This is a convenience translation. In case of divergence, the Portuguese (pt-BR) version prevails.
Policy
Cookie Policy
Last updated: August 28, 2026version 1.0
01What cookies are
Cookies are small text files a site stores in your browser to remember information between visits, such as a preferred language or an authenticated session. Some are essential for the service to work; others only improve the experience.
02On this website (indene.io)
This website, today, writes no cookies of its own during ordinary browsing. Usage metrics come from two deliberately cookie-free tools: OpenPanel (self-hosted analytics, with an anonymous identifier in the browser's local storage) and Cloudflare Web Analytics (aggregate performance measurement). There is no advertising tracking and no third-party profiling cookie.
The only cookies that may appear on this domain are the ones below, under the conditions described:
| Cookie | Purpose | Duration | Category |
|---|---|---|---|
| indene_lang | Language preference read by the site's root router to direct you to the pt, en or es version. Only written when an explicit, persistent language choice exists; browsing works fully without it. | 1 year | functional |
| __cf_bm / cf_clearance | Cloudflare security cookies, written only during automated-traffic mitigation or a security challenge, to distinguish legitimate visitors from bots. | Minutes to hours, as mitigation requires | required |
03In the application (the product)
When you authenticate in the Indene product, the cookies below come into existence. The list is exhaustive: it reflects what the code writes, not a generic list.
| Cookie | Purpose | Duration | Category |
|---|---|---|---|
| authjs.session-token / __Secure-authjs.session-token | Keeps the session authenticated after the access code sent by e-mail. Without it, the product does not know who is logged in. | Session / as configured expiration | required |
| authjs.csrf-token | Protection against cross-site request forgery (CSRF) on the authentication forms. | Session | required |
| NEXT_LOCALE | Stores the language chosen inside the product (pt-BR, en or es) so it is not asked again on every visit. | 1 year | functional |
04Cookie categories
- Required: without them the function does not exist (authentication, form-fraud protection, attack mitigation). They require no consent, supported by the legitimate interest in security.
- Functional: improve the experience (remembering language), but everything works without them, just asking again on each visit.
- Analytics: we use no analytics cookie. The tools adopted measure without cookies; if that ever changes, this page will be updated and consent will be requested before anything is written.
- Marketing/advertising: we do not use them. The product is B2B, sold directly, with no targeted advertising.
05Third-party connections
For transparency, these are the network connections browsing this site may generate beyond our domain:
- analytics.uspery.cloud: the OpenPanel script and endpoint, operated on the site operator's own infrastructure (not a commercial third-party service).
- static.cloudflareinsights.com: the Cloudflare Web Analytics beacon, cookie-free.
The typefaces (Newsreader, IBM Plex Sans, IBM Plex Mono) are served from our own domain: unlike the market default, no connection is made to Google Fonts while you browse.
06How to manage or disable cookies
Required cookies cannot be disabled without breaking the function they protect (in the product, login). The others can be blocked in your browser settings, usually under Settings → Privacy and security → Cookies. Blocking the language cookie only means the preference is not remembered between visits.
09Legislation observed and target certifications
Legislation observed (in force)
- LGPD (Lei 13.709/2018)
- Marco Civil da Internet (Lei 12.965/2014)
- CMN Resolução 4.893/2021
- BCB Resolução 85/2021
Target certifications (none obtained)
- ISO/IEC 27001
- ISO/IEC 27701
- SOC 2 Type II