Cookie Policy
Effective date: 2026-08-24
This page lists everything Attia stores in your browser and everything Attia reads back from it. For each entry it says what the entry is for, who set it, how long it lasts, and which consent category it falls in.
Norwegian law ties consent to storing or reading data on your device (ekomloven § 3-15), not to collecting data as such. So the question here is a narrow one. What does Attia put on your device, and why.
Attia AS, Solheimgata 1a, 0267 Oslo, Norway. Questions go to hello@attia.app.
The three categories
Necessary. Either the surface breaks without it, or you set it yourself by an explicit action and it records only that choice.
Statistics. Measures how the product is used or how it performs. Nothing in it identifies you for advertising.
Marketing. Advertising, cross-site profiling, remarketing.
Everything on this page is necessary. We store nothing at all in the statistics category, and nothing at all in the marketing category. There is no Google Analytics, no Meta or TikTok pixel, no Hotjar, no PostHog, no Segment, no advertising cookie, no heatmap and no session replay.
Cookies
Every cookie set on our sites is necessary. A … stands for an identifier that varies by account, workspace or project. Clerk also writes suffixed copies of its own cookies, such as __session_abc123.
| Cookie | Set by | What it does | How long it lasts |
|---|---|---|---|
attia_consent | Attia | Your answer to the cookie banner, so you are not asked again and so only what you allowed can run | 365 days |
exponential-ui.theme | Attia | Your theme choice and your current system colour scheme, so the first paint uses the right colours instead of flashing | 365 days |
sidebar_state | Attia | Whether the app sidebar is expanded or collapsed | 7 days |
attia.last-workspace | Attia | The workspace you visited last, so signing in returns you where you left off. It grants no access on its own | 365 days |
attia-onboarding-last-step | Attia | The onboarding step you reached, so a reload resumes there | 14 days |
candidate-apply-sign-in | Attia | Holds your email address between "send code" and "verify code" so it never travels in a URL | 15 minutes |
sb-…-auth-token | Supabase | Your session in the candidate portal | Until you close the browser |
__session, __client_uat | Clerk | The signed-in session, and the timestamp that lets our server tell signed in from signed out without a round trip | Set by Clerk; the session token rotates about once a minute |
__refresh | Clerk | Mints a new session token so you stay signed in | Set by Clerk |
__clerk_db_jwt | Clerk | A further handle on the same session | Set by Clerk |
__clerk_handshake, __clerk_handshake_nonce, __clerk_redirect_count | Clerk | Carry a session refresh through its redirect and stop it looping | Seconds |
NEXT_LOCALE | Attia | The language you chose with the language switcher, so your next visit opens in it | 1 year |
Storage in your browser
Cookies travel to the server with every request. The entries below stay in the browser and are read only by the code that wrote them. Most of them exist because you clicked, dragged or typed something and the surface should still look that way when you come back.
localStorage
Entries marked "signed-in app" are written only inside Attia itself, never on the public site and never on a career site.
| Entry | Set by | What it does | How long it lasts |
|---|---|---|---|
exponential-ui.theme | Attia | The full theme record. The cookie above is the server's copy of it | Until you clear it |
exponential-ui.saved-colors.… | Attia | Up to 18 colours you saved in the theme editor | Until you clear it |
exponential-ui:app-sidebar:…:v1 | Attia | Whether a given sidebar is open | Until you clear it |
react-resizable-panels:…, side-panel-width, attia:agent-panel-size | Attia | The widths you set by dragging a divider (signed-in app) | Until you clear it |
exponential-ui:view-editor-icons:v1, exponential-ui:resource-create-dialog-icons:v1, exponential-ui:data-table-row-icons:v1, exponential-ui:data-table-json-title-icons:v1, exponential-ui:resource-data-details-panel:view-icon, attia:new-team-icons:v1, attia:team-general-icons:v1, attia:career-site-icons:v1, workspace-document-comment-reactions | Attia | The icons and emoji you reached for most recently, so each picker opens on them (signed-in app) | Until you clear it |
attia.view-prefs:… | Attia | Your columns, grouping and ordering in a table (signed-in app) | Until you clear it |
attia.job-create-draft:… | Attia | A job you started writing and have not saved, so closing the dialog does not lose it (signed-in app) | Until you clear it or discard the draft |
attia.search.recent.… | Attia | Your last ten searches in a workspace, shown back to you (signed-in app) | Until you clear it |
attia:team-resources-collapsed:… | Attia | Which groups you collapsed in the sidebar (signed-in app) | Until you clear it |
attia-plan-cap:…:applicationsReadOnly:v1 | Attia | That you dismissed the plan limit notice, so it stays dismissed (signed-in app) | Until you clear it |
attia:chat-tabs:… | Attia | Which agent chat tabs you have open and which have unread messages (signed-in app) | Until you clear it |
attia:onboarding:lastStep, attia:onboarding:workspace | Attia | How far you got in onboarding and the workspace you just created, so a reload resumes there | Cleared when onboarding finishes |
attia.local-data.session-scope.v1, attia.local-data.last-workspace-id.v1:…, attia.local-data.last-user-id, attia.local-data.database-name.v1:… | Attia | Which account and workspace the offline copy described below belongs to. They are what lets signing out prove it deleted everything (signed-in app) | Until you clear it |
recruitr:qc:…:v1 | Attia | A saved copy of data you had already loaded, so a return visit renders straight away (signed-in app) | 12 hours |
career-site-theme:… | Attia | Your light or dark choice on a career site that follows the system theme, kept per site. It is the only entry a career site writes for itself. Clerk's sign-in script, which our shared layout loads on every page, still writes __clerk_environment here as well; it holds Clerk's own configuration and nothing about you | Until you clear it |
__clerk_environment | Clerk | Clerk's own configuration, cached so the sign-in code does not fetch it on every load | Until you clear it |
sessionStorage
These belong to a single browser tab and are gone when you close it. Every one of them is written inside the signed-in app or during onboarding.
| Entry | Set by | What it does |
|---|---|---|
attia.settings.backNav | Attia | Where to send you back to when you leave settings |
attia.account-switch.focus-main | Attia | That you just switched account, so keyboard focus lands in the right place |
attia:onboarding:plan, attia:onboarding:period | Attia | The plan and billing period you picked, carried across the onboarding steps |
attia:clerk-org-sync-attempt:… | Attia | That a sign-in step already ran in this tab, so a failure does not loop |
recruit-io:workspace-invite-link:v1:… | Attia | The invite link you just created, token and all, so you can copy it. The server does not hand it out a second time |
IndexedDB
The signed-in app keeps a local copy of the records you already have access to, so lists open without waiting for the network. It lives in two databases, attia-local:u:… for your own data and attia-local:w:… for a workspace you opened. Both are deleted when you sign out, switch workspace or lose access. Nothing outside the signed-in app creates them.
Statistics
Nothing. Clerk's sign-in code used to write clerk_telemetry_throttler to rate-limit telemetry about its own software. We turned that telemetry off, so the entry is no longer written and the beacons are no longer sent. If you have it from an earlier visit, clearing site data removes it.
Marketing
Nothing. Attia runs no advertising, no cross-site profiling and no remarketing, and stores nothing on your device for any of them.
Who receives the data
A cookie goes back to whoever set it: ours to Attia, Clerk's to Clerk, Supabase's to Supabase. Clerk provides sign-in for the Attia app and Supabase provides the candidate portal session. Both process the data under contract with us.
The localStorage, sessionStorage and IndexedDB entries do not travel anywhere on their own.
What does not touch your device
Our error monitoring (Sentry) and our page-speed measurement (Vercel Speed Insights) write nothing to your browser at all: no cookie, no storage entry, no database. We checked both in the code we ship and on a live page. Speed Insights runs on Attia's own pages only: it is not loaded on a career site or in the candidate portal. What they do collect is covered by the Privacy Policy.
Changing or removing what is stored
Clearing site data for attia.app in your browser removes every entry on this page. You will be signed out, and Attia will forget your theme, your layout and any unsaved draft.
Your browser can also block cookies for this site. Because everything here is either necessary or a preference you set yourself, blocking them does not stop any tracking. It stops you signing in.
To ask what we hold, to object, or to have something removed, write to hello@attia.app. The Privacy Policy covers the rest of what we process and the rights you have over it.