Cookie Notice
Version 1.0.0, effective from October 4, 2026
This notice explains which cookies and similar technologies Spyral uses, what each one is for and how long it lasts. It covers the website at www.spyral.lu, the sign-in and sign-up pages and the Spyral application. It complements our Privacy Policy, which explains how we process personal data more generally.
Summary
- We use only cookies and browser storage that are strictly necessary to run the website and the service you have asked for: keeping you signed in, protecting sign-in and connection steps, and remembering choices you make yourself.
- We do not use analytics, advertising, social media or cross-site tracking cookies. We do not record your sessions (no session replay) and we do not measure how you browse.
- Because everything we use is strictly necessary, we do not ask for your consent. We tell you about it instead, through a short notice on your first visit and through this page.
- Services of other companies, such as Google Drive, Dropbox, DocuSign and Stripe, are involved only when you choose to use them.
The rule we apply
Article 5(3) of the ePrivacy Directive (2002/58/EC), implemented in Luxembourg by the law of 30 May 2005 on the protection of privacy in the electronic communications sector, allows a website to store information on your device, or to read it, without your consent only where this is strictly necessary to provide a service you have explicitly asked for, or where its sole purpose is to carry out the transmission of a communication. The cookie guidance of the Luxembourg data protection authority (Commission nationale pour la protection des données, CNPD) applies the same test.
Each item listed below meets that test. It makes a function you are using work (for example signing in, or connecting Dropbox), protects the security of your account, or remembers a choice you made yourself (for example your language or colour theme). None of it is used to profile you, to measure audiences or to follow you on other websites.
What we store on your device
Cookies
Set by Spyral and strictly necessary for the service. They need no consent.
| Name | Purpose | Duration | Set by |
|---|---|---|---|
__Secure-session | Keeps you signed in (encrypted session).Only when signed in. | 24 hours | Spyral |
session_id | Identifies the session so you can see and end your active sessions.Only when signed in. | 24 hours | Spyral |
2fa_verified | Confirms the two-factor step of a sign-in.Only during a two-factor sign-in. | 5 minutes | Spyral |
oauth_state_docusign | Protects the DocuSign connection against forged requests.Only while connecting the service. | 10 minutes | Spyral |
oauth_state_dropbox | Protects the Dropbox connection against forged requests.Only while connecting the service. | 10 minutes | Spyral |
NEXT_LOCALE | Remembers the language you chose.Only after you pick a language. | 1 year | Spyral |
Local storage
Kept in your browser to remember choices; never sent to our servers.
| Name | Purpose | Duration | Set by |
|---|---|---|---|
spyral-cookie-notice-dismissed | Remembers that you closed the cookie notice.Only after you act on it. | Until you clear it | Spyral |
theme | Remembers light or dark mode. | Until you clear it | Spyral |
spyral-appearance | Applies your appearance settings before the page loads.Only when signed in. | Until you clear it | Spyral |
favorites | Remembers documents you marked as favourites on this device.Only when signed in. | Until you clear it | Spyral |
project-<id>-last-read | Marks where you stopped reading a project chat.Only when signed in. | Until you clear it | Spyral |
demo_uploaded_documents | Keeps files uploaded in demonstration mode on this device.Only when signed in. | Until you clear it | Spyral |
Session storage
Kept in your browser until you close the tab.
| Name | Purpose | Duration | Set by |
|---|---|---|---|
2fa-banner-dismissed | Hides the two-factor reminder for this session.Only after you act on it. | Until the tab is closed | Spyral |
Set by a provider, only when you start that flow
When you open a provider's own page or window, that provider may set its cookies under its own terms.
| Name | Purpose | Duration | Set by |
|---|---|---|---|
Google | Google's file picker, when you choose files from Google Drive.Only while connecting the service. | Set by the provider | |
Dropbox | Dropbox's file chooser, when you choose files from Dropbox.Only after you act on it. | Set by the provider | Dropbox |
Stripe | Stripe's checkout page, when you subscribe or update payment details.Only after you act on it. | Set by the provider | Stripe |
DocuSign | DocuSign's signing page, when you sign a document.Only after you act on it. | Set by the provider | DocuSign |
The table lists every cookie and browser storage entry that Spyral itself sets, with its purpose, its lifetime and its category. They are of three kinds:
- Cookies are small pieces of data that your browser sends back to our servers with each request. Our sign-in cookies are HttpOnly (scripts on the page cannot read them), Secure (sent only over an encrypted connection) and SameSite=Lax (not sent with cross-site requests that could change data).
- Local storage keeps small values in your browser until you or the website remove them. We use it for interface choices (your colour theme and appearance settings, your favourite documents and projects, when you last read a project chat, and whether you have closed the cookie notice) and, in demonstration mode only, to keep a list of the files you upload on your own device. Your browser does not send local storage to our servers with your requests.
- Session storage works like local storage but is cleared when you close the browser tab. We use it only to remember, for the rest of your visit, that you closed a reminder to set up two-factor authentication.
Signing in
When you sign in, we set two cookies. The first holds a signed token that identifies your account and keeps you signed in. It expires 24 hours after it was last renewed, and it is renewed automatically while you use Spyral. The second identifies your session record and expires 24 hours after you signed in.
The session record on our servers stores your IP address and your browser's user-agent string, with timestamps. We use it to show your active sessions in your settings, to let you sign out other devices, and to protect your account. When you sign out, both cookies are deleted together with the session record. Session records that have expired are deleted by our daily retention routine.
If you use two-factor authentication, a further cookie records, for five minutes, that you have just confirmed your identity with your second factor.
Connecting other services
When you connect Dropbox or DocuSign to Spyral, we set a cookie that holds an encrypted value describing the connection you started. When Dropbox or DocuSign sends you back to Spyral, we compare the reply with that value to make sure it belongs to your connection, which protects you against cross-site request forgery. The cookie lasts at most 10 minutes and is deleted once the reply has been checked.
Your language
If you choose a language in Spyral, we remember your choice in a cookie for one year. We do not set this cookie unless you make a choice: without it, Spyral uses the language your browser asks for.
What we do not use
- No analytics or audience measurement, whether our own or a third party's.
- No advertising, retargeting or social media cookies or pixels.
- No session replay or other recording of what you do on a page, and no performance tracing in your browser.
- No fingerprinting or other technique to recognise your device without storing anything on it.
If something goes wrong in your browser, the page sends a technical error report to our error-monitoring provider so that we can find and fix the fault. Document names and similar details are removed from these reports, nothing is stored on your device for them, and they are not used to follow your activity. The Privacy Policy describes this processing.
Every change to Spyral's code passes an automated check that fails if a known analytics, advertising or session-recording tool is added, or if a page starts to load scripts from a website we have not approved.
Services of other companies
Some features rely on another company's service. That company's scripts or pages are loaded only when you use the feature, and the company may then set or read its own cookies under its own policy. Spyral has no access to those cookies.
- Google Drive. When you choose to import files from Google Drive, your browser loads Google's file picker and sign-in scripts from Google's servers. Nothing from Google is loaded before you click. See Google's privacy policy.
- Dropbox. When you choose files with the Dropbox Chooser, your browser loads Dropbox's script. When you connect Dropbox to your workspace, you are sent to Dropbox's website to approve the connection. See Dropbox's privacy policy.
- Stripe. When a person who manages billing for a workspace subscribes or changes the subscription, Spyral sends them to Stripe's own payment and billing pages. Spyral's pages do not load any Stripe script. See Stripe's privacy policy.
- DocuSign. When you connect DocuSign, you are sent to DocuSign's website to approve the connection, and people who sign a document do so on DocuSign's website. See DocuSign's privacy notice.
The notice on your first visit
The first time you open Spyral in a browser, a small notice at the bottom of the screen tells you that Spyral uses only strictly necessary cookies and storage, with a link to this page. It appears on the website, on the sign-in pages and in the application alike. When you close it, we record that in your browser's local storage, with the date, so that the notice does not appear again in that browser.
The notice does not ask for your consent and does not offer a choice: closing it, or ignoring it, does not change which cookies we use. It appears again if you clear your browser's site data, use a private window, or use another browser or device.
Controlling and deleting cookies and storage
You can see and delete the cookies and storage that Spyral has set at any time in your browser's settings, usually under privacy or site data, where you can remove the data for spyral.lu alone. You can also block cookies for spyral.lu.
Because everything we set is strictly necessary, blocking or deleting it has consequences. Without the sign-in cookies you cannot sign in or stay signed in, a connection to Dropbox or DocuSign cannot be completed, and your language and interface choices are reset. Signing out deletes the sign-in cookies.
Changes to this notice
If we ever want to use a cookie or storage entry that is not strictly necessary, we will update this notice and ask for your consent before setting it. When we add or change a strictly necessary item, we update the table on this page.
Contact
Questions about this notice or about cookies can be sent to privacy@spyral.lu. Who we are and how else to reach us is set out in the Legal notice.
Version history
| Version | Effective from | Status |
|---|---|---|
| 1.0.0 | October 4, 2026 | In force |