Last updated: August 23, 2026
Reflexive primarily uses browser localStorage (on your device), not classic cookie files. These are technical records: sign-in tokens, UI language, theme, note drafts, cookie consent and similar settings. Account personal data (notes, email, etc.) is stored on the server in Helsinki, Finland (EU) — not in localStorage. Third-party services (Google OAuth) may set their own cookies when you sign in through them.
Essential (required for the Service): authentication (JWT in localStorage), session security, language and theme, input drafts, selected note branch, recorded cookie consent (key reflexive-cookie-consent). The Service cannot work properly without them. Optional (only after “Accept all” in the banner): future usage analytics (not active today). Marketing emails — separate opt-in at registration, not via the cookie banner.
Sign-in tokens — until logout or token expiry. UI settings — until you clear site data in the browser. Cookie consent — until withdrawn or policy version changes (the banner may reappear after policy updates).
Clear site data for reflexive.at in your browser settings or delete localStorage for the domain. This will sign you out and reset settings. To withdraw consent for server-side processing and delete your account — Telegram @sefrwea. To withdraw marketing email consent — account Settings.
This policy is governed by the GDPR and applicable EU/EEA national law for processing in Finland. If you use the Service from the Republic of Kazakhstan or other countries outside the EEA, local rules may also apply.