In short
- Dium sets only strictly necessary cookies, mostly to keep you signed in.
- No advertising or cross-site tracking cookies. Cloudflare Web Analytics is cookieless.
- So there is no consent banner. The marketing site sets no cookies at all.
- One open item: YouTube embeds need a click-to-play or consent fix before launch.
- Global Privacy Control signals are honoured.
What we found
We reviewed the cookies and browser storage Dium sets, based on the app's code. Dium uses only what it needs to sign you in, keep you secure and make the app work. It sets no advertising, social media or cross-site tracking cookies. Our site analytics, Cloudflare Web Analytics, is cookieless: it does not store anything on your device or follow you across sites.
Because everything Dium itself sets is strictly necessary, we show you this notice instead of a consent banner. The law does not require consent for strictly necessary storage. The dium.io marketing pages, including this one, set no cookies at all.
Cookies Dium sets
These are set on the dium.io domain when you sign in. All are Secure and SameSite=Lax, so browsers only send them over HTTPS and not with most cross-site requests.
| Name | Set by | Purpose | Category | Duration | HttpOnly |
|---|---|---|---|---|---|
sasq_public_key | Dium (first party) | Your Moat identity key. The main way Dium knows it is you | Strictly necessary | 30 days | Yes |
email | Dium | Backup sign-in identifier (refused on its own for incomplete accounts) | Strictly necessary | 30 days | Yes |
user_key | Dium | Your Werify sign-in key | Strictly necessary | 30 days | Yes |
moat_pk | Dium | Copy of your Moat identity key used by shared sign-in code | Strictly necessary | 30 days | Yes |
sr_token | Dium | Signed session token | Strictly necessary | [confirm JWT lifetime] | Yes |
tao_profile_info | Dium | Small profile snapshot from sign-in so the app can load your name and photo | Strictly necessary | 30 days | Yes |
sasq_logged_in | Dium | Tells the app's scripts you are signed in | Strictly necessary | 30 days | No |
sasq_display_name | Dium | Shows your name before your profile loads | Strictly necessary | 30 days | No |
MOAT_logged_in, MOAT_display_name | Dium | The same two flags, set by the sign-in page | Strictly necessary | 30 days | No |
dium_back_url, dium_back_slug | Dium | Remembers the partner page to return to. Being retired | Strictly necessary | 30 days | No |
[PHP session cookie name, default PHPSESSID] | Dium | Server session: anti-forgery (CSRF) token and where to send you after single sign-on | Strictly necessary | Until you close the browser | Yes |
Browser storage Dium uses
| Name | Purpose | Category | How long |
|---|---|---|---|
dium_token (local storage) | Keeps you signed in when Dium runs inside a partner's website, where cookies from dium.io cannot be used | Strictly necessary | Until you sign out [confirm it is cleared on sign-out] |
asq_onboarding (local storage) | Remembers which steps of the welcome tour and checklist you finished | Functional, part of the tour you asked for [COUNSEL: confirm classification] | Until you clear site data |
| Dium cache (IndexedDB, with local storage fallback) | Keeps recent Flows, Waves and messages on your device so pages open fast and stay in sync across tabs | Strictly necessary | Refreshed as you use Dium; cleared with site data [confirm whether cleared on sign-out] |
| App cache (service worker, Cache Storage) | Stores the app's own code and styles so it loads fast and works briefly offline | Strictly necessary | Replaced with each app version |
Cookies from other services
When you sign in, the Werify sign-in widget runs on its own site (werify.ai) and may set its own cookies to complete the sign-in you asked for [confirm Werify cookie names and durations]. After sign-in, Dium hands you to Moat (moat.page) so you are signed in there too, and Moat sets its own sign-in cookies on moat.page. Werify Paywall sets its own cookies during checkout. These services' cookie policies apply.
Embedded videos and consent
The Dium app allows YouTube videos inside Waves and Pages. A standard YouTube embed can set YouTube cookies that are not strictly necessary. [DECISION: either load YouTube embeds from youtube-nocookie.com behind a click-to-play placeholder, or add a consent tool with equal Accept all and Reject all buttons before any embed loads]. Until that is done, this is the one place where Dium content can cause a non-essential cookie, and a consent tool is required for it.
Cookie settings
Because Dium only uses strictly necessary cookies and storage, there are no optional categories to switch on or off, so a Cookie settings link only needs to lead to this page [add a persistent Cookie settings link to the site and app footers that points here]. If we ever add analytics, functional or marketing cookies that need consent, we will add a settings panel with Essential, Functional, Analytics and Marketing choices, all non-essential ones off by default, and a Reject all button as easy to use as Accept all. We will ask you again before anything new runs.
You can also control cookies yourself. Your browser lets you view and delete cookies and site data. If you block Dium's strictly necessary cookies, you will not be able to stay signed in.
Global Privacy Control and Do Not Track
If your browser sends a Global Privacy Control (GPC) signal, we treat it as an opt-out of the sale and sharing of your personal information. [Confirm: we do not sell or share it today]. We do not use cookies for advertising, so the signal does not change how Dium works, but we honour and record it [confirm GPC handling in the app]. There is no common standard for Do Not Track, so we do not respond to it separately; the same limits apply either way.
Changes and contact
We will update this page before we add a new cookie or storage item, and date the change. Questions: [email protected]. See our Privacy Policy for everything else.