Skip to content

Consent & device storage

Cookie Policy

Operator:
Science Communications Worldwide (Science Communications Worldwide - Verein zur weltweiten Verbreitung wissenschaftlicher Kommunikation)
Last updated:
21 September 2026
Effective:
21 September 2026
Version:
2.4 — supersedes the revision dated 20 September 2026

In short

World Wide works without any tracking by default. Essential cookies keep you signed in and keep the site secure. First-party analytics and the limited Google Analytics, server-side PostHog processing, and public-page PostHog session replay described below run only after you explicitly opt in, and you can change that choice on this page at any time. There are no advertising cookies.

Overview and legal framework

Storing information on your device, or reading information from it, requires your consent under § 165(3) of the Austrian Telecommunications Act (TKG 2021, implementing the EU ePrivacy Directive) — unless the storage is strictly necessary to provide a service you have explicitly requested. Any personal data involved is additionally governed by the GDPR and our Privacy Notice.

Accordingly, we separate storage into two classes: essential (sign-in, security, forgery protection, your consent choice itself, interface preferences you set — no consent required) and analytics (set only after you opt in). We use no marketing or advertising storage of any kind.

Cookies we set

All cookies below are first-party (set by world-wide.org for world-wide.org only). In production, most carry the __Host- security prefix, are marked Secure, and — except where noted — are inaccessible to JavaScript (HttpOnly).

First-party cookies
CookiePurposeLifetimeClass
__Host-world-wide.session-token.v2Keeps you signed in (session token)15 minutes, renewed while you are activeEssential
__Host-world-wide.refresh-tokenRenews your session without re-authentication (rotating token)7 daysEssential
__Host-authjs.* (csrf-token, state, pkce.code_verifier, nonce, callback-url)Protects the sign-in flow against forgery and replayUp to 15 minutes (state, PKCE verifier, nonce); browser session (CSRF token, callback URL)Essential
__Host-world-wide.csrfRequest-forgery protection for forms and API calls (readable by the page so it can echo the token)24 hoursEssential
__Host-world-wide.webauthn-* (three cookies)Carries the short-lived challenge during passkey registration or sign-in5 minutesEssential
ww_bot_guardDistinguishes browsers from automated scrapers (abuse protection)15 minutesEssential (security)
__Host-ww_onboarded_userStores a one-way, pseudonymous hash after first sign-in so account setup completes reliably without placing the account identifier in the browser7 daysEssential (functional)
cookie-consentStores your analytics decision (a versioned “accepted” value or “rejected”)180 days if accepted, 30 days if rejectedEssential (consent record)
cookie-consent-rejection-pendingImmediately blocks analytics while a rejection is being saved on the serverUp to 30 days; removed after the server confirms the rejectionEssential (consent enforcement)
cookie-consent-rejection-sessionRetains the session identifier only to retry an unfinished analytics rejection, including after a page reloadUp to 30 days; removed after the server confirms the rejectionEssential (consent enforcement)
session-idPseudonymous analytics session identifier (random UUID)1 dayAnalytics — set only after consent
_ga, _ga_* (and legacy _gid, _gat)Google Analytics visitor distinction — set by Google’s script, which loads only after consentSet by Google (typically up to 2 years); actively deleted by us if you withdraw consentAnalytics — set only after consent

Browser storage we use

Beyond cookies, the application uses browser storage for small device-side conveniences and consented analytics state. The PostHog entries identified below are the only entries in this table that are read by a third-party analytics library.

Local storage, session storage, and IndexedDB entries
EntryPurposeLifetime
world-wide:cookie-consent-sync and world-wide:cookie-consent-decisionSynchronises the latest consent status, timestamp, and random decision identifier across open tabsUntil you clear site data
Interface preferences (brand accent, view mode, resolved timezone, event-filter keyword and type, dismissed sign-up prompt, notification read marker)Remembers display choices on this deviceUntil you clear site data
Device-side lists (bookmarks, followedSpeakers, jobAlerts)Keeps items you save, speakers you follow, and job-alert criteria you set on this deviceUntil you remove them or clear site data
Short-lived navigation and recommendation contextRemembers recently viewed domains, the previous page, and a bounded recommendation cache in the current tabSession storage — deleted when the tab closes
Sign-in coordination entries (world-wide.auth.refresh.*)Prevents multiple tabs from refreshing your session simultaneouslyUntil you clear site data
Draft autosave and upload recovery (world-wide:draft:v2:*, CV editor drafts, world-wide:presigned-upload-recovery:v1:*)Recovers half-finished submissions, profile documents, and interrupted file uploads in this tabSession storage — deleted on submit or when the tab closes
Support and error context (last support ticket, incident de-duplication)Pre-fills the support form after an error and avoids duplicate reportsSession storage — deleted when the tab closes
ww-analytics-ignorePer-device exclusion flag: while present, this device is excluded from all measurement regardless of consentUntil you remove it
world-wide:analytics-principalKeeps consented analytics events assigned to the correct anonymous or signed-in principal and is cleared on rejectionUntil consent is withdrawn, you sign out, or you clear site data
ww.search.destination.pending.v1Links a consented search to the result you open from it; written only after analytics consentSession storage — deleted when the destination page loads or the tab closes
world-wide:posthog-consentRemembers whether the consented PostHog replay library is opted in or out so withdrawal remains effectiveLocal storage — until you change the choice or clear site data
ph_<project-token>_posthogKeeps the anonymous PostHog replay session continuous within the current tab; created only after analytics consentSession storage — deleted when the tab closes or when consent is withdrawn
IndexedDB database "ww-analytics"Offline queue for consent-gated analytics events; entries are deleted once transmitted, and purged whenever consent is absentTransient

What analytics collect (with consent)

4.1 First-party analytics

Our own measurement stores its data in our EU-hosted database and is enforced on both sides: the browser sends nothing without consent, and the ingestion APIs reject unconsented requests. With consent, we record: pages viewed, referrer, campaign (UTM) parameters, search terms entered, product interactions (saving, sharing, following), clicks on outbound links (destination site and page only — never query parameters), performance timings, and sanitised semantic failure categories. We do not record exception messages or stack traces for product analytics.

Identifiers are deliberately weak: a random session identifier that expires after one day, and a fingerprint computed as a keyed hash over a truncated network prefix and coarse browser characteristics. Raw IP addresses are not written to our database. Location is recorded at country level from our content delivery network; no external IP-geolocation service is used.

4.2 Google Analytics 4

With the same consent, Google Analytics 4 (Google Ireland Ltd / Google LLC) runs alongside. Our configuration is restrictive: Google’s Consent Mode starts in a fully denied state; advertising storage and ad personalisation remain permanently denied even after you accept; IP anonymisation is on; Google signals and cross-site linking are off; page paths are truncated to their first segment before being sent, except that the FENS poster-upload page is reported as /fens-26/poster-upload; and no account identifiers are transmitted. Consented GA4 also receives coarse actions such as a server-confirmed submission, but not the submitted content. If you withdraw consent, we instruct Google to stop and delete the Google Analytics cookies from your browser. Google may process this data in the United States under the safeguards described in the Privacy Notice, Section 8.

4.3 PostHog product analytics

After the first-party database records a selected product event, our server may send PostHog US Cloud a minimal pseudonymous copy. It uses separate hashed identities and session identifiers, stable semantic event names, generalised route templates, coarse device and source context, and hashed entity references. Search text, form content, query strings, raw World Wide account, session, and content identifiers and email addresses are not sent. Anonymous events do not create a person profile. Separately, after the same consent, a PostHog browser library records interaction replays only on approved public, non-sensitive pages. It masks every form input, select, and textarea before transmission; blocks forms, dialogs, account menus, file and hidden inputs; strips query strings and fragments; and excludes account, sign-in, administration, Library, calendar, settings, employer, submission, upload, contact, and support routes. Network bodies and headers, console logs, canvas content, cross-origin frames, heat maps, automatic product events, and exception capture are disabled. Visible public-page text, layout, pointer interaction, and navigation are recorded. Your browser necessarily exposes its IP address and basic request metadata to PostHog when delivering a recording, but World Wide does not place that IP address in the replay event payload. PostHog sets no cookie; it uses the consent and tab-session storage entries listed in Section 3. A provider outage cannot block the action you take on World Wide.

Third-party content your browser loads

The consent banner governs analytics. Independently of it, some features fetch content directly from third parties when you use them, which necessarily reveals your IP address and browser characteristics to that provider:

  • Maps — basemap tiles and the map stylesheet load from CARTO (basemaps.cartocdn.com) and unpkg.com on pages that display a map;
  • Embedded recordings — an external player is not contacted when the World Wide page renders. A labelled placeholder identifies the provider. Only after you choose to load it does your browser contact YouTube (in privacy-enhanced “nocookie” mode), Vimeo, Loom, Crowdcast, Dailymotion, or Spotify; that provider’s own privacy and cookie rules then apply;
  • Profile images — avatars referenced from external services (for example Gravatar or Google) load from those hosts;
  • Posting security checks — the default check requests a short-lived challenge from World Wide and solves it locally in your browser. It sets no third-party cookie and sends no data to Google. You may instead choose “Load Google security check”; only that explicit choice contacts reCAPTCHA and reveals browser and network information to Google. A completed check is required to post, but never to browse the site.

None of these providers receives your World Wide account identity from us.

Managing your choice

Give or withdraw analytics consent here — the control below has exactly the same effect as the banner:

You have not made a choice in this browser yet. Until you do, optional analytics stay off.

Your choice takes effect immediately, applies to this browser, and can be changed here at any time. Withdrawing consent stops future analytics collection; it does not affect the lawfulness of processing that took place while consent was active.

You can additionally clear cookies for world-wide.org in your browser settings at any time; the consent banner will then appear again on your next visit. Essential cookies re-establish themselves as you use the site, because signing in and posting are impossible without them. Note that we periodically version the consent value — after a material change to what analytics collect, earlier acceptances expire and you will be asked again.

How your decision is recorded

Article 7(1) GDPR requires us to be able to demonstrate consent. When you accept or reject analytics we therefore store one consent record — the decision, its timestamp, the policy version, and pseudonymised technical context — on our servers, for both choices. This record is the proof of your decision, not a measurement of your behaviour. The cookie holding your choice on your device is described in Section 2.

Do Not Track and browser signals

Because analytics are off unless you opt in, first-party analytics and Google Analytics do not additionally interpret Do Not Track or Global Privacy Control signals — the default state already is what those signals request. The PostHog replay library does not record while your browser sends Do Not Track, even after consent. Automated browsers (WebDriver) are excluded from measurement regardless of consent.

Questions about this policy: info@world-wide.org.

Contact

For legal, privacy, and policy inquiries, email info@world-wide.org.

This policy documents the cookies and the material categories of browser storage used by the current platform release. It is reviewed with changes to the consent or analytics implementation; the formal text of the Privacy Notice governs the underlying data processing.

We use essential cookies to run the site. Optional analytics and public-page session replay help us improve World Wide. Learn more.

Cookie Policy | World Wide - World Wide