Cookie / Storage Notice
Last updated: July 27, 2026
This Cookie / Storage Notice explains how GetHug uses cookies and similar technologies, including localStorage and sessionStorage, when you access the website and its workflows. It describes the technologies currently in use, their purposes and typical durations, which technologies are essential, which are optional, and how to give, refuse, review, or withdraw consent.
For server-side processing of account information, scripts, uploaded files, graph sessions, saved content, public creator profiles, public scripts, public graph recipes, support messages, technical logs, and analytics data, read the Privacy Policy.
1. Legal framework and categories
GetHug distinguishes between:
- Essential technologies, which are necessary to provide a feature you request, maintain authentication and security, preserve limited workflow continuity, or remember your privacy choice.
- Optional analytics technologies, which help measure aggregate use of pages and features and are used only after you actively grant analytics consent.
GetHug does not currently use advertising cookies, Google Ads, DoubleClick, AdSense, marketing pixels, cross-site marketing trackers, behavioral-advertising technologies, or advertising personalization.
2. Your consent choice
On the first visit without a valid stored preference, GetHug presents a banner that allows you to:
- Continue without optional analytics by selecting the close control or “Reject optional”.
- Accept optional analytics.
- Open detailed preferences, where necessary storage remains enabled and analytics can be enabled or disabled.
Acceptance and rejection are intended to be equally accessible. Optional analytics is not required to create an account or use essential GetHug features. Scrolling or continuing to browse is not treated as consent.
You can review or change the choice at any time through the “Cookie settings” or “Review cookie choices” link available in the footer of every consent-enabled GetHug page.
3. Current cookie and storage inventory
| Technology | Category and provider | Purpose and typical content | Typical duration |
|---|---|---|---|
| GetHug session cookie Technical name determined by server configuration |
Essential; GetHug | Maintains authentication, associates requests with the correct session, supports request validation, account security, and restricted workflow actions. | Usually the browser session or another limited server-configured period. |
gh_consent_v1localStorage |
Essential preference storage; GetHug | Stores the consent-format version, analytics granted or denied, marketing denied, and the update timestamp so GetHug can respect and document the choice. | Approximately 180 days from the recorded update, until changed, cleared, invalidated by a new consent version, or removed earlier. |
| Workflow-intent values sessionStorage or session-supported state |
Essential; GetHug | Prevents duplicate or unintended workflow-session creation and helps preserve the correct workflow action. | Usually the current browser tab, session, or limited workflow period. |
| Graph Maker resume reference localStorage |
Essential or user-requested functionality; GetHug | May contain a graph-session identifier, the page used to resume the session, and an update timestamp so an authorized user can return to recent work in progress. | Until replaced, cleared, removed by GetHug code, or no longer useful. |
| Editor and interface state localStorage or sessionStorage |
Essential or user-requested functionality; GetHug | Remembers limited panel positions, open or closed states, selected views, and continuity information needed to resume an in-progress workflow. | Current tab or session, or until replaced or cleared, depending on the feature. |
_ga |
Optional analytics; Google Analytics | Stores a pseudonymous client identifier used to distinguish browsers after analytics consent. | Google documents a default expiration of up to two years, subject to browser limits, renewal behavior, deletion, and withdrawal. |
_ga_ZXY6QZG7YG |
Optional analytics; Google Analytics | Preserves session state for the GetHug Google Analytics 4 stream after analytics consent. | Google documents a default expiration of up to two years, subject to browser limits, renewal behavior, deletion, and withdrawal. |
Google Tag Manager container GTM-WRTCTNLN is a tag-delivery mechanism. In the current
configuration it is not loaded until analytics consent and is used only to load the Google Analytics 4
tag described below. GetHug does not currently configure a separate advertising or marketing tag in the
container.
4. Optional Google Analytics 4
Only after you accept analytics does GetHug load:
- Google Tag Manager container:
GTM-WRTCTNLN. - Google Analytics 4 measurement ID:
G-ZXY6QZG7YG.
The current implementation records page loads only. Browser-history page changes, scrolls, outbound clicks, site search, video engagement, file downloads, and form interactions are disabled in Enhanced Measurement. Custom GetHug workflow events are not currently connected to operation-success paths.
GetHug has also configured the Analytics property as follows:
- Google Signals is disabled.
- Google Analytics User-ID is not configured.
- Collection of user-provided data is disabled.
- Granular location and device collection is disabled in all available regions.
- Advertising personalization is disabled in all available regions.
- No Google Ads, Google AdSense, Google Ad Manager, Display & Video 360, or Search Ads 360 product link is configured.
- Optional Analytics account data-sharing settings are disabled.
- User-level and event-level Analytics retention is set to two months, with reset on new user activity disabled.
Analytics information may include:
- A pseudonymous browser identifier and session identifier.
- Page path and page title.
- A sanitized page URL and sanitized referrer containing origin and path only.
- Date, time, session statistics, language, country- or region-level location, and general browser, operating-system, and device-category information.
- Consent and tag-configuration information required to operate Consent Mode.
Because granular location and device collection is disabled, Google Analytics is not configured to collect city, detailed browser user-agent strings, device brand, device model, device name, minor browser or operating-system versions, platform minor version, or screen resolution for new data.
GetHug does not intentionally send names, email addresses, account identifiers, profile slugs, filenames, uploaded files, source code, datasets, graph specifications, support-message text, URL query strings, or URL fragments to Google Analytics. Do not place personal data in public URL paths or page titles.
GetHug removes query strings and fragments from the Analytics page URL and referrer. Google Analytics
email redaction and URL-query-parameter redaction are also enabled for
email, email_address, first_name,
last_name, name, user_id, token,
access_token, api_key, key, code,
session, and session_id. Redaction is a supplementary, best-effort safeguard.
Google states that IP addresses are used during collection to determine the appropriate collection location and geographic information and are discarded before being logged in Google Analytics. Data is transmitted over HTTPS.
5. Consent Mode settings
GetHug uses a consent-first Basic Consent Mode implementation. Before any choice, the page establishes these default states locally:
analytics_storage: deniedad_storage: deniedad_user_data: deniedad_personalization: denied
Google tags are not loaded while analytics consent is absent or denied. If you accept analytics,
analytics_storage changes to granted, while every advertising-related state
remains denied.
6. Preference renewal and material changes
A valid choice is normally remembered for approximately 180 days so the banner is not repeatedly shown. The banner may be shown sooner when:
- You clear cookies or browser storage.
- GetHug cannot read a previously stored choice.
- The consent format changes.
- The analytics purpose, provider, categories, or other material processing conditions change.
After the preference expires, GetHug may request a new choice. A later choice replaces the earlier one.
7. Withdrawing or changing consent
You may withdraw analytics consent as easily as you grant it:
- Open “Cookie settings” or “Review cookie choices”.
- Disable Analytics.
- Save the preference.
After withdrawal, GetHug records analytics as denied, removes accessible first-party
_ga and _ga_* cookies from the GetHug domain, reloads the page when necessary,
and does not load Google Analytics on later page views. Withdrawal does not retroactively erase data
lawfully processed before withdrawal; privacy-rights requests may be sent using the contact details in
the Privacy Policy.
8. Blocking or clearing essential storage
Most browsers let you inspect, block, or delete cookies and site data, including localStorage and sessionStorage. Blocking or clearing essential storage may:
- Sign you out.
- Interrupt account, form, or request security.
- Prevent authenticated pages from loading correctly.
- Remove Graph Maker resume information.
- Reset editor positions or interface state.
- Interrupt an in-progress workflow.
- Cause the consent banner to appear again because GetHug can no longer read the previous choice.
Clearing a browser reference does not necessarily delete associated account content, saved projects, support threads, security records, Analytics records already processed, or server-side workflow data. See the Privacy Policy.
9. Google and international processing
Google Analytics is provided by Google entities identified in the applicable Google terms, which may include Google Ireland Limited and Google LLC. Analytics data may be processed in the United States or other countries. GetHug has accepted the applicable Google data processing terms, disabled optional Analytics account data-sharing settings, and configured no advertising-product links. Google describes its own privacy, security, subprocessor, retention, and international-transfer practices in its service terms and privacy documentation.
Where required, transfers may rely on an adequacy decision, the EU-U.S. Data Privacy Framework where applicable to a certified recipient, standard contractual clauses, supplementary measures, or another lawful transfer mechanism.
10. Global Privacy Control and Do Not Track
GetHug does not currently sell personal data, share personal data for cross-context behavioral advertising, use targeted-advertising trackers, or enable advertising personalization. Therefore, Global Privacy Control and browser “Do Not Track” signals do not currently trigger a separate advertising opt-out. Analytics remains off unless you actively consent, and you can withdraw consent through GetHug's preference control.
11. Third-party links
Public creator profiles, scripts, and graph recipes may contain user-selected links to personal websites, LinkedIn, GitHub, Google Scholar, ORCID, or other third-party sites. Visiting a third-party site may allow that site to use its own cookies or tracking technologies under its own policies. GetHug does not control storage used by third-party sites.
12. Changes to this notice
We may update this Notice to reflect changes in the Service, storage behavior, consent interface, analytics configuration, providers, or legal obligations. We will update the “Last updated” date and request renewed consent where required before materially changed optional processing begins.
13. Contact
Questions about this Cookie / Storage Notice may be sent to:
Data Controller: Federico Cosenza
Italy
Privacy contact: privacy@get-hug.com