Cookies and browser storage
Version 4 · last updated October 6, 2026
In short
nerdbox sets no advertising or audience-measurement cookie, and loads no third-party script. The only cookies and storage keys used are those strictly needed to sign you in, to protect sign-in, and to open a mailbox someone shared with you. They are exempt from consent (loi Informatique et Libertés, art. 82), which is why no cookie banner is shown.
The fonts are served by nerdbox itself: no request leaves for a font provider.
Full list
“Site” is nerdbox itself; “sign-in page” is the Auth0 page where you type your email and password; “Chrome extension” is nerdbox’s extension, if you installed it. This list is checked automatically: a test fails when the site sets a cookie or a storage key that is not in it.
| Name | Where | Set by | Purpose | Lifetime | Consent |
|---|---|---|---|---|---|
workbox-precache-v2-<site>cache storage | Site | nerdbox | Keeps the site’s own files (pages, scripts, fonts, icons) so that the installed app opens even offline. Never your mail nor your account. | Until the next version of the site | Exempt: needed for the app to work |
nerdbox.localelocal storage | Site | nerdbox | Remembers the language you chose with the selector, for your space. | Until you clear the site’s data | Exempt: a preference you chose |
nerdbox.sharesession storage | Site | nerdbox | Holds the key of the shared mailbox you opened, so that it stays open if you reload the page. Only on a shared page. | Until the tab is closed | Exempt: authentication |
nerdbox.refreshTokenextension session storage | Chrome extension | nerdbox | Keeps the extension signed in while the browser is open. Unreadable by the pages you visit. | Until the browser is closed or you sign out | Exempt: authentication |
nerdbox.codesextension session storage | Chrome extension | nerdbox | The last code received by each mailbox, shown in the extension’s window. | Until the browser is closed or you sign out | Exempt: needed for the app to work |
auth0.<client>.is.authenticatedcookie | Site | Auth0 | Remembers that you are signed in, to renew your session without asking again. | 1 day | Exempt: authentication |
_legacy_auth0.<client>.is.authenticatedcookie | Site | Auth0 | The same, for browsers that do not support the previous one. | 1 day | Exempt: authentication |
a0.spajs.txs.<client>session storage | Site | Auth0 | Holds the state of a sign-in in progress, to check it when you come back. | Until the sign-in completes | Exempt: authentication |
auth0, auth0_compatcookie | Sign-in page | Auth0 | Your session on the sign-in page. | 3 days | Exempt: authentication |
did, did_compatcookie | Sign-in page | Auth0 | Recognises your device to detect attacks on sign-in (repeated attempts, robots). | 1 year | Exempt: security of sign-in |
__cf_bmcookie | Sign-in page | Cloudflare | Tells people from robots, to protect the sign-in page. | 30 minutes | Exempt: security of sign-in |
Deleting them
Signing out deletes the cookies of the site. You can also delete every cookie and storage key from your browser’s settings, for this site and for the sign-in page: you will then have to sign in again.