# Cookie Policy

**Controller:** Keynodex LLC, Florida, USA (contact@keynodex.com)
**Last updated:** 2026-09-13

This policy explains what keynodex.com stores on your device, why, and how you
control it. It describes the site as it actually works today; if the code and
this page disagree, the code is the bug.

---

## 1.0 The short version

1.1 You are not tracked for analytics or advertising unless you turn those
categories on. Both start **off**.

1.2 Your theme, language and cookie choices are stored on your device so the
site works and remembers your preferences. Those are always on because the site
cannot function without them.

1.3 You can change or withdraw your choices at any time from the cookie banner,
the settings link in the footer, or your browser.

1.4 We do not sell your personal data, and we do not use advertising cookies
for anyone unless you grant **targeting** consent.

---

## 2.0 What cookies and similar storage are

2.1 Cookies are small files a site asks your browser to keep. Local storage and
session storage are similar: the browser holds small pieces of data for the
site.

2.2 "Session storage" lives only in the current tab and is erased when the tab
closes. "Local storage" and cookies can survive between visits until they
expire or you delete them.

---

## 3.0 Strictly necessary storage (always on)

3.1 This storage is required to deliver the site and your privacy choices. It
is not used to profile you.

| Key | Type | Purpose |
|---|---|---|
| `knx-consent-v2` | localStorage | Records whether you accepted or rejected non-essential cookies |
| `knx-consent-prefs-v1` | localStorage | Records your granular performance / functional / targeting choices |
| language cookie | cookie, `SameSite=Strict` | Remembers the language you selected |
| sidebar state | cookie | Remembers whether the docs sidebar is open |
| Cloudflare Turnstile | cookie / challenge | Security check for forms, stopping bots and spam |

---

## 4.0 Functional storage (always on)

4.1 Functional storage powers site features you can see. It is not used for
advertising or analytics.

| Key | Type | Purpose |
|---|---|---|
| `keynodex-theme` | localStorage | Remembers light or dark mode |

---

## 5.0 Analytics — only with your consent

5.1 Analytics is **off by default**. Nothing below loads or fires until you
grant **performance consent** (the "Performance (Analytics)" switch in the
cookie settings).

5.2 **Google Analytics 4, via Google Tag Manager.** Google Tag Manager loads in
consent-denied mode and Google's Consent Mode keeps analytics storage denied
until you grant performance consent.

5.3 **Session activity sent to PingRep.** When performance consent is granted,
keynodex.com sends page views, dwell time, CTA click events and a periodic
session heartbeat to PingRep's tracking API at `api.pingrep.com`. PingRep is our
infrastructure provider and processes this as a service provider to produce
aggregate performance metrics for keynodex.com.

| Key | Type | Purpose |
|---|---|---|
| `kn_tracking_session_id` | sessionStorage | Random session identifier for the current visit; not linked to you across sessions |
| `kn_tracking_session_meta` | sessionStorage | Session creation and last-seen timestamps |

5.4 The session identifier lives in session storage only. It is erased when the
tab closes, when consent is withdrawn, and when the session is idle for 30
minutes or older than 4 hours. We keep no cross-session identifier for
keynodex.com visitors.

5.5 The tracking payload is minimized to the page path, the referring host, UTM
campaign parameters and the session identifier. It does not include your screen
size, timezone, connection type, touch support or device fingerprint.

5.6 Withdrawing performance consent removes the session keys, stops all
tracking in the open tab, and returns Google Consent Mode to denied.

---

## 6.0 Advertising — only with your consent

6.1 Advertising and personalization tags are **off by default** and stay off
until you grant **targeting consent**.

6.2 Advertising tags are configured inside Google Tag Manager (for example,
Meta). Google Consent Mode holds `ad_storage`, `ad_personalization` and
`ad_user_data` at denied until targeting consent is granted.

6.3 If your browser sends a Global Privacy Control (GPC) signal, targeting is
**forced off** and cannot be turned on while GPC is active. Analytics remains
off unless you explicitly enable it yourself.

---

## 7.0 Managing your choices

7.1 **Cookie banner.** On your first visit, choose "Accept", "Reject" or
"Manage". Rejecting turns off everything optional.

7.2 **Cookie settings.** Reopen the settings any time from the footer ("Your
privacy choices") or the link in the banner, and change individual categories.

7.3 **Browser controls.** You can delete or block cookies in your browser.
Blocking strictly necessary storage may break parts of the site, such as
remembering your privacy choices.

7.4 **Do Not Track.** Browser Do Not Track signals are not standardized. We
honor Global Privacy Control, which is the standard signal with legal weight in
the places we operate.

---

## 8.0 How long your choices last

8.1 Your consent choice is kept for up to 6 months. After that the record
expires: the tracker is torn down, Google Consent Mode returns to denied, and
the banner asks you again.

---

## 9.0 Service providers involved

| Provider | Role | Data |
|---|---|---|
| Google (Tag Manager, Analytics, ads tags) | Analytics and advertising tags, loaded only with consent | Page usage, ad interactions |
| PingRep (api.pingrep.com) | Tracking ingest for aggregate performance metrics, only with performance consent | Session id, page path, referring host, UTM parameters |
| Cloudflare (Turnstile) | Form security | Challenge and security signals |
| Vercel | Hosting | Request logs needed to serve the site |

9.1 A current list of the processors the site uses, with what each one handles,
is maintained in the Privacy Policy.

---

## 10.0 Changes to this policy

10.1 When we change how storage works, we update this page and its date. If the
change is material, the banner will ask for your choice again.

---

## 11.0 Contact

11.1 Questions about this policy: **security@keynodex.com**
11.2 Data protection requests (access, deletion, correction):
**security@keynodex.com**. Requests submitted to security@keynodex.com are
acknowledged within 3 business days and processed within 30 calendar days.
