This is a draft prepared from the actual code. The storage listed below was read from the application itself, so it is accurate as at the review date - but it has not been reviewed by a lawyer, and it must be re-checked whenever the application changes.
01The short version
Savvy DocGen does not set any cookies. Not for sign-in, not for preferences, and not for tracking. There is no advertising network here, no tracking pixel, and nothing that follows you to another site.
What the application does use is local storage in your own browser: a small set of values that keep you signed in and remember your preferences. They stay on your device and are not transmitted to us as a cookie header would be.
We are describing it here anyway, because the law that governs cookies generally governs anything stored on your device - and because a policy that claimed cookies we do not set would be worse than useless.
02Why there is no consent banner
Consent is required for storage that is not necessary to deliver a service you asked for. Everything we store falls into two groups:
- Strictly necessary - without it you cannot stay signed in, and the product cannot tell what your account is permitted to do. Consent is not required for this, and refusing it would mean refusing to log in.
- Functional - your theme, your language, which org you were last working in. Convenience only, and losing it costs you nothing but a re-selection.
There is no advertising, profiling or cross-site tracking storage of any kind, which is the category a banner exists to obtain consent for.
03What we store
The complete list, read from the application itself.
All of it is first-party: readable only by this application, in your browser, on your device.
04Analytics
The platform includes a setting for a Google Analytics measurement identifier, but no analytics script is currently loaded and no analytics data is currently collected. The field exists; the tracking does not.
If analytics is ever switched on, this policy will be updated before it is, and a consent mechanism will be added where the law requires one. Analytics is not strictly necessary storage and we will not treat it as though it were.
05Other people's cookies
When a document is sent for signature, the recipient opens it on Circularo, not here. Circularo's own cookie and privacy notices apply from that point, and we do not control what they set.
The same is true of Salesforce when you are working in your own org. Anything either provider stores is governed by your agreement with them.
06Clearing it
Signing out clears the values tied to your session. To remove everything, clear site data for [APPLICATION DOMAIN] in your browser settings - in most browsers, under Privacy, then site or storage settings.
Clearing storage signs you out and resets your preferences. It does not delete anything from your account, your documents or your Salesforce data.
Blocking local storage entirely will prevent sign-in from working, because there would be nowhere to hold the session.
07Changes
This policy is re-checked against the application whenever storage changes, and always before analytics or any similar capability is enabled. The version and date at the top reflect the current text.
Questions about this policy: [PRIVACY CONTACT EMAIL]
See also our privacy policy for how personal data is handled more broadly, and our security page for how it is protected.