Cookie policy

Every cookie and storage item Dium uses, why, and for how long. No ad trackers, and no banner.

Last updated Effective [Effective date] Questions: [email protected]
Template, not live data. Draft for review. Confirm bracketed items and have counsel review before publishing.

In short

  • Dium sets only strictly necessary cookies, mostly to keep you signed in.
  • No advertising or cross-site tracking cookies. Cloudflare Web Analytics is cookieless.
  • So there is no consent banner. The marketing site sets no cookies at all.
  • One open item: YouTube embeds need a click-to-play or consent fix before launch.
  • Global Privacy Control signals are honoured.

What we found

We reviewed the cookies and browser storage Dium sets, based on the app's code. Dium uses only what it needs to sign you in, keep you secure and make the app work. It sets no advertising, social media or cross-site tracking cookies. Our site analytics, Cloudflare Web Analytics, is cookieless: it does not store anything on your device or follow you across sites.

Because everything Dium itself sets is strictly necessary, we show you this notice instead of a consent banner. The law does not require consent for strictly necessary storage. The dium.io marketing pages, including this one, set no cookies at all.

Cookies Dium sets

These are set on the dium.io domain when you sign in. All are Secure and SameSite=Lax, so browsers only send them over HTTPS and not with most cross-site requests.

From the Dium app's sign-in code. Durations default to 30 days.
NameSet byPurposeCategoryDurationHttpOnly
sasq_public_keyDium (first party)Your Moat identity key. The main way Dium knows it is youStrictly necessary30 daysYes
emailDiumBackup sign-in identifier (refused on its own for incomplete accounts)Strictly necessary30 daysYes
user_keyDiumYour Werify sign-in keyStrictly necessary30 daysYes
moat_pkDiumCopy of your Moat identity key used by shared sign-in codeStrictly necessary30 daysYes
sr_tokenDiumSigned session tokenStrictly necessary[confirm JWT lifetime]Yes
tao_profile_infoDiumSmall profile snapshot from sign-in so the app can load your name and photoStrictly necessary30 daysYes
sasq_logged_inDiumTells the app's scripts you are signed inStrictly necessary30 daysNo
sasq_display_nameDiumShows your name before your profile loadsStrictly necessary30 daysNo
MOAT_logged_in, MOAT_display_nameDiumThe same two flags, set by the sign-in pageStrictly necessary30 daysNo
dium_back_url, dium_back_slugDiumRemembers the partner page to return to. Being retiredStrictly necessary30 daysNo
[PHP session cookie name, default PHPSESSID]DiumServer session: anti-forgery (CSRF) token and where to send you after single sign-onStrictly necessaryUntil you close the browserYes

Browser storage Dium uses

NamePurposeCategoryHow long
dium_token (local storage)Keeps you signed in when Dium runs inside a partner's website, where cookies from dium.io cannot be usedStrictly necessaryUntil you sign out [confirm it is cleared on sign-out]
asq_onboarding (local storage)Remembers which steps of the welcome tour and checklist you finishedFunctional, part of the tour you asked for [COUNSEL: confirm classification]Until you clear site data
Dium cache (IndexedDB, with local storage fallback)Keeps recent Flows, Waves and messages on your device so pages open fast and stay in sync across tabsStrictly necessaryRefreshed as you use Dium; cleared with site data [confirm whether cleared on sign-out]
App cache (service worker, Cache Storage)Stores the app's own code and styles so it loads fast and works briefly offlineStrictly necessaryReplaced with each app version

Cookies from other services

When you sign in, the Werify sign-in widget runs on its own site (werify.ai) and may set its own cookies to complete the sign-in you asked for [confirm Werify cookie names and durations]. After sign-in, Dium hands you to Moat (moat.page) so you are signed in there too, and Moat sets its own sign-in cookies on moat.page. Werify Paywall sets its own cookies during checkout. These services' cookie policies apply.

Embedded videos and consent

The Dium app allows YouTube videos inside Waves and Pages. A standard YouTube embed can set YouTube cookies that are not strictly necessary. [DECISION: either load YouTube embeds from youtube-nocookie.com behind a click-to-play placeholder, or add a consent tool with equal Accept all and Reject all buttons before any embed loads]. Until that is done, this is the one place where Dium content can cause a non-essential cookie, and a consent tool is required for it.

Cookie settings

Because Dium only uses strictly necessary cookies and storage, there are no optional categories to switch on or off, so a Cookie settings link only needs to lead to this page [add a persistent Cookie settings link to the site and app footers that points here]. If we ever add analytics, functional or marketing cookies that need consent, we will add a settings panel with Essential, Functional, Analytics and Marketing choices, all non-essential ones off by default, and a Reject all button as easy to use as Accept all. We will ask you again before anything new runs.

You can also control cookies yourself. Your browser lets you view and delete cookies and site data. If you block Dium's strictly necessary cookies, you will not be able to stay signed in.

Global Privacy Control and Do Not Track

If your browser sends a Global Privacy Control (GPC) signal, we treat it as an opt-out of the sale and sharing of your personal information. [Confirm: we do not sell or share it today]. We do not use cookies for advertising, so the signal does not change how Dium works, but we honour and record it [confirm GPC handling in the app]. There is no common standard for Do Not Track, so we do not respond to it separately; the same limits apply either way.

Changes and contact

We will update this page before we add a new cookie or storage item, and date the change. Questions: [email protected]. See our Privacy Policy for everything else.