Consent & device storage
Cookie Policy
- Operator:
- Science Communications Worldwide (Science Communications Worldwide - Verein zur weltweiten Verbreitung wissenschaftlicher Kommunikation)
- Last updated:
- 21 September 2026
- Effective:
- 21 September 2026
- Version:
- 2.4 — supersedes the revision dated 20 September 2026
In short
Overview and legal framework
Storing information on your device, or reading information from it, requires your consent under § 165(3) of the Austrian Telecommunications Act (TKG 2021, implementing the EU ePrivacy Directive) — unless the storage is strictly necessary to provide a service you have explicitly requested. Any personal data involved is additionally governed by the GDPR and our Privacy Notice.
Accordingly, we separate storage into two classes: essential (sign-in, security, forgery protection, your consent choice itself, interface preferences you set — no consent required) and analytics (set only after you opt in). We use no marketing or advertising storage of any kind.
Browser storage we use
Beyond cookies, the application uses browser storage for small device-side conveniences and consented analytics state. The PostHog entries identified below are the only entries in this table that are read by a third-party analytics library.
| Entry | Purpose | Lifetime |
|---|---|---|
| world-wide:cookie-consent-sync and world-wide:cookie-consent-decision | Synchronises the latest consent status, timestamp, and random decision identifier across open tabs | Until you clear site data |
| Interface preferences (brand accent, view mode, resolved timezone, event-filter keyword and type, dismissed sign-up prompt, notification read marker) | Remembers display choices on this device | Until you clear site data |
| Device-side lists (bookmarks, followedSpeakers, jobAlerts) | Keeps items you save, speakers you follow, and job-alert criteria you set on this device | Until you remove them or clear site data |
| Short-lived navigation and recommendation context | Remembers recently viewed domains, the previous page, and a bounded recommendation cache in the current tab | Session storage — deleted when the tab closes |
| Sign-in coordination entries (world-wide.auth.refresh.*) | Prevents multiple tabs from refreshing your session simultaneously | Until you clear site data |
| Draft autosave and upload recovery (world-wide:draft:v2:*, CV editor drafts, world-wide:presigned-upload-recovery:v1:*) | Recovers half-finished submissions, profile documents, and interrupted file uploads in this tab | Session storage — deleted on submit or when the tab closes |
| Support and error context (last support ticket, incident de-duplication) | Pre-fills the support form after an error and avoids duplicate reports | Session storage — deleted when the tab closes |
| ww-analytics-ignore | Per-device exclusion flag: while present, this device is excluded from all measurement regardless of consent | Until you remove it |
| world-wide:analytics-principal | Keeps consented analytics events assigned to the correct anonymous or signed-in principal and is cleared on rejection | Until consent is withdrawn, you sign out, or you clear site data |
| ww.search.destination.pending.v1 | Links a consented search to the result you open from it; written only after analytics consent | Session storage — deleted when the destination page loads or the tab closes |
| world-wide:posthog-consent | Remembers whether the consented PostHog replay library is opted in or out so withdrawal remains effective | Local storage — until you change the choice or clear site data |
| ph_<project-token>_posthog | Keeps the anonymous PostHog replay session continuous within the current tab; created only after analytics consent | Session storage — deleted when the tab closes or when consent is withdrawn |
| IndexedDB database "ww-analytics" | Offline queue for consent-gated analytics events; entries are deleted once transmitted, and purged whenever consent is absent | Transient |
What analytics collect (with consent)
4.1 First-party analytics
Our own measurement stores its data in our EU-hosted database and is enforced on both sides: the browser sends nothing without consent, and the ingestion APIs reject unconsented requests. With consent, we record: pages viewed, referrer, campaign (UTM) parameters, search terms entered, product interactions (saving, sharing, following), clicks on outbound links (destination site and page only — never query parameters), performance timings, and sanitised semantic failure categories. We do not record exception messages or stack traces for product analytics.
Identifiers are deliberately weak: a random session identifier that expires after one day, and a fingerprint computed as a keyed hash over a truncated network prefix and coarse browser characteristics. Raw IP addresses are not written to our database. Location is recorded at country level from our content delivery network; no external IP-geolocation service is used.
4.2 Google Analytics 4
With the same consent, Google Analytics 4 (Google Ireland Ltd / Google LLC) runs alongside. Our configuration is restrictive: Google’s Consent Mode starts in a fully denied state; advertising storage and ad personalisation remain permanently denied even after you accept; IP anonymisation is on; Google signals and cross-site linking are off; page paths are truncated to their first segment before being sent, except that the FENS poster-upload page is reported as /fens-26/poster-upload; and no account identifiers are transmitted. Consented GA4 also receives coarse actions such as a server-confirmed submission, but not the submitted content. If you withdraw consent, we instruct Google to stop and delete the Google Analytics cookies from your browser. Google may process this data in the United States under the safeguards described in the Privacy Notice, Section 8.
4.3 PostHog product analytics
After the first-party database records a selected product event, our server may send PostHog US Cloud a minimal pseudonymous copy. It uses separate hashed identities and session identifiers, stable semantic event names, generalised route templates, coarse device and source context, and hashed entity references. Search text, form content, query strings, raw World Wide account, session, and content identifiers and email addresses are not sent. Anonymous events do not create a person profile. Separately, after the same consent, a PostHog browser library records interaction replays only on approved public, non-sensitive pages. It masks every form input, select, and textarea before transmission; blocks forms, dialogs, account menus, file and hidden inputs; strips query strings and fragments; and excludes account, sign-in, administration, Library, calendar, settings, employer, submission, upload, contact, and support routes. Network bodies and headers, console logs, canvas content, cross-origin frames, heat maps, automatic product events, and exception capture are disabled. Visible public-page text, layout, pointer interaction, and navigation are recorded. Your browser necessarily exposes its IP address and basic request metadata to PostHog when delivering a recording, but World Wide does not place that IP address in the replay event payload. PostHog sets no cookie; it uses the consent and tab-session storage entries listed in Section 3. A provider outage cannot block the action you take on World Wide.
Third-party content your browser loads
The consent banner governs analytics. Independently of it, some features fetch content directly from third parties when you use them, which necessarily reveals your IP address and browser characteristics to that provider:
- Maps — basemap tiles and the map stylesheet load from CARTO (basemaps.cartocdn.com) and unpkg.com on pages that display a map;
- Embedded recordings — an external player is not contacted when the World Wide page renders. A labelled placeholder identifies the provider. Only after you choose to load it does your browser contact YouTube (in privacy-enhanced “nocookie” mode), Vimeo, Loom, Crowdcast, Dailymotion, or Spotify; that provider’s own privacy and cookie rules then apply;
- Profile images — avatars referenced from external services (for example Gravatar or Google) load from those hosts;
- Posting security checks — the default check requests a short-lived challenge from World Wide and solves it locally in your browser. It sets no third-party cookie and sends no data to Google. You may instead choose “Load Google security check”; only that explicit choice contacts reCAPTCHA and reveals browser and network information to Google. A completed check is required to post, but never to browse the site.
None of these providers receives your World Wide account identity from us.
Managing your choice
Give or withdraw analytics consent here — the control below has exactly the same effect as the banner:
You have not made a choice in this browser yet. Until you do, optional analytics stay off.
Your choice takes effect immediately, applies to this browser, and can be changed here at any time. Withdrawing consent stops future analytics collection; it does not affect the lawfulness of processing that took place while consent was active.
You can additionally clear cookies for world-wide.org in your browser settings at any time; the consent banner will then appear again on your next visit. Essential cookies re-establish themselves as you use the site, because signing in and posting are impossible without them. Note that we periodically version the consent value — after a material change to what analytics collect, earlier acceptances expire and you will be asked again.
How your decision is recorded
Article 7(1) GDPR requires us to be able to demonstrate consent. When you accept or reject analytics we therefore store one consent record — the decision, its timestamp, the policy version, and pseudonymised technical context — on our servers, for both choices. This record is the proof of your decision, not a measurement of your behaviour. The cookie holding your choice on your device is described in Section 2.
Do Not Track and browser signals
Because analytics are off unless you opt in, first-party analytics and Google Analytics do not additionally interpret Do Not Track or Global Privacy Control signals — the default state already is what those signals request. The PostHog replay library does not record while your browser sends Do Not Track, even after consent. Automated browsers (WebDriver) are excluded from measurement regardless of consent.
Questions about this policy: info@world-wide.org.
Contact
For legal, privacy, and policy inquiries, email info@world-wide.org.