Last updated: 10 August 2026
Lyniti uses cookies and similar browser storage that are required for authentication, security, preferences, encryption, drafts, and core service operation.
Optional analytics, strictly masked session replay, Google Ads conversion measurement, and Meta Pixel remain controlled by your cookie choices.
The inventory below lists first-party cookies, localStorage, and sessionStorage currently written by Lyniti. The server stores OAuth provider refresh tokens in encrypted account records; Lyniti does not set a refresh_token browser cookie.
Required entries support a feature you request or protect the service. Preference entries remember settings you choose.
| Cookie or storage name | Provider | Purpose and data | Lifetime | Category |
|---|---|---|---|---|
| __Host-session / session (cookie) | Lyniti | Authenticates the user and carries a signed session identifier and security state. | 7 days | Essential |
| csrf_token (cookie) | Lyniti | Stores an anti-forgery token used to validate state-changing requests. | 7 days | Essential |
| oauth_state, oauth_signup, oauth_return_to, oauth_mode, oauth_source, oauth_button, oauth_provider, oauth_legal_acceptance (cookies) | Lyniti | Carries short-lived OAuth state, provider, flow, return path, analytics context, signup intent, and accepted legal-policy version. It contains no provider access token. | 10 minutes | Essential |
| __Host-oauth_desktop_request / oauth_desktop_request (cookie) | Lyniti | Links the browser OAuth callback to a one-time desktop authorization request. | 10 minutes | Essential |
| cookie_consent (localStorage) | Lyniti | Stores essential, preference, analytics, and marketing choices plus consent timestamp. | 180 days | Essential |
| theme (cookie + localStorage) | Lyniti | Remembers selected visual theme. | 1 year | Preference |
| preferred-locale (cookie); lyniti-locale (localStorage) | Lyniti | Remembers selected interface language. preferred-locale lasts 30 days; lyniti-locale remains until changed or cleared. | 30 days for cookie; until changed or cleared for localStorage | Preference |
| selectedWorkspace (cookie + localStorage) | Lyniti | Remembers selected workspace identifier and basic workspace selection data. | 1 year | Essential |
| encryptionKeys (localStorage) | Lyniti | Stores an encrypted local user key bundle needed for client-side encryption. | Until the app or user clears it | Essential |
| encryptionKeys_passphrase (localStorage) | Lyniti | Stores locally generated passphrase material used to unlock the encrypted local key bundle. | Until the app or user clears it | Essential |
| calendarWeekStart (localStorage) | Lyniti | Remembers selected first day of calendar week. | Until changed or cleared | Preference |
| notificationVolume (localStorage) | Lyniti | Remembers selected notification sound volume. | Until changed or cleared | Preference |
| lyniti.auth.navigation; lyniti.auth.oauth; pendingInviteCode (sessionStorage) | Lyniti | Temporarily preserves login, signup, OAuth, return-path, and invitation navigation intent. | Current browser tab/session | Essential |
| localeReloadCount; lyniti-locale-sync-reload:* (sessionStorage) | Lyniti | Prevents repeated locale synchronization reloads. | Current browser tab/session | Essential |
| sidepanelState, activeChatId, chatOverlayState, meetOverlayState, chatPullTabContactId, chatNavigationBehavior, pendingFileAttachment, ws_offline_queue, tracker and whiteboard preference keys | Lyniti | Preserves active panels, overlays, pending attachments, offline operations, and user-selected tracker or whiteboard display state. | Session or until changed/cleared, depending on key | Essential |
| lyniti_file_history_<workspaceId> (localStorage) | Lyniti | Stores up to 50 recent file identifiers and display metadata per workspace for local history. | Until the app or user clears it | Essential |
| chat_draft_<chatId>, chat_files_<chatId> (localStorage); lyniti:blog-edit-draft:<postId> (sessionStorage) | Lyniti | Preserves unsent chat text and file references locally; blog editing drafts remain for the current browser tab session. | Until sent/cleared; blog draft until tab session ends | Essential |
Umami analytics and session replay require Analytics consent. Google Ads and Meta Pixel storage require Marketing consent. Withdrawing consent stops Lyniti from loading those optional scripts again. Storage already set remains until its stated expiry or until you clear it in your browser.
Vendor scripts can be changed by their providers. The table names the cookies and lifetimes expected from Lyniti's present configuration. Browser privacy controls may shorten or block them.
| Cookie or storage name | Provider | Purpose and data | Lifetime | Category |
|---|---|---|---|---|
| lyniti.umami.cache:<websiteId> (sessionStorage) | Lyniti / Custom Analytics Solutions | Caches the first-party analytics session payload used for privacy-focused page, feature, performance, and event measurement. | Current browser tab/session | Analytics |
| _gcl_aw, _gcl_gs (first-party cookies) | Google Ads | Stores Google ad-click information so a completed paid-workspace conversion can be attributed and deduplicated. | 90 days | Marketing |
| _gcl_ls (localStorage) | Google Ads | Stores Google ad-click information so a completed paid-workspace conversion can be attributed and deduplicated. | 90 days | Marketing |
| _fbp, _fbc (first-party cookies) | Meta Pixel | Identifies a browser for consented Meta conversion measurement and advertising analytics. | 90 days | Marketing |
| fr (Meta third-party cookie where browser and Meta context permit) | Meta | Identifies a browser for consented Meta conversion measurement and advertising analytics. | 90 days | Marketing |
| lyniti:meta-pixel:event:* (sessionStorage) | Lyniti | Marks a conversion event identifier as sent in the current tab so it is not reported twice. | Current browser tab/session | Marketing |
After Analytics consent, Lyniti randomly samples 15% of sessions that begin on the public homepage. The recorder is available only to logged-out visitors and each recording stops after at most 3 minutes.
Replay uses strict masking: all page text and every input or form value are masked before replay events are transmitted. The resulting footage is content-censored and anonymized from Lyniti account and workspace data. It shows censored geometry of visible page blocks plus pointer position and movement, clicks, scrolling, navigation, and masked form-interaction events.
The recorder is not loaded on authenticated routes and therefore does not record workspace files, messages, financial data, account settings, or typed form content. Replays are stored for 30 days in Lyniti-controlled analytics infrastructure and then expire.
Google Ads loads only for Marketing consent and is configured for paid-workspace conversion measurement, restricted data processing, and no ad-personalization signals or remarketing. Google Conversion Linker uses _gcl_aw, _gcl_gs, and _gcl_ls for 90 days.
Meta Pixel loads only for Marketing consent. Lyniti reports a Subscribe event after successful paid-workspace creation and does not add email or account-profile fields to Pixel events. Meta documents _fbp, _fbc, and fr with a 90-day lifetime.
You can accept all optional categories, reject them, or change your choice through Cookie settings in the footer. Essential storage cannot be disabled through that control because requested service and security functions depend on it.
Before Marketing consent, Google consent mode remains denied. Google may receive limited, redacted cookieless consent or conversion pings without setting advertising cookies; Lyniti does not use those pings for ad personalization or remarketing.
You can also clear or block storage in browser settings. Doing so may sign you out, reset preferences, remove drafts or encryption-key material, and prevent requested features from working.
The table states browser-side lifetimes. Consent choices last 180 days. Strictly masked session replays last 30 days. Google and Meta advertising identifiers last 90 days unless browser or provider controls shorten them.
Server-side records, including versioned legal acceptance evidence and aggregated analytics, are not browser cookies and follow their applicable service, legal, security, or dispute-retention rules.
Category-specific server retention and deletion rules are in the Trust Center retention schedule .
For cookie or privacy questions, contact support@lyniti.com.