Cookie Policy
Senest opdateret 8. august 2026 - Version 2.1
Dette dokument findes ikke på dit sprog. Den engelske version vises, og det er den, der er juridisk bindende.
This policy lists everything wallticker stores on your device, what each item is for, and how long it lasts. wallticker is operated by Luwall AB (org. nr 559359-5993), Sweden.
2. How We Use Them
Most of what we store is there to make the Service work: to keep you signed in, remember your language and the currency you asked to see prices in, protect against cross-site request forgery, and remember display preferences such as light or dark mode.
One thing is not necessary: product analytics, which counts how features are used and collects error reports so we can improve wallticker. We ask for it in the cookie banner, nothing is stored for it until you say yes, and you can change your answer at any time under Cookie settings. We use no advertising cookies and take part in no cross-site tracking - see "Legal basis" below.
4. Local and Session Storage
We also keep a small amount of interface state on your device. The entries listed below are never sent to our servers and contain no personal data - only how you like the app arranged. They stay on the device you set them on. Analytics storage works differently and is described after the list.
- wallticker.period-range, wallticker.list-mode, wallticker.view-settings - which period and view the home page opens on.
- wallticker.reports-view, wallticker.reports-table-config, wallticker.report-export-config - your last-used report and export layout.
- wallticker.default-preset-hidden - remembers that you removed the built-in Default export preset on this device.
- wallticker.projects-sections - which sections of the clients, projects and tags page you left open.
- wallticker.entry-sort - your chosen sort order for the current session.
- wallticker.runaway-dismissed - remembers that you dismissed a forgotten-timer prompt, for the current session only.
- theme - your light or dark mode choice.
Analytics is the exception to the paragraph above. If you allow it, PostHog stores its identifier in local storage under the same ph_* name as the cookie in section 3, so it survives if cookies are cleared, and it may use session storage the same way for the current visit. That identifier is sent to PostHog - that is what it is for. Withdrawing consent under Cookie settings removes every ph_* entry from cookies, local storage and session storage alike.
5. Legal Basis
Under the ePrivacy Directive and its Swedish implementation, storing information on your device requires consent unless it is strictly necessary to deliver a service you requested.
Everything listed above except the analytics entries is strictly necessary in that sense: without it you could not stay signed in, your language and currency choices would be lost on every page, and the security protections would not function. The language, currency and display preferences are stored only when you actively choose one, and are used for nothing but showing you the interface you asked for. These require no consent and none is asked for them.
Analytics is different. The ph_* cookie and storage are not necessary to deliver the Service, so we rely on your consent under Art. 5(3) of the ePrivacy Directive and Art. 6(1)(a) GDPR. We ask in the cookie banner before anything is written, and refusing costs you nothing - the Service behaves identically either way. You can withdraw at any time under Cookie settings, reachable from the site footer and from your account settings, and withdrawing deletes the identifiers from this browser. Your answer itself is remembered in wallticker.cookie-consent so that we do not keep asking; storing that answer is necessary in order to respect it.
6. Third-Party Cookies
Our analytics provider PostHog sets no cookie on its own domain - the ph_* cookie in section 3 is set on ours - but PostHog does receive what it collects, which makes it a third-party recipient, and its script runs only after you allow analytics. We set no advertising cookies and take part in no cross-site tracking or advertising networks. If you sign in with Google or GitHub, or connect a Google Calendar, those providers may set cookies on their own domains during sign-in, governed by their own policies. Stripe does the same on its checkout pages if you buy a paid plan.
8. Changes to This Policy
We update this policy whenever we add, remove, or change what we store on your device. The version and date at the top of this page always reflect the current version.