Cookie and Tracking Policy

This policy explains which browser technologies AriaFlow uses, why they are used, and which storage the application needs and how you can choose optional diagnostics.

Version 0.1 draft · Updated 22 September 2026 · Pending legal review

No consent choice is recorded

Required storage enables sign-in. Optional diagnostics are your choice.

Scope and controller

This policy applies to the AriaFlow web application operated by AriaFlow GmbH, Große Bleiche 15, 55116 Mainz, Germany. Questions about privacy or this policy can be sent to admin@ariaflow.org.

Your choice and access

Sign-in and account security require browser storage. You may continue with only that required storage, or separately allow optional Sentry diagnostics. Declining all browser storage pauses access and opens the cookie-required page. Withdrawing diagnostic consent leaves your access intact and stops browser telemetry after a page reload. Withdrawal applies to future collection and does not erase telemetry collected before withdrawal.

Required technologies

Provider or keyPurposeDuration
ariaflow_cookie_consentRecords the current policy choice and version.180 days
Clerk __sessionShort-lived application session token.About 60 seconds; refreshed during use
Clerk __client, __client_uat and handshake cookiesSign-in continuity, session refresh and security.Session and browser dependent
Cloudflare challenge cookiesBot checks and sign-up challenge completion when invoked.Depends on the challenge
theme, sidebar_state and view preferencesRemembers chosen display settings, editor layout and dismissed guidance.Until cleared; sidebar state 7 days
Word add-in storageMaintains the Office add-in session and a deliberate sign-out choice.Until sign-out, replacement or clearing

Diagnostic telemetry

Only after you allow diagnostics, the browser initializes Sentry for error reporting, performance traces, browser profiling, and sampled session replay. Replay masks all rendered text and form inputs and blocks media. AriaFlow also disables Clerk product telemetry. Diagnostic data can include opaque user and workspace identifiers, route names, timing data, interaction events, device and browser information, stack traces, and a masked visual reconstruction of the interface around an error. Normal production replays are sampled at 5%; sessions with an error may be retained. Retention follows the configured AriaFlow Sentry project and remains to be confirmed in the Privacy Policy.

Changing your choice

Open Cookie and tracking settings from the account menu to allow or withdraw diagnostics. The app reloads to apply the new choice. If you decline required storage, the app redirects to the required-storage page. The choice cookie remains for 180 days so your refusal is remembered. Clearing browser storage removes the choice and may also sign you out or reset interface preferences.

Payments and external services

Billing actions may redirect workspace administrators to Stripe-hosted checkout or billing pages. Stripe processes payment and fraud-prevention data under its own browser technologies and privacy terms. Cloudflare may process traffic metadata for security, TLS, and bot protection, including during sign-up challenges.

Required storage is used to provide the sign-in and security functions requested by the user under Section 25(2) TDDDG. Optional diagnostic browser telemetry starts only with consent under Section 25(1) TDDDG and Article 6(1)(a) GDPR. You can withdraw diagnostic consent without losing access to AriaFlow.