This policy explains the cookies and similar browser storage used on analyse.net and the Analyse Games dashboard, why we use them, and how you can control them. It is published by Breukers Willem Albertus E.E., trading as VertCode Development, which provides Analyse Games (see the Imprint).
The short version
- We only use cookies and browser storage that are strictly necessary to sign you in, keep your account secure and remember choices you make in the interface.
- We do not use advertising cookies, cross-site tracking or third-party analytics on our website or dashboard today.
- Our cookie banner offers "Essential only" and "Accept all". "Essential only" is always an equally easy choice. At the moment "Accept all" does not switch on any additional cookies, because we don't run any. If we ever add optional cookies, such as product analytics, they will only run after you say yes, and we will update this page first.
- Nothing on this page tracks the players in your games. Player data sent by your servers is covered by the Data Processing Addendum.
The legal basis
Greek law (Article 4(5) of Law 3471/2006, which implements Article 5(3) of the EU ePrivacy Directive 2002/58/EC) says a website may only store or read information on your device with your prior consent, unless the storage is strictly necessary to provide a service you have explicitly asked for. The guidance of the Hellenic Data Protection Authority applies the same rule to cookies, localStorage and similar technologies.
Everything listed below falls within the "strictly necessary" exemption, so it does not need consent. Where these items involve personal data (for example, a session identifier), we process it under Article 6(1)(b) GDPR, to provide the service you signed up for, and Article 6(1)(f) GDPR, our legitimate interest in keeping accounts secure. See the Privacy Policy.
Cookies we set
All of our cookies are first-party (set by analyse.net), marked HttpOnly so page scripts can't read them, sent only over HTTPS in production and restricted with SameSite=Lax.
| Name | Purpose | Duration | Type |
|---|---|---|---|
session | Keeps you signed in. Holds a signed token that points to a session we store on our side, so you can see and end sessions from your account settings. | 7 days, or until you sign out | Strictly necessary |
ag_2fa | Remembers, for one sign-in attempt, that you passed your password (or social sign-in) and still owe a two-factor code. | 10 minutes | Strictly necessary |
ag_2fa_trust | Set only if you tick the option to trust a device after two-factor sign-in, so you aren't asked for a code on that device again for a while. | 30 days | Strictly necessary (set at your request) |
oauth_state | Protects sign-in with Google, Discord or GitHub against cross-site request forgery. | 10 minutes | Strictly necessary |
ag_auth_next | Remembers which page to send you to after a social sign-in. | 10 minutes | Strictly necessary |
ag-invite | Holds a team invitation you opened while signed out, so it can be accepted once you sign in or sign up. | 24 hours | Strictly necessary |
Browser storage we use
These entries live in your browser's localStorage. They never leave your device and we can't read them on our servers. They only remember interface choices you make.
| Key | Purpose | Duration |
|---|---|---|
ag-cookie | Your choice in the cookie banner ("essential" or "all"), so we don't ask again. | Until you clear it or change your choice |
vcd-theme | Light or dark mode. | Until you clear it |
ag-oauth-last | Which sign-in button you used last, so it can be highlighted. | Until you clear it |
ag-ob-step, ag-onboarded | Where you are in the setup wizard, so a reload doesn't send you back to the start. | Until you clear it |
analyse:range | The date range you last picked on dashboards. | Until you clear it |
analyse:history-notice:v2:<game> | That you dismissed the notice about how much history your plan shows. | Until you clear it |
ag-pinned-boards-open | Whether the pinned dashboards list is open. | Until you clear it |
ag-kb-open:<id> | Which folders in the knowledge base tree are expanded. | Until you clear it |
ag-ai-min | Whether the Ask Analyse panel is minimised. | Until you clear it |
Content loaded from other sites
Some dashboard pages show small images that your browser fetches directly from other services. These requests don't set cookies from us, but, like any web request, they reveal your IP address and the image address to that service:
- flagcdn.com serves country flags. The address contains only a two-letter country code.
- mc-heads.net serves Minecraft player heads. The address contains the player's public Minecraft UUID.
When you pay for a plan you are sent to Stripe Checkout or the Stripe billing portal on stripe.com. Stripe sets its own cookies there for payment processing and fraud prevention, under Stripe's cookie policy. If you choose to sign in with Google, Discord or GitHub, that provider's sign-in page sets its own cookies under its own policy.
How to control cookies
- Cookie settings: use the "Cookie settings" button in the footer of our website to see the banner again and change your choice at any time.
- Your browser: you can block or delete cookies and site data in your browser settings. If you block the strictly necessary cookies above, you won't be able to sign in.
- Signing out removes the
sessioncookie. You can end sessions on other devices under Account settings.
Changes
If we add, remove or change a cookie or storage entry, we update this page and the "Last updated" date. If a change means we would need your consent, we will ask for it through the banner before anything new runs.
Contact
Questions about this policy: [email protected]. You can also complain to the Hellenic Data Protection Authority (Kifisias 1-3, 115 23 Athens, www.dpa.gr).