Cookie Policy

Effective date: 2026-08-24

This page lists everything Attia stores in your browser and everything Attia reads back from it. For each entry it says what the entry is for, who set it, how long it lasts, and which consent category it falls in.

Norwegian law ties consent to storing or reading data on your device (ekomloven § 3-15), not to collecting data as such. So the question here is a narrow one. What does Attia put on your device, and why.

Attia AS, Solheimgata 1a, 0267 Oslo, Norway. Questions go to hello@attia.app.

The three categories

Necessary. Either the surface breaks without it, or you set it yourself by an explicit action and it records only that choice.

Statistics. Measures how the product is used or how it performs. Nothing in it identifies you for advertising.

Marketing. Advertising, cross-site profiling, remarketing.

Everything on this page is necessary. We store nothing at all in the statistics category, and nothing at all in the marketing category. There is no Google Analytics, no Meta or TikTok pixel, no Hotjar, no PostHog, no Segment, no advertising cookie, no heatmap and no session replay.

Cookies

Every cookie set on our sites is necessary. A stands for an identifier that varies by account, workspace or project. Clerk also writes suffixed copies of its own cookies, such as __session_abc123.

CookieSet byWhat it doesHow long it lasts
attia_consentAttiaYour answer to the cookie banner, so you are not asked again and so only what you allowed can run365 days
exponential-ui.themeAttiaYour theme choice and your current system colour scheme, so the first paint uses the right colours instead of flashing365 days
sidebar_stateAttiaWhether the app sidebar is expanded or collapsed7 days
attia.last-workspaceAttiaThe workspace you visited last, so signing in returns you where you left off. It grants no access on its own365 days
attia-onboarding-last-stepAttiaThe onboarding step you reached, so a reload resumes there14 days
candidate-apply-sign-inAttiaHolds your email address between "send code" and "verify code" so it never travels in a URL15 minutes
sb-…-auth-tokenSupabaseYour session in the candidate portalUntil you close the browser
__session, __client_uatClerkThe signed-in session, and the timestamp that lets our server tell signed in from signed out without a round tripSet by Clerk; the session token rotates about once a minute
__refreshClerkMints a new session token so you stay signed inSet by Clerk
__clerk_db_jwtClerkA further handle on the same sessionSet by Clerk
__clerk_handshake, __clerk_handshake_nonce, __clerk_redirect_countClerkCarry a session refresh through its redirect and stop it loopingSeconds
NEXT_LOCALEAttiaThe language you chose with the language switcher, so your next visit opens in it1 year

Storage in your browser

Cookies travel to the server with every request. The entries below stay in the browser and are read only by the code that wrote them. Most of them exist because you clicked, dragged or typed something and the surface should still look that way when you come back.

localStorage

Entries marked "signed-in app" are written only inside Attia itself, never on the public site and never on a career site.

EntrySet byWhat it doesHow long it lasts
exponential-ui.themeAttiaThe full theme record. The cookie above is the server's copy of itUntil you clear it
exponential-ui.saved-colors.…AttiaUp to 18 colours you saved in the theme editorUntil you clear it
exponential-ui:app-sidebar:…:v1AttiaWhether a given sidebar is openUntil you clear it
react-resizable-panels:…, side-panel-width, attia:agent-panel-sizeAttiaThe widths you set by dragging a divider (signed-in app)Until you clear it
exponential-ui:view-editor-icons:v1, exponential-ui:resource-create-dialog-icons:v1, exponential-ui:data-table-row-icons:v1, exponential-ui:data-table-json-title-icons:v1, exponential-ui:resource-data-details-panel:view-icon, attia:new-team-icons:v1, attia:team-general-icons:v1, attia:career-site-icons:v1, workspace-document-comment-reactionsAttiaThe icons and emoji you reached for most recently, so each picker opens on them (signed-in app)Until you clear it
attia.view-prefs:…AttiaYour columns, grouping and ordering in a table (signed-in app)Until you clear it
attia.job-create-draft:…AttiaA job you started writing and have not saved, so closing the dialog does not lose it (signed-in app)Until you clear it or discard the draft
attia.search.recent.…AttiaYour last ten searches in a workspace, shown back to you (signed-in app)Until you clear it
attia:team-resources-collapsed:…AttiaWhich groups you collapsed in the sidebar (signed-in app)Until you clear it
attia-plan-cap:…:applicationsReadOnly:v1AttiaThat you dismissed the plan limit notice, so it stays dismissed (signed-in app)Until you clear it
attia:chat-tabs:…AttiaWhich agent chat tabs you have open and which have unread messages (signed-in app)Until you clear it
attia:onboarding:lastStep, attia:onboarding:workspaceAttiaHow far you got in onboarding and the workspace you just created, so a reload resumes thereCleared when onboarding finishes
attia.local-data.session-scope.v1, attia.local-data.last-workspace-id.v1:…, attia.local-data.last-user-id, attia.local-data.database-name.v1:…AttiaWhich account and workspace the offline copy described below belongs to. They are what lets signing out prove it deleted everything (signed-in app)Until you clear it
recruitr:qc:…:v1AttiaA saved copy of data you had already loaded, so a return visit renders straight away (signed-in app)12 hours
career-site-theme:…AttiaYour light or dark choice on a career site that follows the system theme, kept per site. It is the only entry a career site writes for itself. Clerk's sign-in script, which our shared layout loads on every page, still writes __clerk_environment here as well; it holds Clerk's own configuration and nothing about youUntil you clear it
__clerk_environmentClerkClerk's own configuration, cached so the sign-in code does not fetch it on every loadUntil you clear it

sessionStorage

These belong to a single browser tab and are gone when you close it. Every one of them is written inside the signed-in app or during onboarding.

EntrySet byWhat it does
attia.settings.backNavAttiaWhere to send you back to when you leave settings
attia.account-switch.focus-mainAttiaThat you just switched account, so keyboard focus lands in the right place
attia:onboarding:plan, attia:onboarding:periodAttiaThe plan and billing period you picked, carried across the onboarding steps
attia:clerk-org-sync-attempt:…AttiaThat a sign-in step already ran in this tab, so a failure does not loop
recruit-io:workspace-invite-link:v1:…AttiaThe invite link you just created, token and all, so you can copy it. The server does not hand it out a second time

IndexedDB

The signed-in app keeps a local copy of the records you already have access to, so lists open without waiting for the network. It lives in two databases, attia-local:u:… for your own data and attia-local:w:… for a workspace you opened. Both are deleted when you sign out, switch workspace or lose access. Nothing outside the signed-in app creates them.

Statistics

Nothing. Clerk's sign-in code used to write clerk_telemetry_throttler to rate-limit telemetry about its own software. We turned that telemetry off, so the entry is no longer written and the beacons are no longer sent. If you have it from an earlier visit, clearing site data removes it.

Marketing

Nothing. Attia runs no advertising, no cross-site profiling and no remarketing, and stores nothing on your device for any of them.

Who receives the data

A cookie goes back to whoever set it: ours to Attia, Clerk's to Clerk, Supabase's to Supabase. Clerk provides sign-in for the Attia app and Supabase provides the candidate portal session. Both process the data under contract with us.

The localStorage, sessionStorage and IndexedDB entries do not travel anywhere on their own.

What does not touch your device

Our error monitoring (Sentry) and our page-speed measurement (Vercel Speed Insights) write nothing to your browser at all: no cookie, no storage entry, no database. We checked both in the code we ship and on a live page. Speed Insights runs on Attia's own pages only: it is not loaded on a career site or in the candidate portal. What they do collect is covered by the Privacy Policy.

Changing or removing what is stored

Clearing site data for attia.app in your browser removes every entry on this page. You will be signed out, and Attia will forget your theme, your layout and any unsaved draft.

Your browser can also block cookies for this site. Because everything here is either necessary or a preference you set yourself, blocking them does not stop any tracking. It stops you signing in.

To ask what we hold, to object, or to have something removed, write to hello@attia.app. The Privacy Policy covers the rest of what we process and the rights you have over it.