Service information · Updated 19 September 2026
Cookies & local storage
What Dynodoc stores in your browser, why it is there, and how to control optional performance measurements.
Sign-in and security
The workspace uses a secure, HTTP-only session cookie to keep you signed in. Short-lived cookies protect Google sign-in against forged requests. These are scoped to the host that sets them; your homepage visit does not disclose your workspace session to the analytics endpoint.
| Storage | Purpose | Duration |
|---|---|---|
dynodoc_session | Encrypted sign-in session. Access tokens are refreshed while your account remains active. | Up to 30 days; cleared on sign-out. Server-side revocation can end access sooner. |
oauth_state, oauth_verifier | Validate a Google sign-in request and its callback. | Up to 10 minutes; removed when the callback is processed. |
forms_pending | Bind the Google Forms connection to the signed-in researcher. | Up to 10 minutes. |
dynodoc_forms | Encrypted, HTTP-only read-only Google Forms connection, used only by the Forms import endpoint. | Up to one hour; cleared when you disconnect or sign out. |
dynodoc_guide_v1 (local storage) | Remember that you have seen or dismissed the welcome guide. | Until cleared in your browser. You can replay the guide at any time. |
dynodoc_metrics | Remember your performance-measurement preference across Dynodoc subdomains. | Up to 180 days. |
Performance measurements in PostgreSQL
Dynodoc measures page loads and web vitals to understand speed and responsiveness. These samples use a random identifier for the current page load, a coarse page category, a metric name and a number. The identifier is not saved in a tracking cookie or reused as a visitor identity.
Samples do not include document titles, text, form answers, full URLs, search terms, account emails or authentication cookies. They are sent to the Dynodoc workspace service and stored in PostgreSQL, with a 30-day retention job. Network infrastructure necessarily receives connection information such as an IP address; server and provider logs are separate from these metric records.
Page-load counts are not counts of unique people. Do Not Track and Global Privacy Control signals suppress this collection. We do not use these samples for advertising or cross-site profiling.
Your preference
Optional performance measurements are enabled for this browser unless a browser privacy signal disables them. Changing this preference affects future measurements; it does not remove samples already received.
Connected services
Google, Vercel and other services may apply their own storage and privacy practices when you visit or authenticate with them. A Google Forms connection is separate from normal Google sign-in. Disconnecting this browser clears its token; you can also remove Dynodoc’s grant in your Google Account.
Browser controls and questions
You can inspect, block or clear cookies and local storage in your browser settings. Blocking essential sign-in storage prevents authenticated workspace use. Clearing the guide preference may show the welcome message again. See the privacy policy for account and content handling, including retention and the operator-contact information still awaiting confirmation.