Get the beta

Builds · Legal

Cookies and local storage

Applies to: builds.one, app.builds.one, and the Builds apps (iPhone, iPad, Android preview, Windows preview, the Mac's Builds server).

The short version

  • builds.one (this site) sets no cookie and stores nothing on your device.
  • app.builds.one and the apps store what they need to sign you in, remember your settings and open your conversations quickly. None of it tracks you across other sites or apps.
  • Crash reports and usage counts (PostHog, EU) run only after you say yes, asked on each device; then they keep a random id on that device. Saying no changes nothing else.

The rule (ePrivacy Directive Art. 5(3), in Ireland S.I. No. 336/2011 Regulation 5, in Hungary the electronic communications act, Eht. § 155(4)): we may store or read something on your device without asking only if it is strictly necessary for a service you asked for. Everything else needs your consent first, and refusing is as easy as agreeing. The rule covers local storage, app storage, SDKs and service workers, not just cookies, so all of them are listed.

Cookies on app.builds.one

All are ours, on app.builds.one only (no Domain), HttpOnly (the page's scripts cannot read them), Secure (HTTPS only) and SameSite=Lax.

NameWhat it doesHow longKind
bo_sessionKeeps you signed in on the web7 days, renewed as you use it; cleared when you sign outStrictly necessary
bo_sso_stateA one-time random value proving the sign-in that comes back is the one you started10 minutes; cleared when the sign-in endsStrictly necessary
bo_app_flowCarries the app's sign-in from the browser sheet back to the app10 minutesStrictly necessary
bo_app_returnRemembers that a DispatChai link was started from the app, so it returns there10 minutesStrictly necessary
bo_dc_pkceProtects the link to your DispatChai account (an encrypted one-time value)10 minutesStrictly necessary
bo_dc_nextRemembers where to return after linking DispatChai10 minutesStrictly necessary
bo_rootAn old setting from the retired web app; only ever deleted nowDeleted on sight—

Signing in also uses Digital One's cookies on digital1.one (Digital One ID, the sign-in shared by Digital One's products, at ai.digital1.one). They are set by the same company:

NameWhereWhat it doesHow longKind
d1sidAll of digital1.one; HttpOnly, Secure, SameSite=LaxYour Digital One sign-in, shared by Digital One's products1 year after a Google, GitHub, Microsoft or Apple sign-in, or an email-code sign-in with "Remember me on this device" ticked (the default); 7 days if you untick it. Signing out ends the session behind it; the cookie itself stays until it expires but no longer signs anyone inStrictly necessary
d1inviteAll of digital1.one; HttpOnly, Secure, SameSite=LaxCarries an invitation code through sign-up10 minutesStrictly necessary
__Host-zitadel.useragentid.digital1.one only; HttpOnly, Secure, SameSite=LaxRecognises your browser at Digital One's identity server during a Google, GitHub, Microsoft or Apple sign-in1 yearStrictly necessary
__Host-zitadel.login.csrfid.digital1.one only; HttpOnly, Secure, SameSite=LaxProtects that sign-in against forged requests12 hoursStrictly necessary
d1_return (local storage)ai.digital1.oneWhere to send you back after signing inRemoved once you are signed in; followed only within 10 minutesStrictly necessary
d1_analytics (local storage)ai.digital1.oneYour answer to the sign-in page's analytics question (yes or no), so it is not asked againUntil you clear the site's data; Analytics settings on the sign-in page changes itStrictly necessary (it keeps your choice); stored only once you answer
ph_<key>_posthog (a cookie, and a copy in local storage)All of digital1.onePostHog (EU) usage analytics of the sign-in page itself: a random id, the pages and clicks there; linked to your Digital One account id once you are signed in1 yearNot strictly necessary — set only after you say yes on the sign-in page

The sign-in page asks before it counts anything: a bar at its foot asks Yes or No, and until you say yes, PostHog is not loaded there and nothing of it is stored or sent. Signing in works the same either way. Analytics settings on the page asks again; taking a yes back removes PostHog's cookie and id from your browser. The page serves its fonts from its own server, so no font service receives your network address. If you pick Google, GitHub, Microsoft or Apple on the sign-in page, that company's own cookies apply on its own pages.

Stored by the web app (local storage, service worker)

WhatWhyHow longKind
Your choices for this browser: theme, accent, Enter sends, haptics, which organisation you were looking at, panel widths, dismissed banners, update settings (keys starting builds.)So the app looks and behaves the way you set itUntil you clear the site's dataStrictly necessary for features you set yourself
Where you were (the last screen), and whether the app was mid-updateTo reopen where you left off, and recover from a failed updateUntil replacedStrictly necessary
A copy of the conversations you recently opened (up to about 600 KB of text each) and your conversation listSo they open at once and show while you are offlineUntil replaced, or until you clear the site's data. Signing out does not remove them yet: on a shared computer, clear the site's data after you sign outStrictly necessary
An invitation's code, only while you sign in to accept itTo finish accepting after the sign-in round tripRemoved once accepted or no longer validStrictly necessary
A notification's answer waiting to be sentSo an answer you gave from a notification is not lostUntil sentStrictly necessary
The service worker /sw.js and its small cache (builds-unread)Delivers notifications and keeps the app icon's unread countUntil you uninstall the web app or clear the site's dataStrictly necessary for notifications you turned on
PostHog's random id (ph_… in local storage)Crash reports and usage countsUntil you clear the site's dataNot strictly necessary — stored only after you say yes

Stored by the apps (iPhone, iPad, Android, Windows, Mac)

WhatWhereWhyKind
Your sign-in tokeniPhone and iPad: the Keychain, this device only. Android preview: the app's storage, encrypted with a key held in the Android Keystore. The Windows and Mac apps keep the web sign-in cookie above, in their own window's cookie storeKeeps you signed in. Signing out deletes it and signs the device out at our serverStrictly necessary
The same choices, last screen, conversation copies and pending answers as the web appThe app's own storageAs aboveStrictly necessary
Whether the app was on screen when it last stoppedThe app's own storageTo tell a crash from a normal close, so the app reopens on your list rather than the screen that crashed; if you said yes to crash reports, also to report that it ended abnormallyStrictly necessary; reported only with your consent
PostHog's random id and queued reportsThe app's own storageCrash reports and usage countsNot strictly necessary — stored only after you say yes
Face IDHandled by iOS; we never see your face dataTo confirm risky actionsStrictly necessary for the protection you use

Your choices

  • Crash reports and usage counts: you are asked once on each device, and nothing is sent or stored for them until you say yes. "No" changes nothing else in the app. Settings → This device → Share crash reports and usage counts changes your answer at any time; switching it off removes PostHog's id from the device.
  • The sign-in page's own analytics (Digital One ID, ai.digital1.one): asked there, in its own bar, separately from the app. Analytics settings on that page changes your answer at any time.
  • Everything else is needed for the app to work. You can still remove it: sign out (removes the sign-in), delete the app, or clear the site's data in your browser's settings. You will then have to sign in again.

Changes

If we add anything to these lists, we update this page first. Anything not strictly necessary is added only with your consent.

Contact: info@digital1.one · Digital One Technology Consulting Limited, 6-9 Trinity Street, Dublin 2, D02 EY47, Ireland.

Last updated