CodexFlow
System DNAHow It WorksPricingDocs
Get CodexFlow
←Legal center

CodexFlow legal

Cookies Policy

Cookie, storage, consent, analytics, marketing, payment, and security technology disclosures for CodexFlow.io.

Policy status

Production Ready
Updated
24 May 2026
Effective
24 May 2026
Operator
Nova Group Sp. z o.o.
Jurisdiction
Poland / European Union

Documents

TermsPrivacyCookiesRefundsDisclaimerImprintSecurityAccessibility

On this page

1. Operator2. What cookies and similar technologies are3. Categories used by CodexFlow4. Consent mechanism5. Google Consent Mode v26. Cookie and storage table7. Third-party cookies8. Analytics and advertising compatibility9. Managing cookies in your browser10. Changes to this Policy
ScopePoland / European Union
Version24 May 2026
CompanyNova Group Sp. z o.o.

This Cookies Policy explains how CodexFlow uses cookies, local storage, pixels, SDKs, tags, and similar technologies on https://codexflow.io.

1. Operator

CodexFlow is operated by Nova Group Sp. z o.o., Żurawia 6/12 Lok. 745, 00-503 Warszawa, Poland. For cookie and privacy questions, contact privacy@codexflow.io. For general support, contact support@codexflow.io.

2. What cookies and similar technologies are

Cookies are small text files stored on your device. Similar technologies include local storage, session storage, pixels, tags, SDKs, and server-side identifiers. They can be used to keep the website working, remember consent choices, secure accounts and payments, measure website performance, understand product usage, and support advertising or conversion measurement.

3. Categories used by CodexFlow

CodexFlow may use the following categories:

  • Essential cookies and storage: required for website operation, security, checkout, authentication, consent records, and protected digital delivery.
  • Analytics cookies and storage: used to understand website usage, documentation visits, funnel performance, and product interest.
  • Marketing cookies and storage: used for Google Ads conversion tracking, remarketing, ad measurement, and campaign attribution where consent allows.
  • Authentication cookies and storage: used to keep accounts, sessions, and protected access pages working.
  • Payment and security cookies: used by payment providers to process payments, prevent fraud, authenticate transactions, and secure checkout.
  • Preference cookies: used to remember choices such as consent state, interface settings, or language where applicable.

4. Consent mechanism

CodexFlow may use Cookiebot CMP and Google Consent Mode v2 to request, record, and transmit consent choices. Non-essential analytics, advertising, remarketing, and similar storage are used only according to your consent choices where consent is required.

You can change or withdraw your cookie consent at any time by reopening the cookie settings widget available on the website. Browser settings may also allow you to delete or block cookies, but blocking essential cookies may break checkout, account access, protected downloads, payment authentication, or security features.

5. Google Consent Mode v2

Google Consent Mode v2 helps Google tags adjust behavior based on consent choices. It may use consent signals such as analytics_storage, ad_storage, ad_user_data, and ad_personalization. These signals are not ordinary content cookies themselves; they communicate whether Google services may use storage or personal data for analytics, advertising, and personalization according to your consent.

6. Cookie and storage table

ProviderCookie/local storage name or patternCategoryPurposeTypical retentionConsent requiredNotes
Cookiebot CMP / UsercentricsCookieConsent, CookieConsentBulkTicket, consent recordsEssential / consent managementStores consent choices and helps prove and respect cookie preferences12 monthsNo for consent record itselfRequired to operate the consent mechanism
Google Consent Mode v2Consent state signals including analytics_storage, ad_storage, ad_user_data, ad_personalizationConsent signalingSends consent state to Google tags so they behave according to user choicessession to 12 months, depending configurationNo for basic consent signaling; yes for downstream analytics or ads storage where requiredWorks with Google Ads, GA4, and Google Tag Manager
Google Analytics 4_ga, _ga_*AnalyticsMeasures site usage, traffic sources, page views, and eventsup to 24 monthsYes, where requiredUsed only according to consent configuration
Google Ads_gcl_au, _gcl_aw, _gcl_dcMarketing / conversion measurementMeasures ad clicks, conversions, and campaign attribution90 days to 6 monthsYes, where requiredUsed for Google Ads conversion tracking and attribution
Google advertising servicesIDE, NID, ANID, 1P_JAR, AEC, Google ad identifiersMarketing / securitySupports ad delivery, frequency control, fraud prevention, and remarketing where enabledsession to 13 monthsYes for advertising and remarketing where requiredExact cookies depend on Google services and browser context
Google Tag ManagerTag execution state and consent-aware tag behaviorEssential / analytics / marketing depending tagLoads and manages website tags according to consent settingssession or according to loaded tagsDepends on the tagGTM itself may load other tags listed in this table
Plausible AnalyticsUsually no standard cookie in cookieless mode; optional site configuration identifiersAnalyticsPrivacy-friendly aggregate traffic measurementnone in cookieless mode; otherwise configuration-dependentUsually no for cookieless aggregate mode; yes if configured with identifiers requiring consentPlausible is typically configured without cookies
PostHogph_*, posthog_*, local storage identifiersAnalytics / product analyticsHelps understand product usage, funnel behavior, and website interactions12 months to 24 monthsYes, where requiredExact names depend on project configuration
Clerk__session, clerk_*, session/local storage identifiersAuthentication / essentialProvides account login, session management, and protected page accesssession to 12 monthsNo when necessary for account accessRequired where user accounts or protected sessions are enabled
Stripe__stripe_mid, __stripe_sid, m, payment security identifiersPayment / securityFraud prevention, payment security, checkout reliability, and transaction authentication30 minutes to 12 monthsNo where strictly necessary for payment and fraud preventionSet by Stripe during payment and fraud-prevention flows
WorldlineWorldline payment session cookies, fraud identifiers, transaction session storagePayment / securityPayment session continuity, fraud prevention, payment authentication, and checkout securitysession to 13 monthsNo where strictly necessary for payment and fraud preventionExact names depend on Worldline configuration
CodexFlowcodexflow_session, codexflow_access, secure access tokens, local preference storageEssential / authentication / deliveryMaintains protected access pages, license delivery state, download access, and securitysession to 12 monthsNo where necessary for requested serviceAccess tokens should be scoped, time-limited, and protected
CodexFlowcodexflow_preferences, interface or documentation preferencesPreferencesRemembers non-essential website preferences6 months to 12 monthsYes where requiredMay not be present in all deployments
Email and support toolsSupport session identifiers and anti-abuse cookiesEssential / supportEnables support requests, form protection, and abuse preventionsession to 12 monthsNo where necessary for security; yes for non-essential analyticsExact names depend on provider configuration
Security and hosting providersLoad-balancing, firewall, bot-protection, and rate-limit cookiesEssential / securityProtects website availability, prevents abuse, and supports secure deliverysession to 12 monthsNo where strictly necessaryNames depend on hosting and security provider configuration

7. Third-party cookies

Some third-party providers may set cookies or similar identifiers when their services are loaded. This can include Google, Stripe, Worldline, Clerk, Cookiebot, Plausible, PostHog, hosting providers, and security providers. Third-party cookies are governed by the relevant provider’s own notices in addition to CodexFlow policies.

8. Analytics and advertising compatibility

CodexFlow intends to keep analytics and advertising compatible with EU privacy expectations by using a consent-management layer, honoring user choices, and separating essential checkout/security cookies from optional analytics and marketing technologies.

Google Ads conversion tracking, remarketing, Customer Match, enhanced conversions, GA4, and similar features should be used only where the relevant consent and disclosure requirements are satisfied.

9. Managing cookies in your browser

You can delete or block cookies through browser settings. If you block essential cookies or local storage, parts of the website may stop working, including checkout, payment authentication, login, protected access pages, consent preferences, or secure downloads.

10. Changes to this Policy

CodexFlow may update this Cookies Policy when providers, tools, consent mechanisms, or website features change.

CodexFlow

Stop rebuilding context. Start every Codex session inside a disciplined repo workflow.

TermsPrivacyCookiesRefundsSecurityImprintAll legal

CodexFlow is an independent workflow toolkit for developers using Codex. Codex and OpenAI are trademarks of their respective owners. CodexFlow is not affiliated with, endorsed by, or sponsored by OpenAI.

Operated by Nova Group Sp. z o.o.