Cookie Policy
Version: 2026-10-01Effective: Last updated:
Draft – under legal review
This text is still being reviewed by our lawyer. The final version may differ; we will tell you in advance about material changes and ask you to accept them again.
Every cookie and local storage key Sayweek uses: what it is for, how long it lasts and how to change your choice.
1. In short
Cookies and the browser’s local stores (localStorage, sessionStorage, Cache Storage) are small pieces of data a website keeps on your computer or phone. On the sayweek.com website and in the app.sayweek.com application we use only our own (first-party) cookies and storage. We use no third-party advertising or tracking cookies, pixels or social plug-ins, and we run no external analytics tool (such as Google Analytics) on our pages; fonts and videos are served by us as well.
There is exactly one cookie we ask your consent for: sw_attr, which remembers how you reached us. Everything else is needed for the service to work, or remembers a setting you chose.
2. Strictly necessary
Without these, signing in, connecting integrations or remembering your cookie choice would not work. They need no consent.
| Name | Purpose | Provider | Duration | Type |
|---|---|---|---|---|
authjs.session-token / __Secure-authjs.session-token | Keeps you signed in: the encrypted session token (Auth.js). A large session may be split into parts (.0, .1). | Sayweek (first party) | 30 days (renewed while you use the app); deleted when you sign out | cookie · app |
authjs.csrf-token / __Host-authjs.csrf-token | Protects the sign-in forms against forged requests (CSRF). | Sayweek (first party) | until you close the browser | cookie · app |
authjs.callback-url / __Secure-authjs.callback-url | Remembers which page to take you back to after signing in. | Sayweek (first party) | until you close the browser | cookie · app |
authjs.pkce.code_verifier / authjs.state / authjs.nonce (__Secure-…) | Security checks of the Google or Microsoft sign-in (PKCE, state, nonce) – only while you sign in. | Sayweek (first party) | 15 minutes | cookie · app |
pp_passkey | The signed, single-use challenge of a passkey sign-in (Touch ID, Face ID, security key). | Sayweek (first party) | 5 minutes | cookie · app |
pp_google_state / pp_mail_state / sw_meet_nonce / sw_ga_nonce / sw_yt_nonce / sw_gbp_nonce / sw_ms_nonce / sw_zoom_nonce / sw_meta_nonce / sw_th_nonce / sw_tt_nonce / pp_li_nonce / pp_li_personal / sw_notion_nonce / sw_hubspot_nonce / sw_pipedrive_nonce / sw_canva_nonce / sw_canva_pkce / sw_canva_return / sw_return | While you connect an integration (Google, Gmail, Google Meet, Analytics, YouTube, Business Profile, Microsoft 365, Zoom, Meta, Threads, TikTok, LinkedIn, Notion, HubSpot, Pipedrive, Canva): checks that the provider's answer belongs to your request, and where to take you back. When you connect an AI assistant (e.g. Claude, ChatGPT), sw_return also keeps the return address after sign-in for 15 minutes. | Sayweek (first party) | 10 minutes (deleted as soon as you return) | cookie · app |
sw_consent | Stores your choice in the cookie bar (“analytics” = you agreed, “essential” = necessary only), so we don’t ask again. | Sayweek (first party) | 180 days | cookie · website and app |
sw_legal_later | Remembers that you postponed re-accepting an updated document (Terms, Privacy Policy, DPA), so we don’t ask again in the meantime. | Sayweek (first party) | 24 hours | cookie · app |
sw-onboard-seen | After you connect an account we show the set-up wizard once; this remembers that you have seen it. | Sayweek (first party) | until you close the tab | sessionStorage · app |
sayweek-v4 | The service worker cache: the offline page, the icons and the program files, so the app starts fast and can be installed. It stores no personal data, posts or drafts. | Sayweek (first party) | until the next app update | Cache Storage · app |
3. Functional (preferences)
These remember the language, appearance and view you chose on this device, or serve a feature you use. They are only created when you use the feature, and they never reach our servers – except sw_ft, which only arrives with an enquiry you send, and sw_ref, which we read when you sign up.
| Name | Purpose | Provider | Duration | Type |
|---|---|---|---|---|
sw_lang | The language you chose (Hungarian, English, German) – only written when you pick a language or sign up. | Sayweek (first party) | 12 months | cookie · app |
sw_ref / sw_ref_seen | Only if you arrive through a customer’s referral link (/ref/…): remembers the referral code so you both get the reward when you sign up (sw_ref_seen: the click was already counted). It contains no personal data; the referrer only sees counts. | Sayweek (first party) | 60 days (sw_ref_seen: 1 day) | cookie · website and app |
theme | Light, dark or system appearance (chosen in the settings or the command palette). | Sayweek (first party) | until you delete it (clear site data) | localStorage · website and app |
sw-section-{…} / sw-brands-open / sw-brand-open-{…} / sw-accounts-open | Which settings sections and brands you left open on this device. | Sayweek (first party) | until you delete it (clear site data) | localStorage · app |
view:{…} / cal:view | The view you chose (cards or list, calendar view). | Sayweek (first party) | until you delete it (clear site data) | localStorage · app |
sw_install_dismissed | Remembers that you chose “Not now” on the card offering to install the desktop app. | Sayweek (first party) | until you delete it (clear site data) | localStorage · app |
sw_nps_checked | So we only ask the server once per browser session whether the short satisfaction question (NPS) is due. | Sayweek (first party) | until you close the tab | sessionStorage · app |
sw_news_dismissed | Remembers that you already closed the highlight of an important release in this tab. | Sayweek (first party) | until you close the tab | sessionStorage · app |
pp-review-author | The name you typed on a client review link (/r/…), so you don’t have to type it again for the next comment. | Sayweek (first party) | until you delete it (clear site data) | localStorage · app |
sw_chat_seen / sw_chat_dismissed | The website chat: when you first visited and whether you closed the greeting (a timestamp only, no identifier). | Sayweek (first party) | until you delete it (clear site data) | localStorage · website |
sw_here / sw_greeted / sw_nudged | So the website chat doesn’t greet you twice in the same tab. | Sayweek (first party) | until you close the tab | sessionStorage · website |
sw_ft | The first page opened in the tab, the referring site and the link’s UTM parameters. It only reaches us if you send a contact request in the chat. | Sayweek (first party) | until you close the tab | sessionStorage · website |
[whether the referral cookie (sw_ref, 60 days) may be set without consent or must be tied to the cookie bar]
4. Anonymous statistics
We count visits and chat openings anonymously, once per browser tab. This is not a cookie, does not follow you to other sites and cannot be linked to you.
| Name | Purpose | Provider | Duration | Type |
|---|---|---|---|---|
sw_sid / sw_ev_{…} | A random id tied to the browser tab, so a visit or a chat opening is only counted once. Not a cookie, stored without an IP address, gone when you close the tab; kept on our server for 90 days. | Sayweek (first party) | until you close the tab | sessionStorage · website |
[counsel to confirm: whether this sessionStorage entry needs consent (Art. 5(3) ePrivacy Directive, Hungarian Electronic Communications Act s. 155(4), § 25 TDDDG) or the current consent-free approach is sufficient]
5. Analytics – only with consent
These are only written if you click “OK” in the cookie bar.
| Name | Purpose | Provider | Duration | Type |
|---|---|---|---|---|
sw_attr | Only with your consent: how you reached us (campaign parameters such as UTM, the name – not the value – of an ad click id, the referring site and the landing page; up to 6 touches). Only for our own statistics; if you sign up or contact us, the source is recorded with your account or your request. | Sayweek (first party) | 90 days | cookie · website and app |
sw_attr_pending | Until you decide in the cookie bar, keeps the landing page and the referrer in this tab, so it isn’t lost if you choose “OK”. Not used if you decline; gone when you close the tab. | Sayweek (first party) | until you close the tab | sessionStorage · website |
6. Consent and withdrawal
- On your first visit a small bar asks whether we may remember in a cookie how you found us. If you choose “No thanks”,
sw_attris not created; your choice is stored in thesw_consentcookie for 180 days. - If Global Privacy Control (GPC) is switched on in your browser, we treat it as a refusal: the bar is not even shown and
sw_attris not created. - You can change your choice at any time: the footer of every page has a “Cookie settings” link that reopens the bar. If you choose “No thanks” there, the
sw_attrcookie is deleted immediately. Withdrawing consent does not affect the lawfulness of processing before the withdrawal. - You can also delete or block cookies and local storage in your browser settings; without the strictly necessary ones, however, you cannot sign in.
7. Legal basis
Storage that is strictly necessary or created at your request (functional) is permitted without consent under the ePrivacy rules (Art. 5(3) ePrivacy Directive; in Hungary s. 155(4) of the Electronic Communications Act, in Germany § 25(2) TDDDG); the related processing is based on performance of the contract and our legitimate interest (Art. 6(1)(b) and (f) GDPR). The legal basis for sw_attr is your consent (Art. 6(1)(a) GDPR). Details: Privacy Policy.
8. The Sayweek browser extension
If you install the Sayweek browser extension, it does not use cookies but the browser’s own storage reserved for extensions (chrome.storage). Websites cannot read it, and it is deleted when you remove the extension.
| Name | Purpose | Provider | Duration | Type |
|---|---|---|---|---|
sayweek | The extension’s access token and the chosen workspace, so the extension can save ideas to Sayweek on your behalf. | Sayweek (first party) | until you sign out or remove the extension | chrome.storage.local |
connect | While you connect the extension: the check code (state) and the opened tab. | Sayweek (first party) | until the connection is done (at the latest until the browser closes) | chrome.storage.session |
9. Other data stored on your device
- Push notifications: if you switch them on, the browser or phone provides a subscription address (token) that we store on our server; you can switch them off at any time in the browser settings or in the app.
- Phone apps: the iOS and Android apps use the same cookies and storage in their built-in web view; the cookie bar and the website chat are not shown there.
- Operator area: the admin area keeps a few view settings of its own (
admin-kit:…,admin-templates:…); these are only created on the operator’s device.
10. Changes and contact
If we introduce a new cookie or storage key, we update this list before we start using it; if it needs consent, the bar asks you again. Questions: hello@sayweek.com.