Last updated: 2026-09-02
Cookie Policy
How KarriereVault uses cookies and similar terminal storage.
Overview
This policy explains cookies and similar browser storage used by KarriereVault. It should be read together with the Privacy Notice, which explains the related processing of personal data.
Necessary storage
Necessary storage supports authentication, security, and settings that you explicitly request. Blocking these items can prevent parts of the service from working.
- Supabase authentication session
- cookie. Provider: Supabase. Purpose: Keeps an authenticated user signed in and supports secure session refresh. Duration: Session duration; refreshed while signed in. This item is configured as not requiring consent for terminal storage. Legal basis position: Strictly necessary to provide the authenticated service (§ 25 Abs. 2 Nr. 2 TDDDG; Art. 6(1)(b) GDPR).
- sidebar_state
- cookie. Provider: KarriereVault. Purpose: Remembers the signed-in workspace sidebar preference. Duration: 7 days This item is configured as not requiring consent for terminal storage. Legal basis position: Strictly necessary to remember a workspace UI preference within the service (§ 25 Abs. 2 Nr. 2 TDDDG; Art. 6(1)(b) GDPR).
- theme
- local storage. Provider: KarriereVault. Purpose: Remembers the selected light, dark, or system colour preference. Duration: Until changed or browser storage is cleared. This item is configured as not requiring consent for terminal storage. Legal basis position: Strictly necessary to remember display preferences within the service (§ 25 Abs. 2 Nr. 2 TDDDG; Art. 6(1)(b) GDPR).
- KarriereVault analytics consent preference
- local storage. Provider: KarriereVault. Purpose: Remembers the user's product-analytics consent decision. Duration: Until changed or browser storage is cleared. This item is configured as not requiring consent for terminal storage. Legal basis position: Necessary to record and respect the user's analytics choice (§ 25 Abs. 2 Nr. 2 TDDDG; Art. 6(1)(b) GDPR).
- KarriereVault analytics consent bridge
- cookie. Provider: KarriereVault. Purpose: Carries the user's analytics consent decision from the browser to the authenticated account and email/OAuth callback. Duration: Up to 12 months or until the consent decision changes. This item is configured as not requiring consent for terminal storage. Legal basis position: Necessary to record and respect the user's analytics choice (§ 25 Abs. 2 Nr. 2 TDDDG; Art. 6(1)(b) GDPR).
Analytics
Analytics entries are listed here together with their configured storage and legal-basis positions. Do not send personal information in page paths, query parameters, or analytics events.
- Vercel Web Analytics (public landing page)
- no client storage. Provider: Vercel. Purpose: Aggregate measurement of the public landing page, separate from consent-gated PostHog product analytics. Duration: According to Vercel Web Analytics documentation. This item is configured as not requiring consent for terminal storage. Legal basis position: Vercel documents cookieless, aggregated Web Analytics; verify the deployed data points, retention, regional legal posture, and applicable legal basis before relying on this classification.
- PostHog Cloud EU product analytics via Cloudflare managed reverse proxy
- local storage. Provider: PostHog Cloud EU via Cloudflare. Purpose: Consent-approved product analytics from PostHog Cloud EU using the allowlisted event contract and pseudonymous server-derived identity. Consented browser ingestion is routed through Cloudflare's managed reverse proxy before reaching PostHog. After consent, consented browser activity may be associated with the account when the user signs up or signs in. Activity before consent is not collected or backfilled. Withdrawal stops future PostHog capture and resets the active browser identity. Account deletion submits an asynchronous provider deletion request, so completion is not represented as immediate. Duration: The project reports a 12-month event-retention setting, but project-level retention enforcement is currently disabled. KarriereVault does not promise a fixed event deletion period; effective retention remains subject to the configured project plan and provider policy. Session recording is disabled. Consent is required before this item is activated. Legal basis position: Explicit consent under § 25 Abs. 1 TDDDG and Art. 6(1)(a) GDPR.
External media
External media can make a connection to the named provider and may allow that provider to use its own terminal storage. Entries marked as requiring consent must not be activated until the configured consent position is satisfied.
- YouTube privacy-enhanced embeds
- cookie. Provider: Google LLC / YouTube. Purpose: Displays a video that a user has chosen to embed in an editor. Duration: Until browser storage is cleared or consent is withdrawn. Consent is required before this item is activated. Legal basis position: Consent under § 25 Abs. 1 TDDDG and Art. 6(1)(a) GDPR before loading third-party media.
- X post embeds
- cookie. Provider: X Corp.. Purpose: Displays a public X post that a user has chosen to embed in an editor. Duration: Until browser storage is cleared or consent is withdrawn. Consent is required before this item is activated. Legal basis position: Consent under § 25 Abs. 1 TDDDG and Art. 6(1)(a) GDPR before loading third-party media.
Manage preferences
- Preference-management method
- Cookie preferences can be managed through the cookie settings link in the site footer when available.
- Withdrawal position
- You may withdraw consent at any time with future effect through the same cookie settings mechanism.