Cookie Notice
Effective 26 September 2026 · version 2026-09-26
1. We use only strictly necessary cookies
CertAscent (full mode, i.e. when you're signed in) sets a small number of cookies, and only ever cookies that are strictly necessary to provide the service you asked for — keeping you signed in and protecting your account from cross-site request forgery and sign-in hijacking. None of them are used for advertising, analytics, tracking, profiling or any purpose beyond making the account features work.
2. No cookie banner — and why
Under ePrivacy/GDPR guidance and similar regimes, cookies that are strictly necessary to provide a service the user explicitly requested (such as staying signed in) are exempt from the requirement to obtain prior consent. Because CertAscent sets no non-essential cookies — no analytics, no advertising, no third-party trackers — no consent banner is shown. If that ever changes (e.g. product analytics are added), this notice and a consent mechanism will be updated accordingly before any such cookie is set.
3. The cookies we set
| Cookie | Purpose | Duration | Category |
|---|---|---|---|
sid / __Host-sid | Keeps you signed in (session identifier) | Idle 7 days / absolute 30 days | Strictly necessary |
pl | Binds the two steps of the optional password-first sign-in flow to your browser | 2 minutes | Strictly necessary |
oauth / __Host-oauth | Binds a social sign-in (Google/Microsoft/Apple) attempt to your browser to prevent CSRF | ~10 minutes | Strictly necessary |
did / __Host-did | A random device identifier used only for account security: recognising your devices, the device limit and new-device sign-in notices (we store only a keyed hash of it) | 400 days | Strictly necessary (security) |
dlp | Lets you pick which device to sign out when you reach your plan's device limit (sent only to that one sign-in step) | 5 minutes | Strictly necessary |
sso / __Host-sso | Binds a single sign-on attempt with your organization's identity provider to your browser | ~10 minutes | Strictly necessary |
ref / __Host-ref | Remembers the referral link you followed so the discount applies at sign-up (only when the referral program is live and only if you followed a referral link) | 30 days | Strictly necessary (service you requested) |
All are first-party, HttpOnly (not readable by page scripts) and marked Secure whenever served over HTTPS. In local mode (no account) no cookies are set at all.
4. localStorage and sessionStorage (not cookies, but similar in effect)
Device-local storage keeps the app usable offline and fast. It is never sent to any server automatically (your synced workspace reaches our server only through your own account sync) and is described fully in the Privacy Notice.
| Key | Purpose | Duration |
|---|---|---|
infosecCertRoadmap.v1 (localStorage) | Your plan in local mode; with an account, a per-account cache of your synced workspace (also holds your theme, disclaimer acknowledgement and badge-media choice) | Until you clear it; the per-account cache is removed when you sign out or delete your account |
certascent.tour.v1 (localStorage) | Whether you finished the guided tour | Until you clear it |
certascent.locale.v1, certascent.displayCurrency.v1 (localStorage) | Your chosen interface language and display currency (only if you changed them) | Until you clear it |
authIntendedPlanShown, authAddSecurityPromptShown (sessionStorage) | Avoid showing the same sign-up prompt twice in one tab | Until the tab is closed |
5. Third-party content
Fonts, scripts and styles are all served from our own domain; no content delivery network, analytics or advertising service is contacted when you load the app. Third parties are contacted only when you use a feature that needs them: signing in with Google, Microsoft or Apple (their pages set their own cookies), checking out with our merchant of record Paddle (on Paddle's own page), or showing a badge image or Credly embed, which loads only when you click "Show" (or if you turn on automatic loading in Account → Privacy). Those services apply their own cookie and privacy practices.
6. Global Privacy Control
If your browser sends the Global Privacy Control signal we treat it as an opt-out of any non-essential processing: marketing e-mail stays off, and we record once that we received and honoured it. We don't sell or share personal information in any case.
See also the Privacy Notice and the Disclaimer & terms of use.