TDDDG · Consent
Cookie and Storage Information
Legal documents last updated: 2026-08-31. Kasp does not use advertising cookies. Optional statistics are voluntary, overridden by DNT/GPC and counted only for signed-in users.
Consent text: version 2026-08-31 · Validity: 180 days
01 Technology
Storage technologies and legal classification
Cookies are small pieces of text information that a browser associates with a domain. Local Storage generally persists after a tab is closed; Session Storage is tied to the respective tab or browser session. Kasp currently mainly uses these two forms of web storage. The production frontend itself does not create advertising or statistics cookies.
Information that is not technically necessary is stored or read only with consent under section 25(1) TDDDG. Section 25(2) TDDDG applies to expressly requested functions. Necessity under that provision is not a blanket legal basis under data protection law; subsequent processing is additionally governed by the General Data Protection Regulation and the purposes stated in the Privacy Policy.
In the following inventory, 'necessary' means that an entry is written only for a function chosen by the user, for sign-in/security, or to reliably apply the privacy decision. A first page visit alone does not pre-write a language, appearance, career draft or analysis intent to the browser.
02 Inventory
Exact inventory of reachable browser storage
Names correspond to the current software version. 'Browser' as recipient means that the entry initially resides only in the local origin storage. A transfer to Kasp/Supabase occurs only if the specified function needs the value for a server request.
| Key and storage | Trigger and content/purpose | Category and recipients | Validity/expiry |
|---|---|---|---|
sb-gkbpozggufspxgpjshzw-auth-tokenLocal Storage | Only after Google sign-in; Supabase session including access/refresh tokens, expiry information, and authentication user and profile metadata returned by Google/Supabase; provider tokens may be included depending on the OAuth response. | Necessary for sign-in and protected functions; Kasp/Supabase. | Until sign-out, session revocation or deletion of website data; individual tokens expire and are refreshed during an active session. |
kasp:offline-preview-session-v1Local Storage | Only in the isolated, backend-free preview after 'Open preview'; marker 1, not a real account or production session. | Necessary only for the requested offline preview; browser, no external recipient. | Until preview sign-out or deletion of website data. |
kasp_site_access_v3Local Storage | After the access code for a controlled preview is correctly entered; checksum and timestamp. | Necessary for the requested access; browser. | Valid for 30 days; then ignored until overwritten or deleted in the browser. |
kasp_cookie_consent_v2Local Storage | Only after 'Reject all', 'Accept all' or 'Save selection'; exactly version, analytics and decidedAt. | Necessary browser consent record; browser. | Valid for 180 days. After that it is no longer accepted as a decision and a new choice is required; deleted/replaced when a new choice is made or by the browser. |
kasp_cookie_consentLocal Storage (legacy) | An older key no longer used as consent by the current client. | Necessary migration cleanup; browser. | Removed the next time a current choice is saved; otherwise by deleting website data. |
kasp_optional_analytics_denied_v1Local Storage and first-party cookie of the same name | After refusal or failure to save a choice: an independent block containing version, analytics: false and decision time. It prevents an old opt-in from becoming effective again when storage fails. | Necessary to enforce your privacy choice; browser and, for the cookie, the website's own host. No statistics, no third-party provider and no additional user identifier. | Cookie for no more than 180 days, Path=/, SameSite=Lax and Secure on HTTPS. Local Storage block until new consent is successfully saved or website data are deleted. If all storage methods are blocked, the block applies in the current document; failure to persist it is reported in the dialogue. |
plausible_ignoreLocal Storage (compatibility) | Set to true on express refusal and removed on consent; additional protection against older clients. | Necessary to enforce refusal; browser. No Plausible script is loaded and no Plausible request is triggered. | Until the choice changes or website data are deleted. |
kasp-localeLocal Storage | Only after an explicit language choice; de or en. | Necessary for the chosen presentation; browser. | No fixed period; until changed or website data are deleted. |
kasp-theme-preference, kasp-theme, kasp-v2-themeLocal Storage | After an explicit appearance choice or migration of a previous choice; preference and effective light/dark appearance. | Necessary for the chosen presentation; browser. | No fixed period; until changed or website data are deleted. |
kasp-app-1-desktop-sidebar-collapsed, kasp-panel-width-left-v1, kasp-panel-width-right-v1, kasp:first-value-guide:v1, kasp-app-1-cockpit-profile-v1Local Storage | After collapsing the sidebar, closing the hint, saving a cockpit profile or starting a cockpit analysis; UI state, dismissed hint and analysis profile including freely named subject, comparison targets, criteria, scenarios, priorities, depth and assistant. The actual analysis prompt is not part of this key. | Necessary to restore expressly used app functions; browser, profile sent to Kasp/Supabase when a requested analysis starts. | No fixed period; until changed, reset or website data are deleted. |
kasp:analysis-intent:<random-id>Session and Local Storage | After submitting a landing-page request or selecting an example; request/prompt up to 4,000 characters, role, depth, area, plan, source, random ID and creation time. | Necessary for the requested handoff to sign-in/app; initially browser, then Kasp/Supabase on continuation. | Valid for 15 minutes; removed after successful handoff. Expired entries are discarded on the next read/cleanup; the tab copy ends no later than the browser session. |
kasp_career_stateSession Storage | Only after editing the career flow; may contain job, industry, country, experience, skills, free text, concern, education, work mode, email, and result, analysis and sharing information. | Necessary, expressly created form/result state; browser. | Until the end of the tab/browser session or until overwritten/deleted. |
kasp_pending_checkout_v1Session and Local Storage | After choosing a paid plan before sign-in; plan, monthly/yearly and creation time. Does not initiate a purchase. | Necessary for the requested return to checkout; browser. | Valid for 30 minutes; then discarded or removed after completion/cancellation. |
kasp:app1-login-returnSession Storage and, except for capability paths, Local Storage | When sign-in starts from an allowed destination path; normalised return path and creation time. Private sharing and invitation capabilities remain in tab storage only. | Necessary for the requested OAuth return; browser. | Valid for 15 minutes; removed after sign-in or if the value is invalid/expired. |
kasp:support-receipts:v1Local Storage | After successful support submission; no more than 12 case references with category and receipt time, without message text or email address. | Necessary local receipt aid; browser. | Each entry is valid for 90 days; then no longer displayed and replaced at the next update, otherwise removed by deleting website data. |
kasp:app-v2:chat-replay-identities:v1Session Storage | When a chat is submitted; no more than 16 one-way checksums of the exact request, random request IDs and times. The prompt and request payload are not stored. | Necessary to prevent accidental duplicate processing; browser, request ID sent to Kasp/Supabase on continuation. | 30 minutes or until the request is completed/cancelled; no later than the end of the tab/browser session. |
kasp:artifact-share-reader:v2Session Storage | When an expressly requested artifact share is opened; random reader identifier to technically limit repeated access. It is neither the sharing capability nor a statistics identifier. | Necessary for protected access to the requested share; browser, Kasp/Supabase on retrieval. | Until the end of the tab/browser session or deletion of website data. |
kasp-chunk-recovery-atSession Storage | Only when an outdated application module can no longer be loaded after a new deployment; timestamp of the single automatic reload. Never runs with unsaved input, during a running analysis or while offline. | Necessary so the page refreshes itself at most once within five minutes after a deployment; browser, no external recipient. | Effective for five minutes; until the end of the tab/browser session or deletion of website data. |
kasp-admin:return-to, kasp_workforce_batch_idsSession Storage | After admin sign-in or expressly initiated role batch processing; safe return path or internal role IDs. | Necessary for the respective requested function; browser, role IDs sent to Kasp/Supabase during batch processing. | Until consumed/completed, overwritten or the end of the tab/browser session. |
kasp_primaryAnalysisId, kasp_openAnalysisId, kasp_analysisId, kasp_shareHashLocal Storage (existing flow) | When an analysis or result is selected/opened in the existing analysis flow; analysis IDs and, in the sharing flow, a secret sharing capability. | Necessary for the requested restoration of the existing flow; browser, Kasp/Supabase on retrieval. | No fixed period; until the analysis is changed/deleted, replaced by the product flow, or website data are deleted. On shared devices, delete website data after use. |
Optional statistics create no additional user identifier or dedicated statistics key in the browser. Browser extensions, browser manufacturers or operating system services may store their own data independently of Kasp; they are not part of this Kasp inventory.
03 Statistics
Optional, authenticated daily aggregates
Kasp does not load a script from an external statistics provider. Following valid consent, the Kasp client sends only predefined events to a Kasp-controlled Supabase Edge endpoint at https://gkbpozggufspxgpjshzw.supabase.co. Supabase is the technical recipient and infrastructure provider for Kasp; the Supabase Privacy Policy is the primary provider source.
An event is counted only if all of the following apply:
- the browser record, version 2026-08-31 contains
analytics: trueexplicitly and is no more than 180 days old, - neither Do Not Track (DNT) nor Global Privacy Control (GPC) is active,
- the event, normalised route template and optional dimensions are on a fixed, finite allowlist,
- a genuine, non-anonymous Supabase user session has been authenticated, and
- the account projection contains the same version, consent and exactly the same decision time.
Anonymous public events are not aggregated. Page and funnel counters are permitted only for a fixed list of public, non-sensitive route templates. Permitted events are page view, landing-page request, example selection, example CTA and help article view; their finite dimensions are area, depth, example and help article. Free text, search text, support messages, case references and email addresses are not transmitted.
Kasp may additionally measure the Core Web Vitals LCP, INP and CLS on a sample. Alongside public templates, only predefined, normalised app route templates are permitted for this purpose; specific analysis, chat, artifact or occupation IDs are replaced with placeholders. The transmitted data are the measured value, its deterministically derived rating ('good', 'needs-improvement', 'poor'), navigation type and whether this is the final measurement. Sign-in, admin, private sharing, laboratory, data subject rights, withdrawal, reporting, contact, accessibility and support paths, and paths with sensitive token parameters, are excluded.
The Edge endpoint processes the user JWT and exact decision time solely to verify the session and current account consent. Normal connection data may technically arise at Supabase; hosting/security logs are covered by the Privacy Policy. The permanently written statistics contain only the UTC calendar day, permitted event name, normalised route template, the four finite funnel dimension keys and a counter. Core Web Vitals additionally include metric name, rating, navigation type, completion flag, and daily count, sum, minimum and maximum of the measured value. In particular, they contain no user ID, IP address, user agent, raw URL, query string, hash/fragment, referrer, JWT, free text, payload, or individual event or decision timestamp. Daily aggregates are retained for no more than 180 UTC calendar days; a daily database job and the write boundary remove older days.
The legal basis for optional processing is consent under Article 6(1)(a) GDPR and section 25(1) TDDDG. Refusal has no adverse effect on sign-in, core functions, service scope or prices.
04 Records
Browser record and separate account projection
The browser record is device-specific and contains only version, yes/no value for statistics and decision time. It remains authoritative on this browser. For signed-in users, Kasp also synchronises the decision to a separate current account projection containing account ID, version, yes/no value, decision time, source and server time. This projection prevents a browser event from being counted using an outdated decision or one withdrawn on another device.
A separate immutable, account-linked consent record is maintained for evidence and conflict resolution. It contains a random request ID, account ID (until account deletion), a one-way checksum of the data subject reference, version, yes/no value, source, client and server times, projection status and a payload checksum—but no name, email address, IP address or user agent. On account deletion, the direct account link is detached; further evidence retention follows the documented erasure and retention policy.
05 Choice
Change, withdraw or technically block consent
The choice can be changed at any time with effect for the future using the 'Privacy settings' button on public pages, the profile menu in the signed-in app or the button on this page. After withdrawal, no further optional statistics events are transmitted until new consent is given. Daily aggregates already created have no account reference and therefore cannot subsequently be attributed to a person or selectively removed from a counter; under Article 7(3) GDPR, withdrawal does not affect the lawfulness of processing before withdrawal.
DNT and GPC are additional technical blocking signals. If either is active, statistics remain disabled even if consent is stored in the browser. Information on the technical signals is provided by the primary specifications from W3C for DNT and the W3C Privacy Community Group for GPC.
Users can additionally delete or block website data in their browser settings. If necessary session storage is blocked, sign-in, OAuth return and protected functions may not work reliably.
The controller is Anel Alicic, trading as KASP. Further information on recipients, third-country transfers, retention and data subject rights is set out in the Privacy Policy. Questions can be addressed to kontakt@kasp.ai .