About this notice
This notice explains how Annot8 uses cookies, localStorage, sessionStorage, and similar browser technologies. It covers our own website and dashboard and the Annot8 widget when a customer installs it on another website. The customer operating that website is responsible for its own consent banner and for describing its use of Annot8.
Website and dashboard storage
- Clerk authentication cookies and related storage: authenticate users, protect sessions, prevent abuse, and support sign-in. Duration depends on session and browser settings.
- annot8-ui-theme: remembers the user's light or dark dashboard preference until it is changed or browser storage is cleared.
- activeOrgId: remembers the last selected workspace until it is changed or browser storage is cleared.
- annot8:cookie-consent:v1: records whether the visitor allowed optional Analytics so the site can respect the choice on later visits.
- Dashboard view, onboarding, AI-panel, and notification preferences: remember choices requested by the signed-in user until changed or cleared.
- Security and deployment providers may set or access strictly necessary identifiers and request metadata to deliver and protect the Service.
These technologies support a service or preference requested by the user. Annot8 does not use advertising cookies on its website and does not sell or share browser data for targeted advertising.
Widget operation and live chat
- annot8-widget-position and widget theme/pin preferences: remember where a visitor placed the launcher and how the widget is displayed.
- a8_visitor_id: a pseudonymous identifier used to reconnect a visitor to live-chat messages. It remains until the widget's origin storage is cleared.
- a8_visitor_name and a8_visitor_email: remember contact details the visitor chose to submit for live chat until cleared.
- Origin-validation session records: short-lived server-side records that bind public widget actions to an allowed website origin; they expire after two hours.
Whether these technologies are strictly necessary depends on how the customer deploys the widget and the visitor feature requested. Customers must obtain consent before loading or using them where local law requires it and should provide a way to withdraw consent.
Optional Analytics on annot8.app
When a visitor allows Analytics, annot8.app uses Google Analytics 4 and PostHog for acquisition, page-view, product-funnel, and web-vitals measurement. Both remain off when their deployment variables are absent. Advertising signals, PostHog autocapture, and session replay are disabled.
- Google Analytics may set _ga and _ga_* identifiers after consent to distinguish browser sessions and measure page views and intentional product events.
- annot8:posthog-distinct-id:v1 (localStorage): a pseudonymous PostHog event identifier created only after consent and removed when Analytics is withdrawn.
- annot8:launch-attribution:v1 (sessionStorage): the first UTM campaign values, landing path, and external referrer hostname for the current browser session.
- Intentional funnel events include CTA, signup, workspace/project setup, installation, first feedback, integration, AI/Agent Fix, upgrade, checkout, and web-vitals milestones. They may carry opaque account, workspace, project, thread, run, or checkout identifiers needed to connect those steps. Form contents, feedback text, email addresses, and full query strings are not sent.
Optional customer Analytics
Annot8 Analytics is off by default. It starts only when a customer enables Analytics and the host site explicitly sends analyticsConsent=true after obtaining any required consent.
- ca_visitor_id (localStorage): pseudonymous visitor measurement across sessions; remains until cleared.
- ca_session_id and ca_session_start (sessionStorage): group activity into a session, logically expiring after 30 minutes of inactivity and otherwise ending with the browser session.
- Server-side Analytics events and sessions: page/click/scroll/error and device categories associated with those pseudonymous IDs; retained for no more than 13 months.
Analytics is used for aggregate product and website measurement, not targeted advertising. Rejecting Analytics must not prevent access to the core feedback feature.
Controls and withdrawal
- Use Cookie settings in the Annot8 footer to allow, reject, or withdraw Analytics on annot8.app.
- Use the customer website's consent controls to accept, reject, or withdraw optional widget Analytics.
- Customers should re-initialize the widget with analyticsConsent=false and remove ca_visitor_id, ca_session_id, and ca_session_start when consent is withdrawn.
- Browser settings can block cookies or clear cookies, localStorage, and site data. Blocking authentication storage may prevent sign-in; clearing widget storage may reset preferences and live-chat continuity.
- Because Annot8 does not sell/share data for targeted advertising, Global Privacy Control and Do Not Track signals do not change an advertising profile. We honor legally applicable browser signals if our practices change.
Changes and contact
We update this notice when storage names, purposes, providers, or durations materially change. Questions may be sent to privacy@annot8.app.
- privacy@annot8.app
- Website
- annot8.app