You can use the public site and core account features without optional analytics. Essential session, security, and workspace storage cannot be disabled through our banner because the requested service depends on it.
1. What this policy covers
“Cookies” here includes browser cookies, local storage, and similar browser storage. Cookies are small values stored by a browser; they do not themselves contain uploaded document contents. This policy should be read with the Privacy Policy.
2. Essential storage
- Authentication and security. Better Auth session cookies under the
docaccessprefix keep you signed in, protect account requests, and expire after up to seven days. Shorter-lived cookie-cache values may be used to reduce repeated session lookups. - Workspace preference.
docaccess_wsremembers the active workspace for up to one year. Server-side authorization still verifies that the signed-in user belongs to the selected workspace. - Protected document access. After a correct password, a temporary
docaccess_share_cookie carries the server-issued proof only to that link's one-time session-exchange endpoint. It is deleted after the exchange and otherwise expires within 12 hours. The exchange creates two HttpOnly cookies beginning withdocaccess_shared_: one is restricted to that document's/d/page and one to its/api/shared/asset route. They contain an encoded share credential and, when needed, the server proof; they do not contain the password, are not available to browser scripts, are not sent to other site routes or analytics providers, and expire within 12 hours. - Operational protection. Infrastructure may use short-lived routing, load-balancing, or security storage required to deliver the service.
3. Optional analytics
When analytics is configured, DocAccessible first asks whether you want to allow it. Your choice is stored in local storage as docaccessible_analytics_consent. Google Analytics and PostHog load only when the value is granted. We do not use advertising cookies.
Google Analytics measures aggregate page use, referrals, deliberate actions, and web performance. Its configuration anonymizes IP information and disables Google signals and ad-personalization signals. PostHog receives deliberate product events and, after sign-in, may use an opaque internal user ID. Autocapture, page-view and page-leave capture, exception capture, and session recording are disabled. We do not intentionally send document content, form fields, names, or email addresses to either optional analytics provider.
4. Change or withdraw your choice
Current choice: No analytics choice saved
Disabling takes effect for future collection on this browser. Essential account and security storage remains available.
You can change or withdraw your choice above at any time. Disabling optional analytics stops future collection in this browser and resets the active PostHog identity when that client has loaded. You can also block or delete storage using browser settings. Blocking essential storage may prevent login, workspace selection, checkout, or protected-share access. Withdrawing consent does not undo aggregate measurements already received.
5. Connected-site script
The optional DocAccessible website-monitoring script installed by a customer is designed to report same-domain PDF discoveries without collecting visitor identity, form values, cookies, or full page content. It does not set a DocAccessible analytics cookie on the connected site. The site owner remains responsible for its own notice about scripts it deploys.
6. Contact
Ask a cookie or privacy question through the privacy contact form.