Legal Center

Legal Center

Cookie Policy

Last updated 2026-09-01Version 2026-09-01.1

Cookies Kaptly sets directly

Kaptly's own cookies keep account and sign-in flows working or remember product preferences. None are used for advertising or cross-site tracking. Analytics is the only cookie-based measurement and is set only if you accept it, as described in its own section below.

  • kaptly session cookie — keeps you signed in. HttpOnly, SameSite=Lax, marked Secure in production, expires after 30 days or on logout.
  • Language preference — remembers whether you're reading Kaptly in English or Serbian before you sign in.
  • Short-lived sign-in cookies — only while you're signing in with Google. They hold the one-time security values that tie the round-trip to your browser (and, for a first-time signup, a lookup token for the details Google returned). Minutes long, deleted as soon as sign-in finishes.
  • Cookie choice — records whether you accepted or declined analytics, so you aren't asked again on every page. Set the moment you answer the banner either way, and expires after six months.
  • kaptly_mobile_builder_notice — remembers that the one-time phone reminder has been shown in the form builder, so it isn't repeated on every visit. First-party, SameSite=Lax, and expires after one year.
  • kaptly_workspace — an httpOnly, SameSite=Lax selector (Secure in production) that remembers the active workspace for accounts included in the staged collaboration rollout. It contains a workspace id, not an access grant; Kaptly rechecks current membership on every request.

Analytics (only with your consent)

Kaptly uses Google Analytics to see which pages people use and where they get stuck. It is off by default. Until you press Accept on the cookie banner, the Google Analytics script is not loaded at all — no analytics cookie is written and nothing about your visit is sent to Google.

If you accept, Google Analytics sets its own cookies (names beginning _ga) to tell one visit apart from the next and count returning visitors. IP anonymisation is enabled, advertising and personalisation signals are switched off, and Kaptly does not use this data to target ads or link your browsing to your account.

Analytics never runs on public form pages (/f/…) or embedded forms. Those belong to the Kaptly customer who built them, and their respondents are not measured by us.

To change your mind, delete Kaptly's cookies in your browser settings — the banner will ask again on your next visit.

Local storage (not cookies, but similar in spirit)

Kaptly also stores a few small values directly in your browser (not sent to any server automatically):

  • App appearance fallback (System/Light/Dark) for signed-out use. System follows the device theme. While signed in, the account's database preference is authoritative and is not copied to another account.
  • An anonymous, randomly generated visitor identifier used on public forms, so repeat visits/partial saves can be recognized without an account
  • A one-time flag used to show a support nudge after you publish your first form
  • For a workspace invitation, the raw token from the URL fragment and the time it was captured, held in sessionStorage for at most 15 minutes and removed after completion or terminal failure. URL fragments are not sent to the server automatically.

Third-party cookies

Legal review neededDeveloper confirmation needed

Some third-party services embedded in Kaptly may set their own cookies or collect your IP address when their scripts load — for example Google Fonts (loaded live to render custom typefaces) and Google reCAPTCHA (spam protection on some forms). These are governed by the third party's own policies, not this one.

Google One Tap also loads a Google script on the Kaptly sign-in and sign-up pages, so that visitors already signed in to Google can be offered one-tap sign-in. It does not load on the home page or anywhere else — only where you have gone in order to sign in. This means Google can see that you visited those two pages, whether or not you use the prompt. Dismissing the card stops it being offered again for a while; blocking third-party scripts in your browser prevents it loading at all, and every other way of signing in keeps working.

[CONFIRM — legal review: whether Google Fonts and reCAPTCHA also require prior consent in the jurisdictions Kaptly serves, or whether they are covered as strictly necessary. Analytics is now consent-gated and One Tap has been moved off the public marketing page, so the original form of this question is resolved; what remains open is these two.]

Managing cookies

You can control or delete cookies through your browser settings. Blocking the Kaptly session cookie will sign you out and prevent staying signed in.