Privacy and data
Cookie and Local Storage Policy
Every cookie and browser storage key WeGrowNepal sets, what each one is for, how long it lasts, and how to remove them.
- Version
- v1.0
- Effective
- Contents
- 9 sections · 51 clauses
- Document ref.
- WGN-LEGAL-COOKIES-V1.0
The PDF is a watermarked controlled copy. If it differs from this page, this page governs.
At a glance
A plain-language summary. The numbered clauses below are what legally applies.
- No advertising cookies. No tracking networks. No cross-site profiling.
- You can read the whole library without any cookie being set for you personally.
- Signing in sets a session token, because that is what signing in means.
- A few preference keys remember your theme and your last filter.
- Clearing site data removes all of it, and the Service still works.
1. What this covers
- 1.1
This policy covers cookies, local storage, session storage and any similar technology used on the Service.
- 1.2
A cookie is a small file a site asks your browser to store and send back on later requests.
- 1.3
Local storage is a browser facility that holds data on your device and is not sent to us automatically.
Why this is here
The distinction matters: a preference in local storage never leaves your device, whereas a cookie is transmitted with every request to the domain that set it.
- 1.4
This policy forms part of the Privacy Policy.
- 1.5
It applies to the website. The mobile applications store equivalent preferences on the device.
2. What we do not do
- 2.1
We do not set advertising cookies.
- 2.2
We do not operate or embed any advertising network.
- 2.3
We do not use cross-site tracking pixels or conversion tags.
- 2.4
We do not sell or share cookie data with any third party for their own purposes.
- 2.5
We do not fingerprint your device to identify you across sites.
- 2.6
We do not require you to accept anything before reading, because we set nothing that would require consent.
Why this is here
This is also why there is no cookie banner. A banner that asks permission for cookies we do not set would be theatre.
3. Strictly necessary
- 3.1
A session token is set when you sign in, so that the Service knows which account is making a request. Removing it signs you out.
- 3.2
A refresh token is set when you sign in, so that your session can continue without asking for your password repeatedly.
- 3.3
A cross-site request forgery token is set on forms, so that a third-party site cannot submit a form as you.
- 3.4
These are set only once you sign in, and are removed when you sign out.
- 3.5
These cannot be disabled while remaining signed in, because they are what being signed in consists of.
- 3.6
Their lifetime is described in the Privacy Policy and in the session management of the Service.
4. Preferences
- 4.1
A theme key records whether you chose light or dark, so the page does not flash the wrong one on load.
- 4.2
A saved-notes key records what you saved locally, so it survives a reload.
- 4.3
An upload draft key records a partially completed upload form, so a dropped connection does not lose your typing.
- 4.4
A recent-taxonomy key records the category and subject you last used, to save you reselecting them.
- 4.5
These are stored in your browser's local storage and are not transmitted to us.
- 4.6
They contain no identifier that would let us recognise you across sites.
- 4.7
Clearing them loses the convenience and nothing else.
5. Measurement
- 5.1
We measure aggregate usage — page views, load times, error rates — through our hosting provider's built-in analytics.
- 5.2
That measurement is performed on server request logs and does not require a cookie on your device.
- 5.3
It does not identify you and does not follow you to any other site.
- 5.4
We do not use Google Analytics, Meta Pixel or any equivalent third-party analytics product on the Service.
- 5.5
Aggregate measurement tells us which subjects have gaps, which is the only product decision it informs.
6. Third-party content
- 6.1
Fonts are served from a third-party font host and that request reveals your IP address to that host.
- 6.2
Uploaded files are served from object storage and from a content delivery network, which likewise sees the request.
- 6.3
Those providers are listed in the Sub-processors document.
- 6.4
We do not embed social media widgets, comment platforms or chat widgets that would set third-party cookies.
- 6.5
If you follow a link away from the Service, the destination site's own policy applies and we have no control over it.
7. Your control
- 7.1
Every browser allows you to view, block and delete cookies and site data. The relevant setting is ordinarily under Privacy.
- 7.2
Clearing site data for this domain removes everything described in this policy.
- 7.3
The Service continues to work with cookies blocked, except that you will not be able to remain signed in.
- 7.4
Reading and downloading work entirely without cookies.
- 7.5
Private or incognito browsing discards everything at the end of the session.
- 7.6
A browser "do not track" signal is respected in the sense that we do not track in the first place.
8. The mobile applications
- 8.1
The mobile applications do not use cookies. They store the equivalent values in the operating system's own secure storage.
- 8.2
An authentication token is stored so that you are not asked to sign in every time you open the app.
- 8.3
A device push token is stored so that a notification can be delivered to your device.
- 8.4
Downloaded notes are stored on the device so that they remain readable offline.
- 8.5
A theme preference and your last-used filters are stored on the device.
- 8.6
Clearing the app's storage, or uninstalling it, removes all of this from the device.
- 8.7
The Secret Pocket keeps your own private files in encrypted device storage and never transmits them to us.
9. Changes and questions
- 9.1
If we introduce a technology requiring consent, we will ask for it before setting anything, and we will update this policy first.
- 9.2
Additions to this policy are recorded in the version history.
- 9.3
Questions about this policy should be sent to legal@lacspace.com.
- 9.4
This policy should be read with the Privacy Policy and the Sub-processors document.
Version history
Every change to this document is recorded here, so amendments can be inspected rather than taken on trust.
v1.0 ·
- Initial publication.
- Listed every storage key by name and purpose rather than describing categories generically.
- Explained why no cookie banner is shown.