Skip to content

Legal

Cookie Policy

Last updated:

Summary. DesAIgner uses the cookies it needs to sign you in, keep your account secure and remember your cookie choice, plus a few small settings that remember how you like the app to look and work. We use analytics (PostHog) only if you accept them in our cookie banner; rejecting is as easy as accepting, and you can change your mind at any time under "Cookie settings". If your browser sends a Global Privacy Control or Do Not Track signal, analytics stay off. We don't use advertising cookies, and no third party sets cookies on our site.

1. What cookies and local storage are

A cookie is a small text file a website stores in your browser, which your browser sends back with each request to that site. Local storage and session storage are similar places in your browser where a website can keep small settings; unlike cookies, they are not sent to the server. Session storage is cleared when you close the tab.

2. The cookies we use

These cookies and storage items are set only by DesAIgner, on our own domain (first-party).

Strictly necessary

The Service can't work without these, so they don't need your consent. The sign-in cookies are set by the sign-in library we use (Auth.js). On a secure (HTTPS) connection their names start with __Secure- or __Host-.

NameWhat it doesHow long it lasts
authjs.session-tokenKeeps you signed in. It holds an encrypted token that identifies your account. Scripts on the page can't read it. If it gets large, it may be split into several cookies ending in .0, .1 and so on30 days. It is renewed at most once a day while you use the Service, and deleted when you sign out
authjs.csrf-tokenProtects the sign-in and sign-out process against cross-site request forgeryUntil you close your browser
authjs.callback-urlRemembers which page to take you back to after you sign inUntil you close your browser
authjs.pkce.code_verifierUsed only when you sign in with Google: a one-time security code that ties Google's answer to the sign-in you started. Scripts on the page can't read it15 minutes, and removed when the sign-in completes
dsg_verify_tokenSession storage (not a cookie): used only when you open an email-confirmation link while signed out. It holds that one-time link while you sign in, so we can finish confirming your email address afterwards. It is never sent to our server as a cookieRemoved as soon as it is used, whether or not the confirmation succeeds, and at the latest when you close the tab
dsg_consentRemembers your cookie choice (whether you accepted or rejected analytics, and when), so we don't ask again on every page. It contains no identifier6 months; then we ask again

Preferences

These remember a choice you made in the interface. They are set only when you make that choice, and they contain nothing that identifies you.

NameTypeWhat it doesHow long it lasts
themeLocal storageRemembers whether you chose the light, dark or system themeUntil you clear your browser's site data
desaigner:plan-viewLocal storageRemembers whether you last used the Simple or Advanced view when reviewing a planUntil you clear your browser's site data
desaigner:proto-keysLocal storageRemembers whether you turned single-key shortcuts off in the prototype playerUntil you clear your browser's site data

These are set by PostHog, our analytics provider, only after you choose "Accept analytics", and never while your browser sends a Global Privacy Control or Do Not Track signal. They help us understand how people use DesAIgner so we can improve it (see the Privacy Policy). In the names below, <key> is our PostHog project key, which is the same for every visitor.

NameTypeWhat it doesHow long it lasts
ph_<key>_posthogLocal storageHolds a random analytics ID (a pseudonymous ID derived from your account once you sign in), the current analytics session and PostHog's settingsUntil you withdraw consent (we then delete it) or clear your browser's site data
ph_<key>_window_id and ph_<key>_primary_window_existsSession storageTell apart visits in different browser tabsUntil you close the tab
__ph_opt_in_out_<key>Local storageSet only if you withdraw consent after accepting: remembers that analytics are off. It contains no identifierUntil you clear your browser's site data

If your browser blocks local storage, PostHog may keep ph_<key>_posthog in a first-party cookie of the same name instead, for up to 1 year or until you withdraw consent.

Shared projects

These are used on pages that a project owner has shared through a link (addresses starting with /p/). Each is set only when you do what its row describes.

NameTypeWhat it doesHow long it lasts
share_unlockCookie, strictly necessarySet only after you enter the correct password for a password-protected link, so you don't have to enter it on every page of that link. It is limited to that one link, scripts on the page can't read it, and it contains no personal data12 hours. It stops working sooner if the owner changes or removes the password or turns the link off
desaigner:share-visitorLocal storageRemembers the name and email address you entered when you first commented on a shared project, so you don't have to type them again. It stays on your device and is sent to us only as part of a comment you postUntil you clear your browser's site data
desaigner:comment-pinsLocal storageRemembers whether you hid the comment pins on screens, on a shared page or in your own projectUntil you clear your browser's site data

3. What we don't use

We don't use:

  • advertising, retargeting or social-media cookies or pixels;
  • third-party cookies of any kind on our website;
  • analytics of any kind unless you have accepted them;
  • session recording: we don't record your screen, mouse movements or what you type.

Our error monitoring (Sentry) sets no cookies and stores nothing in your browser. It sends technical error reports, cleaned of personal data, as described in the Privacy Policy.

4. Your choice and how to change it

The law (the EU ePrivacy Directive and its national implementations) requires consent for cookies and similar storage unless they are strictly necessary to provide a service you explicitly asked for. The strictly necessary items and the preference items above don't need consent. Analytics do, so we ask first.

  • The cookie banner. When analytics are switched on for our website and you haven't made a choice yet, a banner at the bottom of the page offers three buttons of equal size and style: "Accept analytics", "Reject analytics" and "Settings". Nothing analytics-related loads until you accept. Closing or ignoring the banner is not consent.
  • Settings. "Settings" lets you turn analytics on or off on its own. The strictly necessary items are always on.
  • Change your mind at any time. Open "Cookie settings" at the bottom of our website or in your account menu. If you withdraw consent, PostHog stops straight away and we delete its local storage from your browser.
  • Browser privacy signals. If your browser sends a Global Privacy Control or Do Not Track signal, we treat it as a refusal: analytics stay off, the banner is not shown, and the analytics switch in "Cookie settings" is off and can't be turned on.
  • How long we remember. Your choice is kept in the dsg_consent cookie for 6 months. After that, or if we add a new purpose, we ask again.

The items for shared projects work the same way: share_unlock is strictly necessary to open a password-protected link you asked to see, and the local storage entries only keep, on your own device, what you typed or chose yourself.

5. Checkout

When you buy a plan or a credit pack, we send you to the checkout page of our reseller, Creem, on Creem's own website. That page may set its own cookies, for example for payment security and fraud prevention, under Creem's own policies (Creem's Privacy Notice). These cookies are set by Creem, not by us. We don't load any Creem script on our own pages.

6. How to control cookies

Besides "Cookie settings", you can delete cookies and local storage, or block them, in your browser settings. If you block or delete the strictly necessary cookies, you won't be able to sign in. If you delete the preference items or the dsg_consent cookie, the Service simply forgets your choice and asks again.

7. Changes and contact

We will update this policy whenever we change the cookies we use. The date at the top shows when it last changed. Questions: faris@elevatesolutions.ba. For how we handle personal data in general, see our Privacy Policy.