Table of Contents
- Introduction
- Definitions
- What Are Cookies?
- Types of Cookies
- How We Deploy Cookies
- Cookies We Use
- Third-Party Cookies
- Web Beacons & Pixels
- Do Not Track Signals
- Local Storage & Similar Technologies
- Legal Basis for Processing
- Cookie Consent
- Managing Cookies in Your Browser
- Mobile Devices
- Impact of Disabling Cookies
- International Data Transfers
- Automated Decision Making
- Children's Privacy
- Data Protection Officer
- Supervisory Authority
- Updates and Notifications
- Contact
Cookie Policy
1. Introduction
This Cookie Policy explains how Stellary ("we", "us", or "our") uses cookies and similar tracking technologies when you visit our website stellary.co or use our project management application (collectively, the "Service"). This policy is issued in compliance with the European Union's General Data Protection Regulation (GDPR), the ePrivacy Directive (Directive 2002/58/EC as amended by Directive 2009/136/EC), and the French Data Protection Act (Loi Informatique et Libertés).
We believe in transparency and want you to fully understand what cookies are, why we use them, and what options you have to control them. By using the Service, you consent to the use of cookies as described in this policy. You can manage your cookie preferences at any time through your browser settings or through the consent mechanism described in Section 12 below.
This Cookie Policy should be read together with our Privacy Policy and our Terms of Service, which provide additional context on how we collect, use, and protect your personal data. In the event of any conflict between this Cookie Policy and the Privacy Policy regarding cookie-specific matters, this Cookie Policy shall prevail.
2. Definitions
For the purposes of this Cookie Policy, the following terms shall have the meanings set out below:
- "Cookie" — a small text file placed on your device (computer, tablet, smartphone, or other electronic device) by a website you visit. Cookies are stored in your browser's cookie storage and typically contain a name, an expiration date, and a value (often a unique identifier).
- "First-party cookie" — a cookie set directly by the website you are visiting (in this case, stellary.co or app.stellary.co). These cookies are controlled exclusively by Stellary.
- "Third-party cookie" — a cookie set by a domain other than the one the user is visiting. Third-party cookies are typically used for cross-site tracking, advertising, and analytics purposes.
- "Session cookie" — a temporary cookie that exists only for the duration of your browser session. It is automatically deleted when you close your browser or when the session ends.
- "Persistent cookie" — a cookie that remains stored on your device for a predetermined period of time (which varies by cookie) or until you manually delete it. Persistent cookies are activated each time you visit the website that created them.
- "Personal data" — any information relating to an identified or identifiable natural person, as defined under Article 4(1) of the GDPR. In the context of cookies, this includes any data that can be used to directly or indirectly identify you, such as unique identifiers stored in cookies.
- "Controller" — Stellary, as the entity that determines the purposes and means of processing personal data through cookies on the Service.
- "Consent" — any freely given, specific, informed, and unambiguous indication of your wishes by which you, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to you, as defined under Article 4(11) of the GDPR.
- "Local storage" — a web browser feature (HTML5 Web Storage API) that allows websites to store key-value pairs of data locally within the user's browser. Unlike cookies, local storage data is not automatically sent to the server with each HTTP request.
- "Web beacon" — also known as a tracking pixel, clear GIF, or pixel tag. A small, typically invisible, image or piece of code embedded in a web page or email that is used to track user behavior, such as whether an email has been opened or a page has been visited.
8. Web Beacons & Pixels
Web beacons (also known as "tracking pixels", "clear GIFs", or "pixel tags") are tiny, invisible images — typically a 1×1 pixel transparent image — embedded in web pages or emails. When your browser or email client loads the page or email, it makes a request to the server hosting the beacon image, transmitting information such as your IP address, the time the page was viewed, the browser type, and whether cookies were previously set.
Web beacons are commonly used in conjunction with cookies to measure user activity, track email open rates, and build user profiles for advertising purposes. They are a widespread tracking technology used by advertising networks and analytics providers.
Stellary does not use web beacons, tracking pixels, or any similar invisible tracking technologies on its website, in its application, or in any emails sent to users. We believe in transparent, privacy-respecting communication and do not engage in covert tracking of any kind.
Emails sent by Stellary (such as notifications, password reset links, or workspace invitations) are plain functional communications and do not contain embedded tracking pixels or open-tracking mechanisms.
9. Do Not Track Signals
"Do Not Track" (DNT) is a web browser setting that sends a signal to websites requesting that they do not track the user's browsing activity. The DNT header is sent as an HTTP request header (DNT: 1) by the browser with each request. While the DNT standard has been proposed by privacy advocates and is supported by most major browsers, there is currently no universally accepted standard for how websites should respond to DNT signals, and the W3C Tracking Protection Working Group that was developing the standard was closed in 2019.
Stellary respects Do Not Track signals. However, because we do not engage in any cross-site tracking, behavioral profiling, or third-party cookie usage in the first place, the practical effect is the same whether or not a DNT header is present. Our Service already operates in a manner consistent with a DNT request by default.
Similarly, we respect the Global Privacy Control (GPC) signal, a newer browser-based mechanism that communicates a user's privacy preferences. When we detect a GPC signal, we treat it as a valid request to opt out of any non-essential data processing.
10. Local Storage & Similar Technologies
In addition to cookies, the Service may use local storage (HTML5 localStorage and sessionStorage) for the following purposes:
- Storing UI preferences (e.g., sidebar collapsed state, last viewed project, board view settings)
- Caching application data for performance optimization and reducing server load
- Storing draft content (e.g., unsaved card descriptions, document edits, comment drafts) to prevent data loss if you accidentally close a tab or navigate away
- Storing temporary authentication state during the OAuth login flow
- Maintaining client-side feature flags and configuration for the application interface
Local storage data remains on your device and is not transmitted to our servers automatically with each HTTP request (unlike cookies). The data is only accessible by JavaScript running on our domain (stellary.co and app.stellary.co) and cannot be read by other websites. You can clear local storage through your browser's developer tools (usually accessible via F12 → Application → Local Storage) or through your browser's settings by clearing site data.
Session storage (sessionStorage) works similarly to local storage but is automatically cleared when you close the browser tab. We use session storage for temporary data that should not persist between sessions, such as the state of multi-step forms.
11. Legal Basis for Processing
Under the GDPR and the ePrivacy Directive, different legal bases apply to different categories of cookies:
- Strictly necessary cookies (session, csrf_token, locale, cookie_consent): these cookies are exempt from the consent requirement under Article 5(3) of the ePrivacy Directive because they are strictly necessary for the provision of the Service explicitly requested by you. The legal basis for processing any personal data contained in these cookies is Article 6(1)(b) GDPR — processing necessary for the performance of a contract to which you are party, or in order to take steps at your request prior to entering into a contract.
- Functional cookies (remember_me, theme_preference, sidebar_state, last_workspace): these cookies require your consent under Article 5(3) of the ePrivacy Directive because, while they enhance your experience, they are not strictly necessary for the Service to function. The legal basis for processing is Article 6(1)(a) GDPR — your consent, which you provide through the cookie consent mechanism when you first visit the Service.
You may withdraw your consent for functional cookies at any time. See Section 12 below for instructions on how to manage your consent preferences.
14. Mobile Devices
If you access Stellary from a mobile device, you can also manage cookies through your mobile browser settings. Below are instructions for the most common mobile operating systems:
iOS (iPhone / iPad) — Safari
- Open the "Settings" app on your device
- Scroll down and tap "Safari"
- Under "Privacy & Security", you can enable "Prevent Cross-Site Tracking" and"Block All Cookies"
- To clear existing cookies: tap "Clear History and Website Data"
- For more granular control: "Settings" → "Safari" → "Advanced" →"Website Data" allows you to view and delete cookies per site
iOS — Chrome
- Open Chrome and tap the three-dot menu at the bottom
- Go to "Settings" → "Privacy and Security"
- Tap "Clear Browsing Data" to remove cookies
- Under "Content Settings" → "Cookies", you can block cookies
Android — Chrome
- Open Chrome and tap the three-dot menu in the top-right corner
- Go to "Settings" → "Privacy and Security"
- Tap "Clear browsing data" to remove cookies, cached images, and other data
- Under "Site settings" → "Cookies", you can block third-party cookies or all cookies
Android — Samsung Internet
- Open Samsung Internet and tap the hamburger menu
- Go to "Settings" → "Privacy and Security"
- Under "Accept cookies", toggle the setting to allow or block cookies
- Tap "Delete browsing data" to clear cookies and site data
- Samsung Internet also includes "Smart anti-tracking" which limits cross-site tracking
Please note that mobile browsers may handle cookies slightly differently than their desktop counterparts. Some mobile browsers may also limit the lifetime of cookies or apply additional privacy protections automatically.
16. International Data Transfers
All data collected through cookies on the Stellary Service is processed and stored exclusively within the European Economic Area (EEA). Our servers are hosted in data centres located in France and Germany, operated by European infrastructure providers.
We do not transfer any cookie data, or any personal data derived from cookies, to countries outside the EEA. This applies to all categories of cookies — strictly necessary, functional, and any future categories we may introduce.
Because we do not use any third-party cookies or third-party analytics services, there is no risk of your cookie data being sent to servers in the United States or other jurisdictions that may not provide an adequate level of data protection as determined by the European Commission.
If our data hosting arrangements change in the future, we will ensure that any transfers of personal data outside the EEA are covered by appropriate safeguards in accordance with Chapter V of the GDPR, such as Standard Contractual Clauses (SCCs) approved by the European Commission, and we will update this policy accordingly.
17. Automated Decision Making
Under Article 22 of the GDPR, you have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.
Stellary does not make any automated decisions based on data collected through cookies. Cookies are used exclusively for the technical purposes described in this policy (authentication, security, preferences). No cookie data is used to:
- Profile your behaviour or interests
- Make decisions about your access to features or pricing
- Evaluate personal aspects relating to you, such as performance, reliability, or behaviour
- Target you with personalised advertising
- Score or rank you in any way
The Stellary application may use artificial intelligence features for project management assistance (such as task suggestions or document summarisation). However, these AI features operate on application data you explicitly provide and are not influenced by or connected to cookie data in any way.
18. Children's Privacy
The Service is not directed to children under 16 years of age. We do not knowingly collect personal data from children under 16. If you are a parent or guardian and become aware that your child has provided us with personal data or has consented to cookies on our Service, please contact us at support@stellary.co and we will take immediate steps to remove such data and revoke any consent.
In accordance with the GDPR, where we rely on consent as the legal basis for processing (i.e., for functional cookies), such consent must be given or authorised by the holder of parental responsibility for children under 16 in France (the age may vary between 13 and 16 depending on the EU Member State).
19. Data Protection Officer
If you have questions or concerns about how your personal data is handled through cookies on the Stellary Service, or if you wish to exercise any of your rights under the GDPR (including the right of access, rectification, erasure, restriction of processing, data portability, or the right to object), you may contact our Data Protection Officer at:
Data Protection Officer
Stellary
Email: support@stellary.co
We will respond to your request within 30 days in accordance with Article 12(3) of the GDPR. In certain cases, this period may be extended by two further months where necessary, taking into account the complexity and number of requests. We will inform you of any such extension within one month of receipt of your request.
21. Updates and Notifications
We may update this Cookie Policy from time to time to reflect changes in technology, legislation, our business operations, or any other reason we deem necessary or appropriate. When we make changes, we will:
- Update the "Last updated" date at the top of this page
- Publish the revised policy on our website at the same URL
- For significant changes (such as introducing new cookie categories or third-party cookies), display a prominent notice on the Service and/or send an email notification to registered users
- Where required by law, obtain your renewed consent before implementing changes that affect non-essential cookies
We encourage you to review this policy periodically to stay informed about our use of cookies. We maintain an archive of previous versions of this policy, which is available upon request by contacting us at support@stellary.co.
Your continued use of the Service after any changes to this Cookie Policy constitutes your acceptance of the updated policy, except where your renewed consent is required by law.
22. Contact
If you have any questions, concerns, or requests regarding this Cookie Policy, our use of cookies, or your privacy rights, please do not hesitate to contact us:
Stellary
Email: support@stellary.co
We are committed to resolving any complaints about our collection or use of your personal data. We will endeavour to respond to all enquiries within a reasonable timeframe and will work with you to find a satisfactory resolution to any issue you raise.