Cookie Notice
Effective date: 2026-04-19 Last updated: 2026-06-03
Summary
Dicted uses the minimum cookies necessary to keep you signed in and protect your session. We do not use advertising cookies, cross-site tracking cookies, or third-party analytics cookies.
We currently set only strictly-necessary cookies (admin-console session, OAuth CSRF cookies during sign-in, desktop bridge cookie) — the kind that do not require consent under EU/UK/EEA cookie law. Our marketing site uses cookieless, privacy-preserving analytics (Umami) that sets no cookies and collects no personal data (see §2.3). Because we set no non-essential cookies, no consent banner is shown. If we ever introduce analytics or other technologies that do set non-essential cookies, we will deploy a consent banner first and update this notice.
1. What is a cookie?
A cookie is a small text file stored by your browser on your device. It lets the service recognise you between requests — which is how "stay signed in" works. Cookies can also be set by third parties embedded in a page (for example, a YouTube video, or a tracking pixel). We avoid third-party cookies as much as possible.
This notice also covers similar technologies like localStorage (used for UI preferences such as "dismiss this banner") and sessionStorage.
2. Cookies we set
2.1 Strictly necessary (always on)
These cookies are required for the service to work. You cannot opt out of them — if you turned them off, you would not be able to sign in.
| Name | Purpose | Expires | Where set |
|---|---|---|---|
accessToken |
Keeps an admin signed into the internal admin console. HttpOnly, Secure, SameSite=Strict. Issued only after staff email/password + 2FA. | 2 hours | admin-api.dicted.ai (only the M37 staff who can log in to the admin console will ever see this cookie) |
__Host-google-oauth-csrf |
One-shot CSRF defence during the "Sign in with Google" handshake. Compared to a value embedded in the OAuth state parameter on return; rejected if they don't match. |
10 minutes (cleared on callback) | api.dicted.ai |
__Host-microsoft-oauth-csrf |
Same as above for "Sign in with Microsoft". | 10 minutes (cleared on callback) | api.dicted.ai |
__Host-apple-oauth-csrf |
Same as above for "Sign in with Apple". | 10 minutes (cleared on callback) | api.dicted.ai |
__Host-dicted-bridge |
One-shot handoff cookie that lets the Dicted desktop app finish an OAuth sign-in started in the browser. Set only when you initiated sign-in from the desktop client; cleared once the desktop app retrieves it. | 5 minutes (cleared on retrieval) | api.dicted.ai |
2.2 Functional and authentication state (browser localStorage)
Not technically cookies but covered by the same consent rules. These entries are stored locally on your device by the dashboard at app.dicted.ai. Most are pure preference state that we never read from our servers; the authentication state entries below are the exception — your access token is read by the dashboard to attach to every authenticated request it sends to api.dicted.ai.
Strictly-necessary authentication state (you cannot use the dashboard without these):
| Key | Purpose | Expires |
|---|---|---|
dicted-auth |
Holds your access token and basic profile (id, email, display name) so you stay signed in across page reloads. The token is sent in the Authorization header to api.dicted.ai — this is how the dashboard authenticates you instead of using a session cookie. |
Cleared on logout or until you clear browser storage |
dictedSocketToken |
Legacy fallback for the realtime socket connection if the HttpOnly socketToken cookie path is unavailable |
Cleared on logout |
Functional preferences (UI niceties; we never read these from our servers):
| Key | Purpose | Expires |
|---|---|---|
dicted_near_cap_dismissed_at |
Remembers when you dismissed the "approaching monthly limit" banner so we don't re-show it for 30 days | 30 days from dismissal |
dicted-ui |
Your dashboard theme name, light/dark/system mode preference, and sidebar open/closed state | Until cleared |
dicted.share.theme |
Your colour-theme preference for shared meeting pages (recipient-side only) | Until cleared |
2.3 Analytics
We set no analytics cookies.
The application (app.dicted.ai) loads no analytics at all.
The marketing site (dicted.ai) uses Umami — a self-hosted, cookieless, privacy-preserving analytics tool. Umami sets no cookies, does not fingerprint or cross-site-track visitors, and collects no personal or identifiable data. Because it relies on no cookies or other non-essential storage, no consent banner is required for it under EU / UK / EEA cookie law.
2.4 Advertising
We do not set advertising cookies. We have no advertising business. This will not change.
3. Third-party cookies
The marketing website (dicted.ai) may embed third-party content (for example, a demo video). Where this happens we use privacy-friendly embed methods (YouTube youtube-nocookie.com, Vimeo "do not track" embeds) that do not set cookies until the visitor interacts with the embed.
Payment flows are handled by Stripe Checkout on Stripe's own domain. Stripe sets its own cookies there to prevent fraud and complete the payment. Those cookies are governed by Stripe's cookie notice at stripe.com/cookies-policy/legal.
4. Consent (EU / UK / EEA visitors)
We currently set only strictly-necessary cookies, which under EU / UK / EEA cookie law do not require consent. Our marketing-site analytics (Umami) is cookieless and sets nothing that requires consent. No consent banner is shown today because there is nothing non-essential to opt in or out of.
If we introduce any non-essential cookie (or other non-essential storage) in the future, we will — before activation — deploy a consent banner for EU / UK / EEA visitors that lets you:
- Accept all — allows all current and future non-essential cookies
- Reject non-essential — keeps only the strictly-necessary cookies listed in §2.1
- Customise — pick categories individually
A consent-banner deployment is planned for an upcoming release ahead of any non-essential cookie use.
5. Do Not Track and Global Privacy Control
We do not currently set any non-essential cookies, so there is nothing for the Global Privacy Control (GPC) browser signal to opt you out of today. When we introduce non-essential cookies, the consent banner described in §4 will treat a GPC signal as a valid opt-out of those non-essential cookies — no banner click required.
We do not currently treat the older "Do Not Track" header as an opt-out signal, because browser vendors have effectively deprecated it. GPC will replace it when our consent banner ships.
6. Changes to this notice
If we materially change the set of cookies we use, we will update this page. For EU / UK / EEA visitors, the introduction of any non-essential cookie will be preceded by deployment of the consent banner described in §4. The "Last updated" date at the top is authoritative.
7. Contact
Email [email protected] for any cookie-related question or complaint.
© 2026 M37 Tech Pty Ltd, PO Box 1215, GREYTHORN VIC 3104, Australia. All rights reserved.
dicted