Cookie Policy

A short list. No advertising trackers.

This page describes the cookies and similar storage technologies used by Citesvue on citesvue.com and inside the application. We do not use third-party advertising cookies anywhere on the site or in the product. Strictly necessary and basic functional cookies run by default; analytics cookies and any optional categories are consent-gated where required by law.

Last updatedVersion1.0 · public preview
TL;DR

The whole policy in five bullets.

  • We use first-party cookies only. No third-party advertising or cross-site tracking.
  • Strictly necessary cookies (auth, session, CSRF) run by default — they’re required for the site to work.
  • Functional cookies (timezone, theme, region preference) run by default and only store low-risk personalisation state.
  • Analytics cookies are consent-gated where required (EU/UK/EEA/CH); they sample aggregate behaviour and contain no personally identifying data.
  • Marketing cookies on citesvue.com are limited to consent-gated visit measurement. We do not use ad-tech retargeting.
What cookies are

Small text files, similar tech, same purpose.

A cookie is a small text file a site stores in your browser. We also use closely related technologies — local storage, session storage, and pixels (1×1 transparent images) — for the same purposes described here. Throughout this page, “cookies” means cookies and these similar technologies.

Cookies are either first-party (set by Citesvue) or third-party (set by another domain loaded by the page). They are session cookies (deleted when the browser closes) or persistent cookies (stay until the expiry date or until you delete them).

What we set

The full list, by category.

All cookies on this page are first-party (Citesvue). Names beginning with cv_ are ours.
Inside the application

Three categories. The first two run by default.

1. Strictly necessary

Required for the application to function. Cannot be disabled — without them, the app cannot authenticate you or protect your session. These are exempt from consent requirements under GDPR (Recital 32 / ePrivacy Article 5(3) “strictly necessary” exemption).

CookieSet byPurposeExpiry
cv_sessionCitesvueAuthentication & session integritySession
cv_csrfCitesvueCross-site request forgery protectionSession
cv_wsCitesvueRoutes the request to the correct workspace tenancySession

2. Functional

Remember low-risk personalisation choices so you don’t have to set them on every visit. None of these contain identifiers that can profile you across sites.

CookieSet byPurposeExpiry
cv_pref_tzCitesvueRemembers your timezone preference12 months
cv_pref_themeCitesvueRemembers light/dark display preference12 months
cv_pref_regionCitesvueRemembers data-residency region selection (EU / US / Global)12 months
cv_recent_wsCitesvueLast-active workspace, for fast switching12 months

3. Analytics (first-party, privacy-respecting)

Aggregate product analytics — what features are used, where errors happen, how the application performs in the field. We use a first-party identifier that is not joined with any third-party graph and is not used for cross-site tracking. In jurisdictions where consent is required, these are off by default until you opt in via the in-product or banner control.

CookieSet byPurposeExpiry
cv_anon_idCitesvueAggregate, privacy-respecting product analytics — first-party only, no cross-site tracking13 months
cv_perfCitesvueAnonymous performance & error sampling for the Service6 months
On the marketing site (citesvue.com)

Consent-gated visit measurement only.

The marketing site (citesvue.com pages outside the authenticated app) uses two consent-gated first-party cookies. Where required, both are off until you accept analytics in the consent banner. We do not load Google Ads, Meta Pixel, LinkedIn Insight, TikTok Pixel, or any other ad-network tracker on this site.

CookieSet byPurposeExpiry
cv_mkt_consentCitesvueRecords the choice made in the consent banner6 months
cv_visitCitesvueFirst-party visit counting & navigation analytics on citesvue.com (consent-gated where required)13 months
Service providers we use

Where a vendor processes the data, the data stays first-party.

  • Application observability. A first-party error- and performance-monitoring tool. Receives anonymised diagnostic samples; does not set its own cookies on your browser.
  • Email & support tooling. Used after you contact us. Does not set marketing cookies on this site.
  • Embedded video (where used). If a marketing page embeds a third-party video (e.g. a recorded webinar), the embed is loaded in privacy-enhanced mode wherever the provider supports it (e.g. youtube-nocookie.com) and only after consent if required.
Browser controls

Block, delete, or be told about cookies before they’re set.

Most browsers let you view, manage, or delete cookies for any site. The exact path depends on the browser — these are the typical entry points:

  • Chrome / Edge: Settings → Privacy & security → Cookies and other site data.
  • Firefox: Settings → Privacy & Security → Cookies and Site Data.
  • Safari (macOS): Settings → Privacy.
  • Safari (iOS): Settings → Safari → Privacy & Security.
Disabling strictly necessary cookies will prevent you from logging in or maintaining a session. Disabling functional cookies will reset your preferences each visit. Disabling analytics has no functional impact.
Changes

When this list changes, this page changes.

We update this page when we add, remove, or change a cookie. Material changes (a new category, a new vendor) are also surfaced via the consent banner so you can review and re-consent. Past versions are available on request.

Contact

The single inbox.

Questions about this policy: privacy@citesvue.com. Or use the form at /contact?topic=privacy.