← Back to Derive

Cookies and Local Storage

In force from 7 September 2026

Every cookie and storage key that derivenotes.com and the Derive app actually set, what each one is for, how long it lasts, and how to control it. Written from the code, not from intention.

This notice covers the Derive app (web, Mac, Windows, iPhone and iPad) and the marketing website at derivenotes.com. It is published by Derive Notes Pty Ltd (ACN 696 859 597), 2/290 Boundary Street, Spring Hill QLD 4000, Australia. It sits under the Privacy Policy. Questions go to matt@derivenotes.com.

The short version

The Derive app sets no cookies at all. It is a statically exported application with no server of its own, and it keeps everything it needs on your device in local storage and in a local database.

The marketing website does use cookies. It asks you about the analytics ones on your first visit. One cookie, visitor_id, is set before you answer, and this notice says so plainly below rather than pretending otherwise.

What we mean by these words

  • Cookie: a small file the website asks your browser to store and send back on later visits.
  • Local storage: a place in your browser or app where we keep small settings on your device. It is not sent back automatically the way a cookie is.
  • Local database (IndexedDB): a larger store on your device where the app keeps your notebooks so it works offline.
  • Strictly necessary: without it, something you asked for stops working. These do not need your permission anywhere in the world.

The marketing website: cookies

CookieSet byWhat it is forStrictly necessaryHow long it lastsWhen it is set
visitor_idDeriveA random identifier used to decide which version of the home page headline you see, so we can measure which wording works. It is not linked to your name or email, and it is not sent to your browser's analytics. It is passed to PostHog on our server to pick the headline variantNo365 daysOn your first request, before the cookie banner appears and whatever you later answer
derive_waitlist_metaDeriveRemembers where you arrived from: campaign tags in the link, a referral code, and which page variant you landed on. It is read when you join the waitlist so we know which link brought youNo30 daysOnly when a link you follow carries campaign tags, a referral code, or an access key. Set before the banner is answered
derive_siteDeriveRemembers which version of the site you asked to see, when you follow a link that specifies oneYes30 daysOnly when a link includes a site choice
tester_sessionDeriveKeeps an invited tester signed in to the restricted download portalYes7 daysOnly when a tester signs in to the portal
ph_(key)_posthogPostHogWebsite usage analytics: pages viewed, clicks, scroll depth, campaign tags. Stored as both a cookie and a local storage entryNo365 days, set by PostHog's defaultOnly after you answer yes to the banner. PostHog is not loaded at all before that

Your consent choice is stored in local storage under derive_analytics_consent, not in a cookie. It holds the word "granted" or "denied" and nothing else. It lasts until you clear it or choose "Ask me again next visit" on this page.

What happens before you answer the banner. The visitor_id cookie is set on the first request to the site. Our server uses it to ask PostHog which home page headline to show you. That is a feature flag lookup keyed on a random identifier. No page views, clicks or other events are recorded against it before you say yes. If you say no, the cookie stays in your browser until it expires, and the only thing it is ever used for is picking the headline. The derive_waitlist_meta cookie is also set before you answer, but only if the link you arrived on carried campaign or referral information.

What PostHog receives when you say yes. PostHog loads and records pages viewed, clicks, scroll depth and the campaign tags on the link you arrived on. If you join the waitlist, your email address is sent to PostHog as your identifier, so your earlier anonymous events are joined to it. If you buy a subscription on the website, the payment event is recorded in PostHog against your email address, and a cancellation is recorded against your Stripe customer id. That is more than usage and diagnostics, so we say it here.

Website analytics processing location. PostHog for the website is hosted in the United States. Requests go through our own domain first and then on to PostHog.

The Derive app: local storage and on-device data

The app sets no cookies. The following items are stored on your device.

ItemWhat it is forStrictly necessaryHow long it lastsHow to control it
sb-(project)-auth-tokenKeeps you signed in. Holds your session tokenYesUntil you sign out or clear app storageSign out, or clear the app's storage
derive_settings_v1Your settings: theme, tool preferences, AI switch, analytics choice, age band, onboarding answersYesUntil you sign out or clear app storageSettings, or clear app storage
Local notebook database (IndexedDB)Your pages, strokes, assistant conversations, the queue of changes waiting to sync, and staged images. This is what makes Derive work offlineYesUntil you sign out or clear app storageSign out clears it, or delete the app
derive_analytics_id_v1A random identifier for usage analytics. It is not your account id, your name or your emailNoUntil you sign outTurn off "Share usage analytics" in Settings, Account. Signing out removes it
ph_(key)_posthogPostHog's own storage for usage analyticsNoSet by PostHog; removed on sign outSame as above
derive_analytics_first_stroke_v1, derive_analytics_last_stroke_at_v1Marks whether you have drawn your first stroke, so we can count activation once instead of on every launchNoUntil you sign out or clear app storageSame as above
derive_internal_device_v1Marks a device that has been used to sign in to a Derive staff account, so staff activity is never counted in product analyticsNoPermanent on that device, including after sign outClear app storage
derive.geo.countryThe country we detected, used to show you the right price and to apply the right privacy rules to your accountYesCached for reuse until clearedClear app storage
derive.ageGateLocked.(account id)Marks an account that answered under 13, so the app does not let it back inYesPermanent on that deviceNot user controllable by design
derive_global_theme, derive_sidebar_layout, derive-library-view, derive-view-mode, derive_portrait_hint_dismissed, derive_new_page_background_preferenceInterface preferences: your theme, how the sidebar and library are laid out, and which hints you have dismissedYesUntil you clear app storageChange the setting, or clear app storage
derive_conversion_enabledWhether handwriting conversion is on for this deviceYesUntil you clear app storageSettings, AI

Country detection. On launch the app asks our website for the country your internet connection appears to be in. That request goes to our hosting provider Vercel, which sees your IP address in order to answer it. If that request does not succeed, the app falls back to your device's time zone and then to your device's language setting. We store the country and which of those three signals produced it.

What we do not use

  • No advertising cookies on the marketing website, and none in the Mac, Windows, iPhone or iPad apps.
  • No Google Analytics, no Google Tag Manager, no TikTok, LinkedIn or X tag, no Hotjar and no Clarity, anywhere.
  • We do not sell personal data, and we build no advertising profile of you.
  • One exception, and it is new. The Derive web app at web.derivenotes.com carries the Meta pixel, so that we can tell whether an advert led to a sign up. It loads only if you accept analytics, and not at all if your browser sends a Global Privacy Control signal. It sets two cookies of Meta's, _fbp and _fbc, which identify the browser and the advert clicked, and we keep derive.meta.fbclid and derive.meta.eventIds in that app's local storage for up to 90 days for the same purpose. It applies only to accounts created from 7 September 2026: if your account is older than that, the pixel does not load while you are signed in and nothing about you is sent. A hashed email address is sent only for accounts we know to be 18 or over, and never for a user under 18 or of unknown age. Privacy policy section 13.6 has the detail. An earlier version of this page said there was no Meta pixel; this bullet is the correction.
  • The app shows no App Tracking Transparency prompt on iPhone or iPad, because the iPhone and iPad apps do not track you across other companies' apps or websites.

Your choices, by region

Inside the European Economic Area and the United Kingdom. Usage analytics in the app are off until you turn them on in Settings, Account. If you are under 16 we do not offer the choice at all and analytics stay off. Screen recording is off, with no way to turn it on today.

Everywhere else. Usage analytics in the app are on by default and you can turn them off at any time in Settings, Account. They are always off for an account that has told us it belongs to someone under 13. If we could not work out your country, analytics stay off until you turn them on.

Screen recording. The app contains a screen recording capability which, if it were switched on, would record the canvas, and therefore your handwriting, at four frames per second. It is switched off for everyone. There is no control in the app that turns it on. It is deliberately separate from usage analytics, so turning analytics on does not start it. If we ever turn it on it will be opt in, and we will update these documents first.

The website. We ask on your first visit. Saying no changes nothing about how the site works and we do not ask again. You can change your answer at any time on this page.

Browser privacy signals. We do not currently detect or act on Global Privacy Control or similar browser opt out signals. Your answer to the banner is the control that works.

Turning things off after the fact

Turning analytics off stops new data being collected. It does not delete what was already collected. Email matt@derivenotes.com and we will delete it.

Privacy Policy, Terms of Service, Subprocessors, Children and students, AI disclosure, Data processing addendum.

You have not been asked yet, so analytics is off.

Turning analytics off stops new data being collected. It does not delete what was already collected; email us and we will remove it.