Cookie Policy
Last updated
1. Introduction
This policy explains the small amount of information Verdly stores on your device, and why.
We’ve written it as a “Cookies & Local Storage Policy” rather than a “Cookie Policy” because, in our case, the second name fits better — we don’t use traditional tracking cookies, but we do rely on your browser’s local storage to keep you signed in and remember a few preferences. Under UK and EU regulations (the Privacy and Electronic Communications Regulations and the GDPR), the rules for cookies, local storage, session storage, and similar technologies are the same. So we treat them the same here.
If you’ve read our Privacy Policy, this document complements it by focusing specifically on what we store directly in your browser.
2. Our approach
Verdly is built around the idea that your financial information is yours. That principle shapes what we store on your device:
- No advertising cookies. Verdly carries no ads and no advertising trackers.
- No marketing or profiling analytics. We don’t use Google Analytics, Meta Pixel, Mixpanel, Hotjar, or any equivalent. We don’t build a profile of you, and we don’t share behavioural data with anyone.
- No cross-site tracking. Nothing we store can be used to follow you around the web.
- Only what’s needed. Everything below is limited to keeping you signed in, remembering settings you’ve explicitly chosen, protecting the service from abuse, and — only if you agree to it — finding faults in the app.
We ask for your permission once, for one thing: error and performance monitoring. That’s it. Everything else we store is either required to sign you in or is a setting you turned on yourself, and neither of those needs your consent.
If you decline, Verdly works in exactly the same way. Nothing is stored for monitoring and nothing is sent. You can change your answer whenever you like at app.verdly.io/settings/analytics.
3. What we store on app.verdly.io
3.1 Strictly necessary
These are required for the app to work. Without them, you can’t sign in or complete the actions you’ve asked Verdly to perform.
| Item | Where it’s stored | Purpose | Lifetime |
|---|---|---|---|
| Authentication tokens | Local storage (set by AWS Cognito) | Keeps you signed in across page reloads. Stored under keys beginning CognitoIdentityServiceProvider.* | Until you sign out or clear your browser data; refresh token expires after ~30 days of inactivity |
| Onboarding draft | Local storage (verdly.onboarding.draft) | Preserves your signup form if you reload the page mid-way. Contains details you’ve entered during onboarding, including name, country, currency, date of birth, retirement age, salary, and your first milestone | Cleared automatically when you complete onboarding |
| Email re-send cooldown | Session storage (auth-resend-cooldown:*) | Prevents accidental repeated requests for verification or password-reset emails. Your email address is hashed before being used as a key — we don’t store it in readable form | The current browser tab session |
| Unsaved snapshot | Session storage (verdly:snapshot-draft:*) | Keeps figures you have typed but not yet saved, so a reload or an accidental navigation doesn’t lose them. Contains only the values you changed and any note you wrote — never a copy of your saved data | The current browser tab session |
| Signup agreement record | Session storage (verdly.signup.legalConsents) | Records which versions of these policies you agreed to during signup, so we can store that against your account when it is created | Cleared when signup completes |
| Upgrade intent | Session storage (verdly.upgrade.intent) | Remembers that you were heading to the upgrade page when you were asked to sign in, so you are returned there afterwards | The current browser tab session |
3.2 Preferences
These remember UI settings you’ve explicitly turned on. They contain no personal data, are never transmitted to third parties, and are scoped to your browser on the current device.
| Item | Where it’s stored | Purpose | Lifetime |
|---|---|---|---|
| AI Insights opt-in | Local storage (insights_enabled) | Remembers whether you’ve enabled AI Insights | Persistent until you clear browser data |
| Theme | Local storage (dark_mode) | Remembers whether you prefer light or dark mode | Persistent until you clear browser data |
| Dashboard layout | Local storage (dashboard.*) | Remembers dashboard toggles you’ve set, such as whether milestones are visible | Persistent until you clear browser data |
| Monitoring answer | Local storage (analytics_consent) | Records whether you accepted or declined error and performance monitoring, so we don’t ask again | Persistent until you clear browser data |
We treat these as strictly necessary on the basis that each one only exists because you actively flipped a toggle to enable it. If you’d rather not have them set, you can simply leave the relevant settings at their defaults.
analytics_consent is stored whichever way you answer, including when you decline. Remembering a refusal is the only way to avoid asking you again on every visit, and it is set on the basis that it is necessary to honour your choice — not on the basis of the choice itself.
3.3 Error and performance monitoring — only if you agree
This is the one item we ask permission for. It is not set unless you accept, and declining leaves it unset.
| Item | Where it’s stored | Purpose | Lifetime |
|---|---|---|---|
| Monitoring session id | Session storage (com.grafana.faro.session) | A random id that lets us see that several errors came from the same visit rather than from many different people. It is not linked to your account and tells us nothing about who you are | Cleared when you close the tab |
While monitoring is on, we also send technical details about faults to Grafana (see section 5.3): the type of error and the place in our code it happened, the page you were on, your browser and operating system, and page-load timings. We do not send the error’s own text — error messages can quote back what you typed, so we replace each one with the location in our code instead. Your figures, asset names, email address and name are removed in your browser before anything is sent, and web addresses are stripped of anything after the ?.
You can withdraw permission at any time at app.verdly.io/settings/analytics. Sending stops immediately, and the session id is cleared when you close the tab.
4. What we store on verdly.io (marketing site)
Nothing.
The Verdly marketing site sets no cookies, writes to no local or session storage, and loads no analytics, advertising, or tracking scripts of any kind.
5. Third-party services we use
5.1 Cloudflare
We use Cloudflare as our CDN and security layer. Cloudflare may set a small number of cookies on verdly.io and app.verdly.io to protect the site from abuse:
| Cookie | Purpose | Lifetime |
|---|---|---|
__cf_bm | Distinguishes legitimate visitors from automated bots | ~30 minutes, rolling |
_cfuvid | Helps Cloudflare’s rate-limiting and bot-management features work correctly | Browser session |
cf_clearance | Set only if you’ve successfully completed a Cloudflare security challenge | Up to 1 year |
These are classified by Cloudflare as strictly necessary for the security of the service. You can read Cloudflare’s documentation on these cookies for more detail.
5.2 AWS Cognito
We use AWS Cognito for authentication. The authentication tokens listed in section 3.1 are issued by Cognito and stored in your browser’s local storage by the Cognito SDK. They are not transmitted to anyone other than Verdly’s own servers.
5.3 Grafana Cloud (Faro)
If — and only if — you accept monitoring, we use Grafana Faro to record errors and page performance. The session id in section 3.3 is written by the Faro SDK running in your browser, and the technical details described there are sent to Grafana Cloud’s United Kingdom (London) region.
Grafana acts as our processor: they may only use this data to provide the monitoring service to us, and we retain it for 14 days. Grafana Faro is a monitoring tool, not an advertising or audience product — it does not track you across other websites and sets no advertising identifiers.
6. Managing what’s stored
Error and performance monitoring can be turned on or off at any time at app.verdly.io/settings/analytics, without clearing anything.
You can clear everything Verdly has stored in your browser at any time. The exact steps depend on your browser, but in general:
- Chrome / Edge: Settings → Privacy and security → Clear browsing data → Cookies and other site data
- Firefox: Settings → Privacy & Security → Cookies and Site Data → Clear Data
- Safari (macOS): Safari → Settings → Privacy → Manage Website Data
- Safari (iOS): Settings → Safari → Advanced → Website Data
If you clear Verdly’s stored data, you’ll be signed out, any in-progress onboarding draft will be lost, and your preferences will reset to their defaults. Your Verdly account and all the financial data you’ve saved are unaffected — those live on our servers and are accessed separately through your account.
You can also use your browser’s developer tools (Application tab in Chrome / Edge, Storage tab in Firefox) to inspect or remove individual entries.
7. Changes to this policy
If we add new items to what we store, we’ll update this policy and, where required by law, ask for your consent before setting anything new. That is what we did for the error and performance monitoring in section 3.3.
8. Contact
If you have questions about this policy, contact us at support@verdly.io.