Cookie policy
Last updated: September 3, 2026
This Cookie Policy explains which cookies and browser-storage technologies Lange Labs currently uses on lange-labs.com, auth.lange-labs.com, and mesh.lange-labs.com. Mix does not currently set separate browser storage. For information about other processing of personal data, please read our Privacy notice.
Cookies are small text files. Local storage is a separate browser mechanism, but it can also retain information on a device. The inventory below identifies the mechanism explicitly. Storage is host-specific unless a different domain is stated.
Necessary technologies
These items provide a feature requested by the user, preserve a privacy choice, authenticate a session, or protect a service. They are not used for advertising.
cookie-consent-store
- Mechanism, provider, and host: Local storage; Lange Labs; each of the three web hosts.
- Purpose and category: Necessary; stores whether analytics was accepted or rejected so optional code can remain disabled and the choice can be changed.
- Duration: Until the choice or site data is deleted.
- Legal basis: § 25(2) no. 2 TDDDG; where personal data is involved, Article 6(1)(c) GDPR together with Article 7(1) GDPR.
- Status: Active on all three web hosts.
umami.disabled
- Mechanism, provider, and host: Local storage; Lange Labs / self-hosted Umami; the host on which analytics is withdrawn.
- Purpose and category: Necessary privacy preference; prevents further Umami collection after withdrawal.
- Duration: Until analytics is accepted again or site data is deleted.
- Legal basis: § 25(2) no. 2 TDDDG; where personal data is involved, Article 6(1)(c) GDPR.
- Status: Set only after analytics is withdrawn.
lange-labs-language
- Mechanism, provider, and host: Local storage; Lange Labs;
lange-labs.com. - Purpose and category: Necessary preference; remembers the selected German or English interface language.
- Duration: Until changed or site data is deleted.
- Legal basis: § 25(2) no. 2 TDDDG; Article 6(1)(b) GDPR where personal data is involved.
- Status: Active on the public site.
project-flow-settings
- Mechanism, provider, and host: Local storage; Lange Labs;
mesh.lange-labs.com. - Purpose and category: Necessary preference; remembers the selected workflow edge style.
- Duration: Until changed or site data is deleted.
- Legal basis: § 25(2) no. 2 TDDDG; Article 6(1)(b) GDPR where personal data is involved.
- Status: Active when the setting is changed.
mesh_session and mesh_csrf
- Mechanism, provider, and host: First-party, host-only cookies; Lange Labs;
mesh.lange-labs.com. - Purpose and category: Necessary authentication and security;
mesh_sessionholds an opaque session token, whilemesh_csrfbinds write requests to the signed-in browser to prevent cross-site request forgery. - Duration: Up to 7 days under the current configuration; removed on logout.
- Legal basis: § 25(2) no. 2 TDDDG; Article 6(1)(b) and Article 6(1)(f) GDPR.
- Status: Active after Mesh sign-in.
__Secure-better-auth.session_token
- Mechanism, provider, and host: Secure first-party cookie; Lange Labs / Better Auth;
auth.lange-labs.com. - Purpose and category: Necessary authentication; identifies the Auth session.
- Duration: Up to 7 days; removed on logout.
- Legal basis: § 25(2) no. 2 TDDDG; Article 6(1)(b) and Article 6(1)(f) GDPR.
- Status: Active after Auth sign-in.
Temporary Auth security cookies
- Names:
__Secure-better-auth.state,__Secure-better-auth.oauth_state,__Secure-better-auth.two_factor, and__Secure-better-auth.better-auth-passkey. - Mechanism, provider, and host: Secure first-party cookies; Lange Labs / Better Auth;
auth.lange-labs.com. - Purpose and category: Necessary security; validates OAuth redirects, links a pending two-factor check, or binds a WebAuthn challenge to a passkey flow.
- Duration: 5 minutes for
stateandbetter-auth-passkey; 10 minutes foroauth_stateandtwo_factor. - Legal basis: § 25(2) no. 2 TDDDG; Article 6(1)(b) and Article 6(1)(f) GDPR.
- Status: Set only during the relevant Auth flow.
__Secure-better-auth.trust_device
- Mechanism, provider, and host: Secure first-party cookie; Lange Labs / Better Auth;
auth.lange-labs.com. - Purpose and category: Necessary preference and security; remembers a device only when the user selects “Trust this device”.
- Duration: 30 days.
- Legal basis: § 25(2) no. 2 TDDDG; Article 6(1)(b) and Article 6(1)(f) GDPR.
- Status: Optional user-requested Auth feature.
The theme local-storage key is read by dormant Mesh theme code but is not currently written by the application. Sidebar cookie code exists in generated UI components but no active SidebarProvider uses it. These dormant items are not presented as active storage and must be added above before the corresponding feature is enabled.
Analytics
After affirmative consent, the web host loads the self-hosted Umami script from a.lange-labs.com. Umami measures page views, referrers, language, screen size, browser, device, and operating system. The current tracker does not set an analytics cookie. Its server-side session value is derived from request information and is described in the Privacy notice.
Provider: Lange Labs (self-hosted Umami). Category: analytics. Host: the web host being visited, with requests sent to a.lange-labs.com. Duration: collection starts only after consent and stops for future activity after withdrawal. Legal basis: consent under Article 6(1)(a) GDPR and § 25(1) TDDDG. Status: active only after consent. No marketing technology is currently active.
Cloudflare edge security
The three web hosts and the analytics host are currently proxied through Cloudflare. Routine production requests checked on September 3, 2026 did not set a Cloudflare cookie, and the current application code does not embed Turnstile. Cloudflare may nevertheless set strictly necessary security cookies when an enabled rule challenges or distinguishes suspicious traffic:
__cf_bm: Cloudflare may set this necessary bot-protection cookie on the challenged Lange Labs host for 30 minutes after the last activity. It contributes to Cloudflare's encrypted bot score. The legal basis is § 25(2) no. 2 TDDDG and Article 6(1)(f) GDPR. It was not observed during the production check.cf_clearance: Cloudflare may set this necessary security cookie on the challenged host as proof that a challenge was passed. It lasts for the configured Challenge Passage period, which defaults to 30 minutes. The legal basis is § 25(2) no. 2 TDDDG and Article 6(1)(f) GDPR. It was not observed, and no Turnstile integration is active.
_cfuvid is not currently observed and must not be enabled through Cloudflare's unique-visitor rate-limiting option without first updating this inventory. Cloudflare documents its cookies in its cookie documentation.
Managing and withdrawing consent
Rejecting optional analytics is as direct as accepting it. Before a decision, analytics is off. After making a choice, use the Privacy settings button on any page in the legal section to reopen the manager. Disable Analytics and select Save preferences to withdraw consent. The Umami script is removed, its opt-out flag is set, and future analytics processing stops. Withdrawal does not affect processing that occurred lawfully before it.
The choice applies only to the current host, browser, and device. Browser controls can also delete site data or block cookies, but doing so may remove saved preferences or signed-in sessions.
Changes and questions
This inventory must be rechecked before enabling a new browser-storage feature and after changes to Auth, Mesh, Mix, analytics, Cloudflare security, or retention settings. Questions can be sent to [email protected].