Last updated · 2026-09-11

Cookies and preferences

Necessary storage maintains your session and preferences. Optional measurement starts only with your permission.

Operator and service details must be completed before publishing this document.

English translation. Spanish is the reference version, subject to mandatory local language and consumer rights.

Identification and contact

Operator (individual)
To be completed by the operator
Address for legal notices
To be completed by the operator
Country of establishment
Colombia
Contact and privacy email
To be completed by the operator
Contact phone
To be completed by the operator

1. Necessary storage

The oruka_session cookie maintains sign-in for up to 30 days unless logged out or revoked earlier. OAuth flows use temporary state and verification cookies, normally up to ten minutes. These are necessary for secure sign-in or service connections.

The browser stores theme (oruka-theme), language (oruka-locale), sound and other interface preferences. These may remain until changed or cleared. oruka-consent stores the version, date and analytics choice for up to 180 days. It is not used for advertising.

2. Google Analytics: public visits

Only when configured and authorized, Google Analytics receives public page visits, technical information and a browser identifier using cookies such as _ga and _ga_*. Our events do not send query parameters, fragments or a navigation referrer. Google receives connection information when processing the request.

Explicit events are limited to allowed public pages, excluding private screens, sign-in, password recovery and customer forms. Cookies are configured for up to 180 days. Event retention depends on the property and is listed in the operations record. This integration does not enable advertising features.

3. PostHog: product use

Only when configured and authorized, we send general product screen names through PostHog's API. A random sessionStorage identifier (oruka-product-session) groups visits within the browser tab's session. It is removed when you withdraw this option and is not linked to your email or account.

No autocapture SDK is installed and no sessions, audio, forms, clicks or screen content are recorded. Conversation and customer identifiers and full URLs are not sent. The provider receives the network connection and may process technical data such as IP addresses; a random identifier does not make all processing anonymous. The US/EU destination and retention are described according to configuration.

4. Accept, reject or change

Both options are off before your choice. Accept the available options, reject them or choose each separately. Closing settings without saving does not grant consent. Rejection does not affect service access.

Your choice applies to this browser and origin and is requested again after expiry, policy-version changes or provider-configuration changes. Withdraw it just as easily from this site. Global Privacy Control overrides the choice and blocks optional analytics. Withdrawal stops future events and removes optional storage controlled by this integration; requests already transmitted cannot be recalled.

5. No exempt in-house measurement

This version does not include in-house audience measurement running without consent. Technical records needed to operate, protect and bill the service differ from optional analytics and are explained in the privacy policy. This integration includes no advertising cookies or cross-site tracking.

6. Browser controls

You can clear or block cookies and storage in your browser; blocking necessary items may prevent sign-in or saving preferences. Clearing oruka-consent prompts a new choice. Choices do not synchronize across devices. For data already sent, use the privacy-rights procedure.

This installation's operations record

Hosting
Vercel — web application and agent execution; function region iad1 (United States).
Database
Neon — PostgreSQL; AWS us-east-1 region (United States).
File storage
Neon PostgreSQL for application files. The media library may use Google Drive when you connect a Google account. No S3 bucket is configured for this installation.
Processing countries
Colombia (service operations) and the United States (verified Vercel and Neon infrastructure). Google APIs and AI or other integration providers may process data in other countries depending on the service and configuration you enable.
Retention, deletion and backups
To be completed by the operator
Analytics event retention
Google Analytics and PostHog are not configured for this deployment; the application does not send optional analytics events to them. If enabled, retention will be disclosed and your choice will be requested before sending events.