What this policy covers
Cookies are small text files stored by a browser. Similar technologies include local storage, session storage, SDK storage, pixels, and identifiers in request headers. This policy refers to all of them as “cookies” unless a distinction matters.
This policy applies to Fireflies services operated by [LEGAL ENTITY NAME], [REGISTERED ADDRESS]. It should be read with the Privacy Notice. Because the production domain and final vendor configuration are not yet fixed, every example and duration below must be tested before launch.
Launch position: essential only
Strictly necessary cookies may be used without an optional consent toggle where applicable law permits because they are needed to deliver a service you requested, secure the service, remember privacy choices, or balance traffic. They are still documented and minimized.
Categories of technology
| Category | Purpose | Launch status | Typical duration |
|---|---|---|---|
| Authentication | Create and maintain Clerk sign-in sessions; support email/password, Google, and Apple login; prevent session forgery | Strictly necessary | Session or provider-configured persistent period; verify before launch |
| Security & abuse prevention | CSRF protection, bot and rate-limit signals, suspicious-login detection, request integrity | Strictly necessary | Request, session, or short persistent period |
| Infrastructure & load management | Route requests, preserve a secure session across service instances, support availability | Strictly necessary if deployed | Session or short persistent period |
| Privacy & interface preferences | Remember cookie choice, reduced-motion or safety-display preference, locale, and limited display settings | Necessary or functional depending on implementation | Session to 12 months |
| Local draft storage | Prevent loss of an unfinished submission on the same device, only if this feature is enabled | Functional; local and disclosed in the upload flow | Until submitted, cleared, expired, or manually deleted |
| Analytics | Measure product use and performance beyond essential server logs | Disabled at launch | Not applicable until consent and inventory are implemented |
| Marketing / advertising | Advertising, conversion tracking, profiling, or retargeting | Disabled at launch | Not applicable |
First and third parties
A first-party cookie is set on the Fireflies domain. A third-party technology is provided by another organization or can communicate with another domain. Fireflies expects Clerk to support authentication and Railway-hosted infrastructure to serve the application. Social sign-in can also involve Google or Apple when you choose that method.
A sign-in redirect or provider cookie may be controlled by Google, Apple, or Clerk under their own notices. Fireflies should configure providers for data minimization and must not treat a social sign-in choice as consent to unrelated analytics or marketing.
Production inventory required before launch
- Scan every public flow
Test signed-out, email/password, Google, Apple, signed-in, upload, map, report, appeal, and deletion flows across relevant browsers.
- Record each technology
Capture exact name, domain, first or third party, provider, purpose, category, trigger, data, duration, and whether browser storage is used.
- Block optional tags
Confirm optional technologies cannot load before a valid choice and that rejection is as easy as acceptance.
- Test withdrawal
Withdrawing optional consent should stop future optional collection and remove the relevant first-party identifiers where technically feasible.
- Publish and monitor
Replace this provisional table with the real inventory, date it, and rescan after vendor, tag, domain, or authentication changes.
Your controls
- Use the Fireflies cookie settings link if optional categories are introduced.
- Reject optional cookies without losing core account, map, upload, report, or appeal functionality.
- Withdraw optional consent as easily as it was given; withdrawal applies to future processing.
- Use browser controls to delete or block cookies. Blocking essential cookies may sign you out or prevent secure features from working.
- Clear local or session storage through browser site-data settings. Clearing an unfinished local draft may be irreversible.
- Use private-browsing controls with the understanding that some security, session, or sign-in features may behave differently.
Fireflies will assess legally recognized browser or device privacy signals if they become applicable to its processing. A generic “Do Not Track” signal does not have one universally agreed legal effect; this policy will be updated if Fireflies responds to a specific signal.
Legal basis and retention
Essential technologies are used to provide a requested service, perform the user agreement, comply with legal duties, and pursue legitimate interests in security and continuity, subject to applicable ePrivacy and national rules. Consent will be requested before non-essential access to or storage on a device where required.
Cookie duration should be no longer than needed for its purpose. Session cookies normally end when the browser session ends, although recovery and authentication settings can persist. Server logs and data linked to a cookie may have a different retention period described in the Privacy Notice.
Changes and questions
Fireflies will update the date and inventory when the purposes, providers, or choices materially change. A new purpose will not be silently bundled into an earlier optional consent.
Questions or requests about cookies: [PRIVACY EMAIL]. General support: [SUPPORT EMAIL].