Legal and trust
Cookie and Tracking Policy
How One Realm uses cookies, browser storage, analytics, and similar technologies.
Last updated: May 25, 2026Summary
One Realm uses necessary cookies and browser storage to sign users in, protect accounts, remember preferences, and run the app. If enabled, One Realm may also use optional analytics tools such as PostHog to understand product usage and improve the service.
Where required by law, optional analytics and tracking technologies do not run until you consent.
Strictly Necessary
These technologies are needed for login, session security, routing, account protection, and core app behavior. They are not used for advertising.
| Name | Type | Purpose | Duration |
|---|---|---|---|
| or-session | httpOnly cookie | Server session cookie for authenticated pages and route handling. | Up to 14 days |
| Firebase Auth browser persistence | Browser storage | Keeps client authentication state available between page loads. | Until sign-out or browser clearing |
| or-consent | Cookie | Stores cookie and tracking preferences. | Until changed or expired |
| dashboard-theme | Local storage | Remembers UI theme preference. | Until changed or cleared |
| or-email-verification-complete | Local storage | Coordinates email verification completion in the browser. | Until cleared or overwritten |
Functional Storage
Functional storage remembers non-essential preferences that improve the experience. Some current UI preferences may be treated as necessary if the app requires them for stable behavior, but they are not used for tracking.
Analytics
If enabled and consented where required, analytics may collect page views, navigation and feature events, button clicks, browser and device metadata, account identifiers after sign-in, and session replay or autocapture events.
If autocapture or session recording are enabled, they are treated as optional analytics/tracking. Inputs are masked where supported, and these tools are gated behind consent in opt-in regions.
Backend analytics and exception diagnostics do not store or access information on the user's device, so they are not cookie consent flows. They still belong in the Privacy Policy, Subprocessors page, and retention decisions if they process personal data.
Marketing
One Realm does not currently plan marketing or retargeting cookies. If this changes, the product must add a separate marketing consent category before those tools run.
Regional Consent Behavior
- EU, EEA, UK, and Switzerland: analytics and marketing default off until explicit opt-in.
- Unknown region: default to opt-in required.
- Other regions: either show the same preference center globally or run only analytics that is lawful for that region.
Region detection can be wrong because of VPNs, proxies, travel, or hosting limitations. User preference controls once set.
Managing Preferences
Users can accept analytics, reject analytics, change preferences later, and keep using the app with only necessary cookies.
Contact
Cookie and privacy questions: privacy@one-realm.com.