1. Scope and current position
This notice applies to moduly.club and Moduly-controlled workspace pages. It should be read with the Privacy Policy. A cookie is a small value saved by a website in your browser; local and session storage are browser areas used to preserve a limited state on the same device.
Moduly currently uses only strictly necessary or user-requested storage. We do not currently set advertising, cross-site behavioural, or non-essential analytics cookies. If that changes, we will update this notice and deploy a consent control before setting those technologies where consent is required.
2. Technologies we use
The production application may use the following first-party technologies:
- __Host-moduly_session: an HttpOnly, Secure, SameSite=Lax session cookie used to authenticate a signed-in user. Its normal maximum lifetime is five days and it may end earlier when you sign out, the session is revoked, or security requires it.
- moduly_locale: a SameSite=Lax language-preference cookie retained for up to twelve months so public pages open in the language you selected.
- __Host-moduly_peqaboo_state and __Host-moduly_peqaboo_exchange: HttpOnly, Secure, SameSite=Lax cookies used only for the Peqaboo authentication hand-off. The state cookie normally expires within five minutes and the one-time exchange cookie within two minutes; both end earlier after use or cancellation.
- moduly_pending_organization and moduly_pending_legal_acceptance: local-storage values used while email or Google authentication completes. The organisation and email match may remain for up to seven days; the exact legal-acceptance hand-off may remain for up to thirty minutes. Successful completion clears the relevant value.
- moduly_pending_team_invitation: session storage in the active tab may keep the raw one-time invitation token for up to forty-eight hours. The token remains in the URL fragment and tab storage rather than a server URL. Successful acceptance clears it; after rejection or expiry it may remain until the tab session ends or you clear site storage, but the server will not accept it.
- moduly_checkout:{selection}: session storage may retain a random, non-payment idempotency key for a particular plan selection so retrying a Stripe Checkout request in the active tab does not create duplicate sessions. It can remain until the tab or browser session ends or you clear site storage; it contains no card or payment details.
- Feature state requested by you: browser storage may preserve an unfinished form or preference when the relevant interface says so. It must not contain passwords, full payment-card data, connector secrets, or veterinary records.
3. Third-party pages
When you deliberately continue to Stripe Checkout, a Google or Peqaboo sign-in page, Meta, or another connected service, that provider may set its own cookies under its own notice. Those pages are not Moduly-controlled cookie storage. We send only the data needed for the requested authentication, payment, or connector operation.
Moduly does not permit a connector to set third-party advertising cookies on Moduly pages merely because the connector is available.
4. Legal basis and controls
We use necessary storage to provide a secure service you requested, perform the contract, remember an explicit language choice, prevent duplicate operations, and protect accounts. Where applicable, this use is necessary rather than based on optional marketing consent.
You can delete or block cookies through your browser. Blocking the session cookie prevents sign-in; clearing temporary hand-off storage may require you to restart authentication, an invitation, or Checkout. Signing out clears the Moduly session cookie.
5. Changes and contact
We will update this notice before adding a materially different storage purpose. A material change to the incorporated legal bundle follows the version and re-acceptance controls in the Terms of Service.
Questions or privacy requests: privacy@decennium.app. General support: hello@decennium.app.