted data processing, and no ad-personalization signals or remarketing. Google Conversion Linker uses _gcl_aw, _gcl_gs, and _gcl_ls for 90 days.

Meta Pixel loads only for Marketing consent. Lyniti reports a Subscribe event after successful paid-workspace creation and does not add email or account-profile fields to Pixel events. Meta documents _fbp, _fbc, and fr with a 90-day lifetime.

  • Google Conversion Linker documentation
  • Meta Cookies Policy

6. Your Controls

You can accept all optional categories, reject them, or change your choice through Cookie settings in the footer. Essential storage cannot be disabled through that control because requested service and security functions depend on it.

Before Marketing consent, Google consent mode remains denied. Google may receive limited, redacted cookieless consent or conversion pings without setting advertising cookies; Lyniti does not use those pings for ad personalization or remarketing.

You can also clear or block storage in browser settings. Doing so may sign you out, reset preferences, remove drafts or encryption-key material, and prevent requested features from working.

7. Retention

The table states browser-side lifetimes. Consent choices last 180 days. Strictly masked session replays last 30 days. Google and Meta advertising identifiers last 90 days unless browser or provider controls shorten them.

Server-side records, including versioned legal acceptance evidence and aggregated analytics, are not browser cookies and follow their applicable service, legal, security, or dispute-retention rules.

Category-specific server retention and deletion rules are in the Trust Center retention schedule .

8. Contact

For cookie or privacy questions, contact support@lyniti.com.