Cookie & Tracking Notice
Effective Date: September 19, 2026
Last Updated: September 22, 2026
Platform Provider: Startum Identity Platform ("Startum", "we", "us", or "our")
1. Overview & Purpose
This Cookie & Tracking Notice explains how Startum uses cookies, browser storage, and related web technologies across the Startum Account Portal (startum.cloud), Developer Portal (develop.startum.cloud), and OpenID Connect consent screens.
Startum uses cookies strictly for security, authentication, and session management. We do not use advertising cookies, cross-site tracking pixels, or third-party marketing analytics cookies.
2. Cookies We Use
Startum sets only first-party, essential cookies necessary for identity authentication and OAuth security:
| Cookie Name | Purpose | Security Flags | Expiration |
|---|---|---|---|
startum_session |
Stores cryptographically secure user authentication session ID for single sign-on across Startum services. | HttpOnly, Secure, SameSite=Lax, Domain=startum.cloud |
30 Days |
oauth_state |
Transient security token used to prevent Cross-Site Request Forgery (CSRF) during login / consent flows. | HttpOnly, Secure, SameSite=Lax |
10 Minutes (Single Use) |
pkce_verifier |
Transient cryptographic PKCE verifier stored during authorization code exchanges. | HttpOnly, Secure, SameSite=Lax |
10 Minutes (Single Use) |
Note: The startum_session cookie is scoped specifically to the identity authentication host (startum.cloud) to ensure session tokens remain strictly isolated and are not exposed to auxiliary or untrusted subdomains.
3. Local & Session Storage Usage
In addition to HTTP cookies, Startum web interfaces utilize browser sessionStorage and localStorage for essential user interface preferences:
- UI Theme Preference: Remembers whether light mode or dark mode is selected (
startum_theme). - Developer Code Snippet Preferences: Remembers active language tabs (Node.js, JS Popup, HTML) in the documentation viewer.
No personal identity claims or access tokens are stored unencrypted in browser storage.
4. Third-Party Cookies & Analytics
- Zero Third-Party Advertising Cookies: Startum does not integrate third-party ad networks, tracking pixels, or behavioral retargeting cookies.
- No Third-Party Analytics Trackers: Platform metrics (such as daily authorization requests and active app counts) are computed directly on Startum backends using aggregated, privacy-preserving server log metrics.
5. How to Control Cookies
Most web browsers allow you to manage cookie preferences through browser settings:
- Cookie Disabling Warning: Because
startum_sessionandoauth_stateare strictly essential for core authentication, disabling cookies in your browser will prevent you from signing in to Startum or authorizing third-party applications via Startum SSO. - Clearing Session Cookies: Logging out of the Startum Account Portal automatically clears and invalidates your active
startum_sessioncookie.
6. Contact Us
If you have questions about our use of cookies or session security:
Email: [email protected]
Account Portal: https://startum.cloud