Legal

Cookies and trackers

Every cookie and storage key of the site, the client area and the console, with its purpose, duration and basis. No analytics, no advertising.

Last updated · 13 Sept 2026

01

The vesperid.com site

vid_lang: the language you read the site in, to bring you back to it on your next visit. Preference cookie, one year, no identifier. Basis: legitimate interest, exempt from consent as strictly necessary to the preference you express.

vid_theme: the display theme you chose (dark, light or the system setting), set as a cookie (one year) and kept under the same key in your browser’s local storage until you clear the site’s data. No identifier. Same basis.

The contact form loads the Turnstile anti-bot service of Cloudflare, Inc. from challenges.cloudflare.com. That service processes your IP address and browsing signals to tell a visitor from a bot and may set, on its own domain and for the short duration of the challenge, the technical cookies described in Cloudflare’s documentation; vesperid.com does not read them. Purpose: security and abuse prevention; basis: legitimate interest, exempt from consent. We keep your IP address only as a hash with your request.

No cookie is set for audience measurement, advertising, profiling or sharing with a third party, and no social network button loads third-party code.

02

The client area and the console

The client area (app.vesperid.com) and the staff console (admin.vesperid.com) use the following session cookies, all necessary to authentication and to the operation of the application; basis: performance of the contract and account security, exempt from consent. The console uses the same cookies under a name of its own.

Access token (__Secure-vid_at): authenticates every request; ten minutes, renewed while the session lasts. Refresh token (__Secure-vid_rt): renews the access token without signing in again; thirty days for a member, twelve hours for VesperID staff. Both are marked Secure and HttpOnly.

vid_s: indicates that a session is open, to show the resume screen rather than the sign-in page; thirty days. vid_org: the organisation last opened, to return to it directly; one year. vid_standalone: the application is installed on the device, to adapt the display; one year. vid_resumed: marks a session resume in progress; thirty seconds. vid_locale: the language of the area; one year.

Local storage: vid-lock-identity (client area) keeps your name and your masked address for the code lock screen, until you sign out; vid-admin-recent-orgs (console, VesperID staff only) keeps the five organisations last opened, per account. None of these keys holds a secret or detection data.

The panels’ sign-in pages load Cloudflare’s Turnstile anti-bot service under the same conditions as the contact form.

03

Error reporting

The client area and the console send their technical errors to Sentry (Functional Software, Inc.), on an ingestion endpoint located in the European Union. No cookie is set for this; messages are scrubbed before sending (never an email address, a token, a cookie, an IP address or a username), no session is recorded, and events are kept ninety days. Purpose: availability and correction; basis: legitimate interest.

04

Managing cookies

You may at any time delete the cookies and local storage data set by the site or the panels, or prevent them being stored, from your browser settings.

Without the language cookie, the language is determined on each visit from your browser preferences; without the display cookie, the dark theme is shown by default and your choice can be changed on every visit. Without the session cookies, the client area and the console cannot keep you signed in.

Technical server logs (IP address, requested page, timestamp, user agent), separate from any audience measurement, are kept six months for security purposes, then deleted.