Cookie and local storage notice

This notice describes the cookies and browser storage Skilltage uses for consent, app operation, analytics, and diagnostics.

Consent model

Klaro manages optional browser analytics and diagnostics choices. These services are enabled by default and can be disabled individually or together at any time.

You can reopen privacy preferences from the footer or the privacy preferences button.

Known browser storage

  • Consent preferences: browser storage records optional analytics and diagnostics choices for up to 365 days.
  • Consent evidence: a pseudonymous consent subject identifier supports minimal consent-change records for up to 400 days.
  • Consent reliability: local browser storage may prevent duplicate consent logs and retry failed consent-event submissions until they are submitted or cleared.
  • Authenticated app session: Supabase-managed browser storage keeps signed-in app sessions active for organisation users.
  • Workspace preference: local browser storage may remember the user's selected organisation workspace.
  • UI preference: a cookie may remember app shell sidebar state where that component is active.
  • Support widget storage: Zoho Desk support widget storage may be set when organisation users open the support widget.

Optional telemetry services

  • PostHog analytics uses the EU host by default, masks text and element attributes, enables session recording only after analytics consent, and only identifies users after analytics consent.
  • Apollo website visitor analytics is enabled by default unless Apollo is declined and helps Skilltage understand which companies visit the public website and which pages they view.
  • Mautic website visitor analytics is enabled by default unless Mautic is declined and records anonymous visitor page activity on the public website. Mautic does not receive account email or organisation identity from the landing site.
  • Sentry browser diagnostics only starts after diagnostics consent. Default PII collection is off unless an approved environment setting enables it.
  • Sentry server-side diagnostics may run for service operation and reliability, with default PII collection off unless explicitly approved.

Consent evidence

The backend stores minimal Klaro consent change evidence: a pseudonymous consent subject, optional authenticated user id, event type, changed service, boolean consent snapshot, config version, and timestamps.

Consent evidence does not store raw IP addresses, full user agents, page-by-page tracking, or banner impressions. It is retained for 13 months.