Canonical page: https://tellenze.com/legal/cookies

# Cookies and browser storage

Document version

Version: 2026-10-10.draft-1

What we save in your browser, why it is there, and how you can remove it.

Tellenze uses browser storage to protect sign-in and forms, remember choices, and help you return to some tools. This notice explains those uses across the public website and private workspaces.

Some information stays in your browser. Shared rooms, submitted forms and workspace content can also be stored on our servers. Removing one copy does not remove the other.

For questions about these uses, contact João Pedro Marques Morais, trading as Tellenze, at general@tellenze.com. Our Privacy Policy explains personal information and your rights.

## 1. What browser storage means

At a glance: Cookies and browser storage serve different purposes.

A cookie is a small value that your browser can send with requests to a website. A session cookie helps the website recognise your current visit. It is different from the workspace information stored on our servers.

Local storage keeps values in your browser between visits. Session storage keeps values for a browser tab session. Browser settings, private browsing and session recovery can affect how long those values stay.

The rules about storing or reading information on a device can apply to these technologies as well as cookies. Information does not have to identify a person for those rules to matter.

## 2. Sign-in and form protection

At a glance: Session and security cookies support the service you use.

Application session cookies support sign-in, protected forms and your participant identity in public rooms. That room identity is held in the server session; your browser carries the session reference.

The security cookie called XSRF-TOKEN helps protect requests against another website trying to act as you. Public embedded forms use a separate submission ticket and do not use the normal sign-in session for submission.

Cookie names depend on the host and feature. Public, workspace, plugin and operator sessions use separate settings. An external sign-in service may also set cookies on its own website.

| Storage | Purpose | Duration |
| --- | --- | --- |
| Public session, normally tellenze_public_session | Protected public forms and participant identity in shared tools. | Configured session lifetime. The application default is two hours of inactivity; live settings need confirmation. |
| Workspace session, normally a tellenze_workspace_ name | Keep the signed-in workspace session on its host. | Configured session lifetime; activity can renew the session. |
| XSRF-TOKEN | Protect forms and other requests from unwanted actions. | Uses the session lifetime for its cookie expiry. |
| Plugin and operator sessions | Support the plugin sign-in flow and the separate operator portal. | Host settings apply. The operator portal uses a one-hour session setting. |

## 3. Website and workspace choices

At a glance: Your public website appearance is separate from your account settings.

When you choose Light or Dark on the public website, we remember that choice in local storage under tellenze-public-theme. It has no automatic expiry in the application. Removing that site data returns the website to its default light appearance.

Your private workspace appearance is saved with your member account. Changing the public website choice, or removing its local storage, does not change that account setting.

Private pages also remember some navigation choices in local storage, such as collapsed Focus groups, document folders and the Home Signals section. Looper uses session storage for the current conversation reference and last interaction time. Clearing those references does not delete the saved conversation or workspace content.

## 4. Public tool drafts and choices

At a glance: Local tools can save your edits in this browser.

The WSJF Calculator, Flow Lab, Focus Sandbox and Scope Slicer save a local draft or settings after you edit them. This helps you return to your work in the same browser. These local records do not have an automatic expiry in the application.

Planning Poker remembers the display name you entered and your chosen results order in local storage. It also uses a tab-session marker to avoid repeating the same reveal animation.

Download or copy a draft you want to keep before clearing site data. A downloaded file, copied text or a copy you shared elsewhere has its own location and must be removed there.

| Feature | Local storage key | What it remembers |
| --- | --- | --- |
| WSJF Calculator | tellenze.wsjf.v1 | Your candidates and scores. |
| Flow Lab | tellenze.flow-lab.v1 | Your experiment settings and seed. |
| Focus Sandbox | tellenze.focus-sandbox.v1 | Work names, notes, estimates and placements. |
| Scope Slicer | tellenze.scope-slicer.v1 | Your scope plan, stories, dependencies and slices. |
| Planning Poker | tellenze-public-poker-name and tellenze-public-poker-order | Your display name and results order. |

## 5. Forms and shared rooms

At a glance: Browser recovery and server records have separate lifetimes.

Custom forms keep draft answers and a retry reference in session storage while you complete the form. The local draft is removed after a successful submission. The submitted response remains with the organisation that owns the form.

Shared workshop rooms store participant names and contributions on the server so the group can use them. Rooms normally expire 24 hours after creation. A Planning Poker host can choose to keep the room open without a fixed expiry; it still closes when the last participant leaves.

Clearing the session cookie can interrupt access to your existing seat. It does not send a leave or delete request. Room expiry controls access; physical cleanup, backups and separately stored statistics follow other processes.

Poker, retrospective and prioritisation tools also produce server-side usage and round statistics, such as participant counts, phase times and voting distributions. Their statistics records exclude display names and raw discussion text. This does not establish that every small-group result is anonymous in all circumstances. See our Privacy Policy for the wider treatment of this information.

## 6. When consent is needed

At a glance: The purpose and privacy effect matter, not just the storage name.

Storage strictly needed for a service you request, such as sign-in or request protection, may be used without cookie consent. We must assess the need for each purpose; calling a feature useful or functional is not enough.

Under Dutch rules, limited measurement of a service's quality or effectiveness may also qualify for an exemption only where it has no or little effect on privacy. This does not automatically cover all analytics, device identifiers or tracking. A separate lawful basis is still needed when personal information is processed.

When consent is required, it must come before the storage or access takes place. It must be a clear, informed choice that can be withdrawn. Continuing to browse does not give consent.

This notice is an explanation, not a consent control. There is no optional-tracking settings button on this page. A new tracking or storage purpose needs its own review and any required controls before it is introduced.

## 7. Your browser controls

At a glance: You can remove site data, with a few effects to consider.

Use your browser's privacy or site-data settings to inspect, block or remove cookies and other storage for the Tellenze host you visited. Cookies and local storage are different: deleting cookies alone may leave local drafts and preferences in place.

Public website and workspace hosts can hold separate data. Check each relevant host. Save any local draft you need, leave shared rooms when appropriate, and close Tellenze tabs before clearing site data so an open page does not save its current state again.

Removing session cookies can sign you out or interrupt forms and room access. Removing local storage can reset website choices and erase local drafts. Blocking required storage can stop some features from working.

These browser actions do not delete your member account, submitted forms, shared room contributions, saved Looper conversations, server logs or backups. Use the relevant product controls or contact general@tellenze.com about a privacy request.

## 8. Other services and changes

At a glance: A service you connect can have its own storage rules.

A sign-in provider, external link or service connected by your organisation has its own cookie and privacy information. Your organisation's choices can affect which services you use. Our provider information distinguishes Tellenze suppliers from services you choose to connect.

We will review this notice when storage purposes or services change. The version shown on this page helps you identify the text you are reading. You can contact general@tellenze.com to ask about a storage use or to object to personal information processed on a legitimate-interests basis.

## Sources used for this document

- [Autoriteit Persoonsgegevens: cookies and consent exceptions](https://autoriteitpersoonsgegevens.nl/nl/onderwerpen/internet-telefoon-tv-en-post/cookies)
- [Dutch Telecommunications Act: Article 11.7a](https://wetten.overheid.nl/BWBR0009950/#Hoofdstuk11_Artikel11.7a)
- [European Data Protection Board: technical scope of the ePrivacy rules, final guidance](https://www.edpb.europa.eu/documents/guideline/guidelines-22023-on-technical-scope-of-art-53-of-eprivacy-directive_en)
- [Autoriteit Persoonsgegevens: clear cookie choices and withdrawal](https://autoriteitpersoonsgegevens.nl/themas/internet-slimme-apparaten/cookies/heldere-en-misleidende-cookiebanners)
- [Google Chrome Help: remove cookies and other site data](https://support.google.com/chrome/answer/95647?hl=en)

Contact: general@tellenze.com
