Cookie Policy
Last updated: August 11, 2026
1. What this page covers
Two hosts are covered here, and they do not behave the same way. The public website at noda.energy shows a consent banner and holds non-essential storage until you answer it. The signed-in workspace at app.noda.energy sets the sign-in cookies it needs and records interaction events, which Section 11 of the Privacy Policy lists in full together with how to be excluded. The workspace sets the authentication and analytics rows; the public website sets the rest.
This Cookie Policy explains what cookies and similar browser-storage technologies we use on noda.energy and on app.noda.energy, why we use them, how long they last, and how to change your preferences. It supplements the Privacy Policy.
2. What cookies and browser storage are
A cookie is a small text file a site stores in your browser. localStorage and sessionStorage are similar mechanisms that hold values locally without sending them with every request. We treat all three the same way for consent purposes, in line with Article 5(3) of the ePrivacy Directive 2002/58/EC and its Romanian transposition (Law 506/2004).
3. Categories we use
- Strictly necessary. Required for the site to work: language preference, your consent choice, your conversation with the site assistant, and authentication in the workspace. Set without consent on the basis of Art. 5(3) second sentence of the ePrivacy Directive.
- Analytics. PostHog product analytics, pseudonymous, plus the session-scoped measurement values listed below. One exception worth naming: where you submit the access-request or booking form on the public website, the identifier sent to our analytics provider is the email address you typed rather than a random id. On this website the PostHog browser SDK is not loaded until you opt in. In the signed-in workspace at app.noda.energy, product analytics start when you sign in and are limited to interaction events: pages opened, controls used, and whether an action succeeded. Session recording is switched off. Section 11 of the Privacy Policy lists exactly what an event carries.
- No advertising cookies. We do not run ad networks, retargeting, or third-party advertising trackers.
4. Cookies and storage in detail
| Identifier | Stored in | Purpose | Duration | Category |
|---|---|---|---|---|
| NEXT_LOCALE | Cookie | Stores your language preference, used by localized links such as booking confirmations | Up to 1 year | Necessary |
| noda_cookie_consent | localStorage | Stores your consent choice | Up to 6 months before re-prompt | Necessary |
| noda_consent_timestamp | localStorage | Records the timestamp of the last consent decision | Up to 6 months | Necessary |
| noda_ref | Cookie | Records which referral link brought you to sign-up, so we know where an account came from | Until cleared | Analytics |
| noda_admin_session | Cookie | Signs in a Noda administrator to the internal admin console. Never set on a customer account | 12 hours | Necessary |
| noda_beta_chat_consent | localStorage | Records whether you agreed to the site assistant reading your messages | Until cleared | Necessary |
| noda_beta_account_v1 | localStorage | Keeps what you typed into the access-request form — your email, name, company, sector and start date — so you do not retype it | Until cleared | Necessary |
| noda_beta_signup | sessionStorage | Carries what you entered across the sign-up steps within one visit, including your email address | Until the browser tab is closed | Necessary |
| noda_beta_did | sessionStorage | Random per-visit identifier used to group measurement events from one visit | Until the browser tab is closed | Analytics |
| noda_beta_session_start | sessionStorage | Start time of the visit, used to measure time on site | Until the browser tab is closed | Analytics |
| noda_beta_first_touch | sessionStorage | Campaign parameters, landing path and referrer from the first page of the visit | Until the browser tab is closed | Analytics |
| noda_beta_scroll_reached | sessionStorage | Scroll depth already reported, so a milestone is not counted twice | Until the browser tab is closed | Analytics |
| noda_access / noda_refresh / noda_session | Cookies (Secure, SameSite=Lax). Two qualifications, because the detail matters: the short-lived access cookie and the refresh cookie are HttpOnly and cannot be read by scripts, but a third cookie that merely marks a session as present is deliberately readable by the page so that navigation works, and it lasts 30 days. It carries no token and no personal data — only the value "1".) | Authentication tokens for the app.noda.energy workspace | Access 30 min, refresh 30 days | Necessary |
| ph_* (also mirrored in localStorage, so clearing cookies alone does not clear the identifier) | Cookie + localStorage | PostHog product analytics, on this website, loaded only after you opt in; in the signed-in workspace, loaded on sign-in | Configured in PostHog (typically 12 months) | Analytics |
Nothing in the table above is shared with an advertising network.
5. Consent and how to change it
The first time you arrive on noda.energy we show a consent banner. You can accept analytics or reject them. Your choice is stored in noda_cookie_consent and respected on subsequent visits.
To change your decision later, clear the cookie/localStorage value from your browser and reload. We will show the banner again. You can also manage cookies through your browser settings: Chrome, Firefox, Safari, Edge.
Blocking strictly-necessary cookies may break authentication, language switching, or consent recording, but the choice is yours.
6. Third-party cookies
We do not embed third-party advertising or social tracking pixels on the website. On this website, the only third-party browser storage that may activate after consent is PostHog (product analytics, EU cloud, Germany). The signed-in workspace is described separately in Section 11 of the Privacy Policy. Fonts are served from the site itself. The site assistant keeps your conversation in your own browser so the panel survives a reload; it writes no tracking identifier and sets no cookie.
7. Updates
We update this page when we add or remove cookies, change retention, or change consent mechanics. The current version is on this page with the date above. Material changes also trigger a re-prompt of the consent banner.
8. Contact
Cookie or consent questions: [email protected].