Cookie Policy

What cookies and similar storage are

Cookies are small text files stored by your browser; we also use comparable browser storage (localStorage and sessionStorage). Below are the cookies and the main browser storage we use, why, how long they last and their legal basis, in line with Belgian Data Protection Authority guidance. A fuller technical inventory is available on request.

Essential to deliver a service you asked for:

  • archimind_refresh — cookie (Path=/api/auth, HttpOnly, Secure, SameSite=Strict). Keeps you signed in (server-side session refresh). 30 days. ArchiMind only.
  • archimind_consent — cookie on .archimind.be. Stores your cookie-consent choice and the policy version, so we stop re-prompting. ~6 months.
  • archimind_pending_terms_ack — localStorage. Briefly bridges your signup Terms/Privacy acknowledgement to your first sign-in, then cleared.

Functional — remember your choices and protect your work

Set by ArchiMind to keep the app usable; no third parties, held only in your browser:

  • Language and theme (archimind-language, archimind-theme) — your UI language and light/dark choice. Persistent.
  • auth-storage — localStorage; a session-restore mirror of your user profile (id, email, name, role) — no tokens. Until logout. ArchiMind only.
  • chat-storage / template-chat-storage — localStorage; the project- and template-assistant chat transcripts, so a conversation survives a reload. Persistent until cleared; contain your own content.
  • project-wizard — localStorage; an in-progress project-creation draft, plus the architectProfile prefill. Persistent until completed.
  • archimind.lastVisitedProject, metre-active-group-storage, archimind.editor-view-mode.v1, archimind.editor-tree-filters.v1, and a local editor backup of unsaved edits — localStorage; editor/navigation preferences and data-loss protection. Persistent until cleared. ArchiMind only.
  • bestek-import: followed by the workspace ID — sessionStorage; remembers an in-flight import so you can resume it. Cleared when the browser tab closes.

These in-app tools run only after you enable them in the consent banner or below, on the basis of your consent (art. 6(1)(a) GDPR):

  • PostHog (EU, Frankfurt) — product analytics and session replay. Sets ph_* cookies and localStorage (including ph_archimind_first_touch, which records the channel that brought you). We send only a pseudonymous user ID and a pseudonymous workspace ID — never your name, email, firm or project content — and replay masks all text and inputs. This is individual, pseudonymous measurement, not merely aggregate statistics.
  • Sentry (EU) — browser error diagnostics. Crash reports limited to the same pseudonymous ID and technical context; sets no cookies.

Server-side logging and backend error diagnostics run under our legitimate interest (see the Privacy Policy), separate from these browser cookies — they are not switched by this consent. Separately, ph_archimind_projected_events (a localStorage queue of our own business-milestone records) exists to make our records reliable, not to track browsing, and is not part of the consent-gated analytics.

Your decision is stored for about 6 months in the archimind_consent cookie (valid across archimind.be subdomains) together with the policy version it was made under; a material change re-opens the banner. You can change or withdraw your choice at any time from the cookie banner or your in-app privacy settings — withdrawal stops all optional collection immediately and deletes the ph_* cookies and storage. On the public marketing pages only the strictly-necessary and functional storage listed above is set (including your language and theme choice); visits to those pages are measured without cookies or any device storage — see 'Visitor measurement on our marketing site' below.

Visitor measurement on our marketing site — nothing stored on your device

On our public marketing pages we measure visits with PostHog (EU, Frankfurt) in cookieless mode: page views, page leaves and clicks on the sign-up and log-in links, together with the referring site and any campaign parameters in the page address. Nothing is stored on or read from your device — no cookies, no localStorage — which is why these pages show no consent banner, and no visitor profile is built: each visit is measured on its own, pseudonymously. Legal basis: our legitimate interest in understanding how our public pages are found and used (art. 6(1)(f) GDPR). You can object at any time — see the Privacy Policy or write to contact@archimind.be. These measurement events are kept by PostHog for up to 12 months, like the other analytics events listed below.

Your rights

You can request access to or deletion of the analytics data linked to your pseudonymous user ID and workspace ID; see the Privacy Policy for the full list of GDPR rights and how to lodge a complaint with the Belgian Data Protection Authority. Contact contact@archimind.be.

Retention at our processors

Analytics events are retained by PostHog for up to 12 months and masked session replays for up to 1 month; browser error reports are retained by Sentry for 90 days. Access is restricted to ArchiMind administrators under each provider's access controls and our data-processing agreements.

Changes

When the cookies or storage we use change, this page is updated and material changes are announced.

Contact

Questions about cookies: contact@archimind.be.