Cookie and Local Storage Notice
Version 1.0 · Effective and last updated: 4 August 2026
This Notice explains how the Assertum website and local MCP/CLI store or access information on your browser or device. It should be read with our Privacy Notice.
1. Summary
Assertum currently uses only storage that is necessary to sign you in, maintain an authenticated session and remember the local CLI configuration you choose.
We do not use advertising cookies, behavioural-tracking cookies, analytics cookies, an installation/device identifier, or a local analytics identifier. Our first-party service events are sent by the authenticated Service and stored server-side; they do not require an analytics cookie or local analytics ID.
2. Browser authentication cookies
| Name | Where it is stored | Purpose | Duration and control | Classification |
|---|---|---|---|---|
access_token | Your browser as an HTTP-only cookie, proxied between the Assertum public site and backend | Authenticate requests and keep your signed-in session working | Until the token/cookie expires or the session is ended; blocking or deleting it signs you out or prevents authenticated use | Strictly necessary |
refresh_token | Your browser as an HTTP-only cookie, proxied between the Assertum public site and backend | Obtain a new access token without asking you to sign in for every request | Until expiry, sign-out or deletion; the database stores only a SHA-256 hash rather than the raw refresh token | Strictly necessary |
“HTTP-only” means browser scripts cannot read the cookie directly. This reduces — but does not eliminate — credential risk.
The public Next.js site does not use these cookies for advertising or tracking. It proxies them for authentication and displays the authenticated account response.
3. Local CLI storage and access
| Item | Where it is stored or accessed | Purpose | Duration and control | Classification |
|---|---|---|---|---|
| Authentication credential or token cache | Locally on your device, using the CLI’s available credential-storage mechanism | Authenticate the CLI and avoid requiring a new Google sign-in for every operation | Until expiry, revocation, sign-out, local deletion or removal of the CLI data | Strictly necessary |
| User configuration | Locally on your device | Remember the settings you choose so the CLI can operate as configured | Until you change or delete the configuration or remove the CLI data | Strictly necessary |
| Per-user fingerprint key | Delivered through an authenticated session and held in memory or protected credential storage as needed | Allow the CLI to create the within-account test-structure fingerprint locally | Controlled by authenticated delivery and key version/rotation; not used as an installation, device or analytics identifier | Strictly necessary for duplicate/quota integrity when that feature is used |
The CLI does not store an installation identifier, device identifier or local analytics identifier. Test content remains local, except that the CLI sends the limited fingerprint and event properties described in the Privacy Notice.
4. Why there is no consent banner
Under applicable ePrivacy rules, consent is generally required before storing or accessing information on terminal equipment unless the operation is strictly necessary to provide a service the user expressly requested or another exemption applies.
The browser cookies and CLI operations listed above are used only to provide authentication, the locally configured Service and its quota-integrity function. Assertum therefore treats them as strictly necessary and does not show a cookie-consent banner for version 1.0.
This conclusion applies only to the operations listed in this Notice. If we introduce analytics, advertising, personalisation, device identification or other browser or CLI storage that is not strictly necessary, we will ask for your consent before using it.
5. Your controls
You can use browser settings to view or delete cookies and to block future cookies. If you block or delete Assertum’s authentication cookies, you will be signed out or unable to use authenticated website features.
You can sign out, revoke the session, delete the local CLI credential/configuration through the applicable local controls, or remove the CLI data from your device. Removing required credentials or configuration may stop the CLI from working until you authenticate or configure it again.
You can also manage or remove the Google Sign-In connection through your Google Account. Removing the Google connection stops future sign-in access but does not by itself delete data already held by Assertum; use Assertum’s account-deletion control or contact us for that.
6. Changes
If our terminal-storage practices change, we will update this Notice, its version and its date. If a new operation requires consent, we will request that consent before using it.
7. Contact
Questions about cookies or local storage can be sent to support@assertum.ai. Assertum Ltd., a company registered in the Republic of Cyprus.