Legal

Cookie Policy

Effective date: 31 August 2026

Cookie Policy

This page lists everything norba.io stores in your browser — cookies, local storage and session storage alike, because the law is about storage and not about the word “cookie”.

Only one group is optional, and it is off until you switch it on. Nothing here is used for advertising, we run no ad networks or social pixels, and we do not sell or share your data with data brokers.

[ 01 ]

Strictly necessary

These make the site work: they sign you in, keep the sign-in honest, and remember the choices you made about how the page looks. They are exempt from consent under Article 5(3) of the ePrivacy Directive because the service you asked for cannot be delivered without them — so there is no switch for them, and turning them off means not using the site.

gds_access_token
The signed-in session itself. Without it every page of the dashboard would ask for the password again.
Local storage · Norba (first party) · Until you sign out, 7 days, or 12 hours of inactivity — whichever comes first
gds_token_expires_at, gds_last_active
When the session stops being valid and when it was last used, so an abandoned tab logs itself out instead of leaving a live session on a shared machine.
Local storage · Norba (first party) · Same as the session
gds_impersonator_token, gds_impersonated_user
Present only while a Norba support operator is working inside your account with your knowledge — it parks their own session so they can return to it. A banner is shown for the whole time.
Local storage · Norba (first party) · Until the support session ends
norba_oauth_state
A one-time random value that ties a “Sign in with Google” round trip to the tab that started it, so somebody else's sign-in cannot be planted in your browser.
Session storage · Norba (first party) · Deleted the moment the sign-in completes; gone when the tab closes
norba_consent
Your answer on this very subject, with the date you gave it. Without it we could not honour a refusal, and we would have to ask on every page.
Cookie + local storage · Norba (first party) · 6 months, then we ask again
lang
The language you picked, so the server renders the first page in it.
Cookie · Norba (first party) · 1 year
theme
Light or dark, read before the first paint so the page does not flash the wrong one.
Local storage · Norba (first party) · Until you clear it
norba_table_view:*
Which columns, filters and sort order you left a dashboard table in. Layout only — no data from the table.
Local storage · Norba (first party) · Until you clear it
__stripe_mid, __stripe_sid
Fraud prevention on the card form. Set by Stripe, and only once you open “Add payment method” on the billing page — Stripe.js is not loaded anywhere else, so these do not exist unless you go there. Card details go straight to Stripe and never touch a Norba server.
Cookie · Stripe Payments Europe, Ltd. · 1 year (mid) and 30 minutes (sid), set by Stripe

[ 02 ]

Product analytics and session replay — your choice

Off by default. Nothing in this group loads, and no request to the provider is made, until you enable it. You can turn it back off at any time; doing so deletes what the provider stored and reloads the page so the recorder stops within the same visit rather than at the next one.

Better Stack browser tag (b.js) and the storage it creates
Which pages are used and how fast they are, JavaScript errors, and a replay of the interaction with every text node and every input masked before capture. Used to find broken and slow pages. Not loaded at all on /dashboard/** or /auth/** — the pages that handle API keys, tokens and TOTP secrets — with or without consent.
Script, cookies and local storage · Better Stack (BetterStack s.r.o.) · Set by Better Stack; the tag is never loaded before you consent

[ 03 ]

What we do not do

  • No advertising or retargeting cookies, and no ad network of any kind.
  • No social-media pixels — no Meta, no LinkedIn Insight, no TikTok, no X.
  • No Google Analytics, and no Google Tag Manager.
  • No fingerprinting, no cross-site tracking and no data sold or licensed to brokers.
  • No cookie walls: refusing the optional group costs you nothing on this site.
  • Fonts are served from our own domain, not fetched from Google Fonts at page load, so reading a page does not tell Google you did.

[ 04 ]

Changing your mind

Withdrawing is as easy as consenting, which is the point of the link below and of the “Cookie preferences” link at the bottom of every page. Because a stored answer stops being a current one, we ask again after six months.

You can also clear or block storage in your browser's settings. Blocking the strictly necessary group will sign you out and stop the dashboard from working; blocking the optional group is exactly equivalent to refusing it here.

[ 05 ]

Changes

If we add or change a purpose, we raise the version this page's banner records and ask you again rather than reading an old answer as covering something new. Material changes are also announced by email to account holders.

[ 06 ]

Contact

Questions about anything on this page, including a request to see the record of your own consent: hello@norba.io.

Cookie Policy — Every Cookie Norba Sets