Skip to main content

Cookie and Local Storage Policy

1. What are cookies and local storage?

This application uses cookies and browser local storage for necessary service functions and to remember certain usage preferences.

Cookies are small text files that websites store in your browser. They are used to remember information about your visit, such as your preferences or authentication status.

Local storage, also known as localStorage, is a browser feature that allows data to be stored directly on your device. Unlike cookies, this data is not automatically sent to the server with every request and remains on your device until you, your browser, or your device settings delete it.

2. Personal and technical data linked to these technologies

To provide the typing service, the application may process personal or technical data linked to the use of cookies, local storage, and network requests.

Metrics associated with registered accounts are stored by the service as described in the Privacy Notice. In guest mode, some progress and practice history may be stored locally in the browser.

Local storage may contain interface preferences, the decision regarding non-essential technologies, and guest progress. It does not directly contain passwords or authentication tokens.

  • Session identifiers: stored in the access_token and refresh_token cookies, which allow the application to recognize your account, authenticate requests, and keep your session active.
  • IP address and technical connection data: transmitted when interacting with the server and when loading external resources, such as flag images from flagcdn.com.
  • Preferences and local data: may include the theme, keyboard layout, font, text size, keyboard visibility, decision regarding non-essential technologies, guest progress, and local history of texts used.

3. Strictly necessary cookies (authentication)

The application uses strictly necessary cookies to sign you in, maintain your identity while browsing, renew your session, and protect authenticated requests.

These cookies are not used for advertising, remarketing, or commercial profiling.

NamePurposeMaximum durationTechnical configuration
access_tokenAuthenticate your requests and keep the access session active.2 hoursHttpOnly, SameSite=Lax, Secure in production.
refresh_tokenSecurely renew the session and allow it to be revoked.7 daysHttpOnly, SameSite=Lax, Secure in production.

4. Local storage (user preferences)

To personalize the experience and retain certain settings, the application stores information in the browser.

This data remains on the device and is not automatically sent to the server with every request, although the application may read it to apply preferences or restore local progress.

KeyPurposeDuration
themeRemember your preference between light and dark mode.Persistent until manually deleted or overwritten.
typing-keyboard-layoutRemember the keyboard layout selected for exercises.Persistent until deleted or overwritten.
typing-fontRemember the font family used in exercises.Persistent until deleted or overwritten.
typing-font-sizeRemember the text size configured for exercises.Persistent until deleted or overwritten.

5. External providers, processors, and possible transfers

The application uses or may use external providers for necessary service functions, such as infrastructure, authentication, security, and resource delivery. Integrations prepared for future functions are not considered active until they are configured and placed into operation.

When a provider processes personal data on behalf of KisoDesk and under its instructions, it will act as a processor or service provider, as applicable.

KisoDesk uses Google Cloud Platform (GCP) infrastructure to host and operate technical components of the service. Data processed in that infrastructure is used to maintain accounts, preserve progress, and operate the platform.

The application allows users to sign in with Google. In that flow, KisoDesk receives only the authorized data necessary to authenticate the account, such as the Google identifier, email address, verification status, and profile name.

The application uses flagcdn.com to load flag images. When those resources are requested, the provider may receive customary technical data, such as the IP address, user agent, date, time, and referrer URL.

When data is disclosed or transferred to a third party other than a processor, it will be handled in accordance with applicable law, including cases necessary to provide the service, maintain the relationship with the user, protect rights, or comply with legal obligations.

Cloudflare Turnstile may be used conditionally to prevent bots and abuse, which may involve Cloudflare processing technical connection data. Email-based recovery is prepared but is not active until an email provider is configured. Analytics cookies, advertising networks, remarketing, and other non-essential tracking systems are not currently used.

7. Data rights and withdrawal of consent

You may request access to, correction, deletion, or objection regarding personal data associated with your account, and you may withdraw consent for processing activities that require it, where applicable.

To exercise these rights, you may send a request to: kisodesk.project@gmail.com.

The controller will communicate its decision within the applicable legal period and, when the request is granted, will implement it within the corresponding period.

These periods may be extended when permitted by applicable law and justified by the circumstances.

Withdrawal of consent will not affect processing previously carried out or processing that must continue because of a legal obligation, an ongoing relationship, security, the defense of rights, or necessary retention.

  • The alias or account identifier used in the application, if applicable.
  • The email address associated with your account.
  • A method for receiving notifications.
  • Reasonable information to verify your identity or ownership of the account, preferably through the associated email address. If acting through a representative, documentation proving their authority.
  • The right you wish to exercise: access, correction, deletion, objection, or withdrawal of consent.
  • A clear and precise description of the personal data involved in your request, such as the email address, alias, preferences, or typing metrics associated with the account.
  • For correction requests, the correct information and, where necessary, supporting information for the requested correction.
  • Any other information reasonably necessary to identify your account and properly address your request.

8. How to manage and delete this data

You can manage cookies, local storage, and your decision regarding non-essential technologies.

  • Sign out: when you sign out, the access_token and refresh_token authentication cookies are deleted from the browser.
  • Privacy and cookie preferences: you can review and change your decision regarding non-essential technologies from your profile. You can also delete cookies and local data through your browser settings.
  • Warning: blocking strictly necessary cookies may prevent you from signing in or using functions that require authentication.

9. Changes to this Policy

The application may update this Policy to reflect legal, technical, or operational changes. Updates will be published on this page with the corresponding last-updated date.

When changes are relevant, they will be communicated through a visible notice in the application, a cookie notice, or another available electronic method.

10. Contact

If you have questions, wish to exercise your rights, or need information about data processing, you may write to kisodesk.project@gmail.com.

To review the identity and contact information of the controller, general purposes, providers, retention, and other processing details, see the application's Privacy Notice.

Cookie and Local Storage Policy | KisoDesk