Cookies & Local Storage
Scope
This page explains information stored on or read from a visitor’s browser or device by the standard installation of InFeeo. The operator must update this page and, where required, add a valid consent interface before activating analytics, advertising, embedded social media, marketing pixels or other non-essential technologies.
Session cookie
A technically necessary session cookie maintains authentication state, CSRF protection, flash messages and secure request continuity. Without it, account and administrative functions cannot operate reliably. It is normally deleted when the session ends, subject to browser behavior and server configuration.
Persistent sign-in cookie
When persistent sign-in is active, a separate cookie keeps the user signed in on the same device until logout, browser-data deletion, token expiry, password-related revocation or administrative invalidation. The cookie contains a random selector and validator, not the password. The database stores only a one-way hash of the validator. Successful automatic sign-in renews the token validity and old tokens can be revoked.
Appearance preference
Guests use the Light or Dark appearance selected globally by the administrator and are not offered a personal appearance selector. Signed-in users can choose Light, Dark or System; their preference is stored in their account and may also be mirrored in local browser storage so it can be applied immediately. This preference is not used to track activity across unrelated websites.
PWA, service worker and cache
When PWA functionality is enabled, the browser can store the application manifest, icons, styles, scripts, offline page and cache metadata. This improves installation and resilience. The standard configuration is not intended to keep a permanent offline copy of private feeds or account pages.
Clipboard and native share
A share action can ask the operating system to open its native share interface. Where unavailable, the service can write the selected canonical link to the clipboard after a user gesture. No contacts or destination are read by the web app.
Legal basis for device access
The standard technologies are intended to be strictly necessary for the service explicitly requested by the user or to store a user-requested preference. In Germany, non-essential access to terminal equipment generally requires consent under Section 25 TDDDG. The operator must reassess this position whenever functionality or providers change.
No advertising or third-party analytics by default
The distributed standard version contains no advertising network, behavioral analytics, cross-site tracking pixel or third-party social-media embed. Server logs and basic internal counters are separate from browser tracking and are described in the Privacy Policy.
Managing stored information
Users can log out to revoke the current persistent sign-in token and can clear cookies, local storage, PWA data and caches in browser or device settings. Clearing data can sign the user out, reset appearance and remove the installed offline shell. Browser names and menu paths vary.

