Cookies, Tracking & Local Storage Policy
Last updated: January 2025
How we use cookies, local storage, session tools, and related technologies within the SOVEREIGN\\PROVENANCE ecosystem.
TL;DR
- •We use cookies only for security, session management, and essential functionality
- •We do not engage in advertising, behavioral profiling, or cross-site tracking
- •Essential cookies do not require consent; functional and analytics cookies do
- •You can control cookies through browser settings or our consent preferences
1. Our Tracking Philosophy
SOVEREIGN\PROVENANCE is a provenance engine, not an advertising network.
We use cookies and local storage only for:
- security
- session continuity
- provenance workflow stability
- analytics necessary to improve reliability
- user preferences
We do not engage in advertising cookies, behavioral profiling, cross-site tracking, or third-party marketing integrations.
2. Types of Cookies & Storage We Use
A. Strictly Necessary Cookies (Essential)
Required for account login, session management, CSRF protection, sovereign zone enforcement, and provenance workflow execution.
Examples: session_id, auth_token (encrypted), zone_residency
Consent: Not required under GDPR Article 5; these are mission-critical.
B. Functional Cookies
Used for saved dashboard filters, theme or interface preferences, and collapse/expand state for UI components.
Examples: ui_theme, dashboard_viewmode, recent_entities
Consent: Required in the EU and UK unless strictly necessary.
C. Security & Integrity Cookies
Used for account protection, suspicious login detection, preventing fraudulent activity, and enabling cryptographic workflow validation.
Examples: security_nonce, integrity_token, rate_limit_token
These cookies do not track user behavior beyond security contexts.
D. Anonymous Analytics (Optional)
Used only to monitor platform performance: page load speed, workflow success rates, freeze/crash metrics, API latency.
Examples: analytics_session, anon_event_id
Data included: Non-personal; never tied to user identity.
Consent: Required under GDPR/ePrivacy. Users may opt out at any time.
3. What We Explicitly Do NOT Use
We do not deploy:
- advertising cookies
- retargeting pixels
- third-party tracking scripts
- fingerprinting technologies
- hidden cross-site identifiers
- behavioral profiling tools
- cookies designed for marketing data sharing
No tracking occurs outside the SOVEREIGN\PROVENANCE environment.
4. Local Storage Usage
Local storage is used exclusively for open tab state, temporary draft data, selected zone view, artifact review modes, cached UI preferences, and client-side cryptographic workflow helpers.
Local storage does not contain personal profile data, artifact contents, sensitive identifiers, private metadata, or proprietary cryptographic keys.
Local storage clears when users wipe browser storage, local preferences are reset, accounts are deleted, or specific retention windows are reached.
5. Consent Requirements
EU/UK Users: Under GDPR + ePrivacy Directive, strictly necessary cookies do not require consent. Functional and analytics cookies require consent, which must be explicit, revocable, and logged.
US Users (CCPA/CPRA): We provide clear opt-out for analytics, do not "sell" or "share" user data, and honor global privacy controls (GPC).
Brazil (LGPD), Canada (PIPEDA), Other Regions: Consent requirements mirror GDPR in most cases. SOVEREIGN\PROVENANCE applies the strictest standards globally.
6. How Users Can Control Cookies
Users may accept or reject non-essential cookies, modify consent at any time, disable cookies in their browser, enable "Do Not Track" (honored), opt out of analytics in Settings, or clear local storage using browser settings.
Note: Disabling essential cookies may break login or provenance functions.
7. Provenance-Specific Considerations
Because provenance operations may require session continuity and zone metadata, certain cookies integrate directly with the provenance engine:
- Sovereign Zone Residency Cookie: Ensures proper jurisdictional processing, correct residency enforcement, and valid cross-zone propagation rules
- Integrity Workflow Cookies: Support tracking workflow states, protecting against workflow tampering, and verifying cryptographic sequence integrity
- Guardian Node Cookies: Used when operating institutional dashboards, city-level provenance views, and sovereign zone configuration tools
These cookies remain technical and non-personal.
8. Retention Durations
Cookies expire as follows:
- essential cookies: session-only or ≤ 30 days
- security cookies: 1–7 days
- functional cookies: 30–180 days
- analytics cookies: 30–180 days
- local storage: until manually cleared or TTL expiry
Users can see exact lifetimes via browser developer tools.
9. Policy Updates
We update this policy periodically to reflect regulatory changes, system improvements, new provenance features, or consent UX enhancements. "Last updated" reflects the most recent version.