Cookies and browser storage

Version 4 · last updated October 6, 2026

In short

nerdbox sets no advertising or audience-measurement cookie, and loads no third-party script. The only cookies and storage keys used are those strictly needed to sign you in, to protect sign-in, and to open a mailbox someone shared with you. They are exempt from consent (loi Informatique et Libertés, art. 82), which is why no cookie banner is shown.

The fonts are served by nerdbox itself: no request leaves for a font provider.

Full list

“Site” is nerdbox itself; “sign-in page” is the Auth0 page where you type your email and password; “Chrome extension” is nerdbox’s extension, if you installed it. This list is checked automatically: a test fails when the site sets a cookie or a storage key that is not in it.

Cookies and storage keys
NameWhereSet byPurposeLifetimeConsent
workbox-precache-v2-<site>
cache storage
SitenerdboxKeeps the site’s own files (pages, scripts, fonts, icons) so that the installed app opens even offline. Never your mail nor your account.Until the next version of the siteExempt: needed for the app to work
nerdbox.locale
local storage
SitenerdboxRemembers the language you chose with the selector, for your space.Until you clear the site’s dataExempt: a preference you chose
nerdbox.share
session storage
SitenerdboxHolds the key of the shared mailbox you opened, so that it stays open if you reload the page. Only on a shared page.Until the tab is closedExempt: authentication
nerdbox.refreshToken
extension session storage
Chrome extensionnerdboxKeeps the extension signed in while the browser is open. Unreadable by the pages you visit.Until the browser is closed or you sign outExempt: authentication
nerdbox.codes
extension session storage
Chrome extensionnerdboxThe last code received by each mailbox, shown in the extension’s window.Until the browser is closed or you sign outExempt: needed for the app to work
auth0.<client>.is.authenticated
cookie
SiteAuth0Remembers that you are signed in, to renew your session without asking again.1 dayExempt: authentication
_legacy_auth0.<client>.is.authenticated
cookie
SiteAuth0The same, for browsers that do not support the previous one.1 dayExempt: authentication
a0.spajs.txs.<client>
session storage
SiteAuth0Holds the state of a sign-in in progress, to check it when you come back.Until the sign-in completesExempt: authentication
auth0, auth0_compat
cookie
Sign-in pageAuth0Your session on the sign-in page.3 daysExempt: authentication
did, did_compat
cookie
Sign-in pageAuth0Recognises your device to detect attacks on sign-in (repeated attempts, robots).1 yearExempt: security of sign-in
__cf_bm
cookie
Sign-in pageCloudflareTells people from robots, to protect the sign-in page.30 minutesExempt: security of sign-in

Deleting them

Signing out deletes the cookies of the site. You can also delete every cookie and storage key from your browser’s settings, for this site and for the sign-in page: you will then have to sign in again.