This English text is a convenience translation. The legally binding version is the German one (Deutsch), reachable via the language switch below.
Last updated: 2026-06-25
This policy is published in English and in German. The German version is the binding version; the English text is a translation provided for convenience.
This Cookie and Storage Policy explains the cookies and browser storage that Finalform GmbH uses on its own websites, autopage.dev and app.autopage.dev. It supplements, and should be read together with, our Privacy Policy and our Impressum.
Controller.Finalform GmbH, Theodor-Heuss-Str. 106, 26129 Oldenburg, Germany, registered in the commercial register of the Amtsgericht Oldenburg under HRB 222780, USt-IdNr. DE457693089, Managing Director (Geschäftsführer) Robin Schröder, is the controller for the storage and processing described here.
This policy covers only the cookies and browser storage that we set on our own properties: the marketing site at autopage.dev and the dashboard at app.autopage.dev.
It does notcover pages that our customers connect to Autopage. When the Autopage snippet runs on a customer's own landing page, it operates on that customer's behalf and under that customer's instructions. For that snippet storage the customer is the controller, and the disclosure of, and any consent for, that storage toward the visitors of those pages is the customer's responsibility, as set out in our Terms of Service and our Data Processing Agreement. The two storage items the snippet sets on a customer page (a 30-day first-party cookie ap_session, a pseudonymous session identifier, and a session-storage key ap_traffic_source) are therefore out of scope here and are documented to the customer, not in this notice.
Two distinct legal layers govern cookies and equivalent browser storage in Germany, and we treat them separately:
Web Storage technologies (localStorage and sessionStorage) carry the same Section 25 duty as cookies. We therefore disclose every browser-storage key below alongside the cookies, with the same level of detail: name, type, purpose, duration, Section 25 status, and Art 6 basis.
This cookie is required to sign you in and keep your session secure. It is strictly necessary for a service you have expressly requested (signing in to the dashboard) and is therefore exempt from consent under Section 25(2) TDDDG.
| Name | Type | Purpose | Duration | Section 25 status | Art 6 basis |
|---|---|---|---|---|---|
| better-auth.session_token (prod: __Secure-…) | Cookie (httpOnly) | Keeps you signed in to the dashboard and keeps your session secure | 7 days | Essential, consent-exempt under Section 25(2) | Art 6(1)(b) contract |
We set no other strictly necessary cookies on our own sites: there is no separate CSRF, consent-store, load-balancer, or CDN cookie configured in our application.
These cookies and storage keys remember choices you made so the interface behaves the way you set it. They are first-party, are set in response to your own actions, and are not used to track you or to build a profile.
| Name | Type | Purpose | Duration | Section 25 status | Art 6 basis |
|---|---|---|---|---|---|
| better-auth.last_used_login_method | Cookie (not httpOnly) | Pre-selects the sign-in method you used last | 30 days | Preference, consent question (see Section 6) | Art 6(1)(f) legitimate interest, or consent if reclassified |
| theme | Cookie | Remembers your light or dark theme choice so pages render correctly on the server | 1 year | Preference, consent question (see Section 6) | Art 6(1)(f) legitimate interest, or consent if reclassified |
| theme | localStorage | Mirrors your light or dark theme choice on the client | Until you clear it | Preference, consent question (see Section 6) | Art 6(1)(f) legitimate interest, or consent if reclassified |
| sidebar_state | Cookie | Remembers whether the dashboard sidebar is expanded or collapsed | 7 days | Preference | Art 6(1)(f) legitimate interest |
| NEXT_LOCALE | Cookie | Remembers your interface language for the duration of your browser session | Session (no max-age) | Preference | Art 6(1)(f) legitimate interest |
| ap:updates-last-seen | localStorage | Stores the timestamp of when you last opened the "What's new" drawer, to show the unread indicator | Until you clear it | Preference | Art 6(1)(f) legitimate interest |
The theme choice is held in two places: a cookie, so the correct theme can be rendered on the server on first load, and a mirrored localStorage key, so the choice persists on the client. Both are listed above so each storage item is disclosed in its own right.
We currently use no analytics or marketing cookies on our own properties. There are no third-party trackers, advertising pixels, or analytics scripts on autopage.dev or app.autopage.dev, and there is no consent-management platform or cookie banner, because none is needed for the storage above. Our internal analytics interface is a no-op stub that stores nothing.
Stripe (our payment provider) sets no cookies on our domains: payment is handled on Stripe-hosted pages, and any Stripe cookies are set on Stripe's own domain, outside the scope of this policy.
Third-country storage: none. All of the cookies and storage keys above are first-party storage on your own device. We use no third-party storage provider that places cookies or storage outside the EEA for our own sites.
If this ever changes, that is, if we introduce any new non-essential storage such as analytics or marketing technology, we will update this policy first and, where the law requires it, obtain your prior consent before that storage is set.
Delete or block in your browser. You can delete or block cookies and clear browser storage at any time in your browser settings. If you block the strictly necessary better-auth.session_token cookie (production: __Secure-…), you will not be able to stay signed in to the dashboard. Clearing the preference storage simply resets your theme, sidebar, language, sign-in-method, and "What's new" defaults; nothing else is affected.
Withdrawing consent. Today we set no storage that depends on your consent, so there is no consent to withdraw and no consent banner to manage. If the classification of theme or last_used_login_method is reclassified as consent-requiring (see the classification in Section 4), we will add a control on app.autopage.dev that lets you withdraw consent as easily as you gave it, and we will update this policy accordingly.
We may update this policy when our storage practices change or when the law requires it. Each version carries an effective date at the top of this document. Where a change introduces new non-essential storage, we will act as described in Section 5.
For questions about this policy or about the storage we use, contact us at support@autopage.dev. You can also read our Privacy Policy for the full account of how we process personal data.