Short version: this website sets no cookies, the CRM sets exactly one — to keep you signed in — and the widget on our customers’ websites sets none at all. Below is everything we store in your browser, where and why.
Cookies and browser storage
Cookies are small files a website saves in your browser and that the browser sends back with every request to that website. Local storage and session storage are similar places in the browser where a page can keep data; they are not sent to the server automatically. Session storage is cleared when you close the tab, local storage stays until it is deleted. The law treats all of them the same way, so this policy lists both.
We sort what we store into three types:
- Strictly necessary — the service does not work without it (for example, staying signed in).
- Preferences — remembers choices you made, such as the theme or language.
- Analytics — helps count visits and sources of traffic.
This website
This website (the home page, documentation, legal pages and the contact form) sets no cookies and uses no analytics, advertising or tracking. It only keeps two preferences in local storage:
| Name | Storage | Purpose | Type | Lifetime |
|---|---|---|---|---|
crm_theme | Local storage | Light or dark theme (shared with the CRM) | Preferences | Until you clear it |
site_locale | Local storage | Remembers that you picked a language, so we stop suggesting another one | Preferences | Until you clear it |
The home page also checks whether the CRM has saved a sign-in token (token, see below) and, if so, takes you straight to your dashboard. It only reads it and never sends it anywhere.
When you press “Try the demo” (and, where enabled, when you send the contact form), the page loads Cloudflare Turnstile, which checks that you are a person. Turnstile runs in its own frame from Cloudflare’s domain under Cloudflare’s privacy policy.
The Diil CRM
The CRM uses one cookie and a few entries in browser storage:
| Name | Storage | Purpose | Type | Lifetime |
|---|---|---|---|---|
refresh_token | Cookie (HttpOnly, Secure) | Keeps you signed in and renews your session | Strictly necessary | 7 days |
token | Local storage | Short-lived access token for requests to the server | Strictly necessary | Until you sign out |
selected_domain | Local storage | Which of your websites is open in the CRM | Preferences | Until you clear it |
crm_theme | Local storage | Light or dark theme | Preferences | Until you clear it |
i18nextLng | Local storage | Interface language | Preferences | Until you clear it |
| Interface state | Local storage | Open pages and folders, dismissed notices | Preferences | Until you clear it |
demo_until | Local storage | When the demo sandbox ends (demo only) | Strictly necessary | Until the demo ends |
invite_token | Session storage | Keeps a team invitation while you sign in or register | Strictly necessary | Until the tab is closed |
When you pay for a plan by card, you are taken to a checkout page hosted by Creem, our Merchant of Record, on its own domain. Diil sets no cookies for payments; whatever that page stores in your browser belongs to Creem and is governed by Creem’s own policies.
The widget on our customers’ websites
Websites built with Diil load our widget (widget.js). It sets no cookies. It keeps the following in the local storage of the website you are visiting; the website owner decides which features are on and is responsible for informing you and asking for consent where needed.
| Name | Purpose | Type | Lifetime |
|---|---|---|---|
crm_vid | Random visitor ID, to tell new visitors from returning ones | Analytics | Until cleared |
crm_sid | Current visit (session) ID | Analytics | New session after 30 minutes of inactivity |
crm_sat | Time of the last activity, to know when a session has ended | Analytics | Until cleared |
crm_consent | Your answer to the analytics consent request (consent mode only) | Strictly necessary | Until cleared |
crm_chat_token | Lets you return to your chat conversation | Strictly necessary (chat) | Up to 180 days |
crm_chat_seq, crm_chat_read | Which chat messages you have already received and read | Strictly necessary (chat) | Until cleared |
crm_chat_cfg | Cached chat settings of the website | Strictly necessary (chat) | 10 minutes |
crm_site_access, crm_site_access_at | Your sign-in to the website’s user account, if the website offers one | Strictly necessary (sign-in) | 15 minutes, renewed while you are signed in |
crm_site_refresh | Renews that sign-in | Strictly necessary (sign-in) | 30 days |
crm_site_user | Basic details of the signed-in user (such as email) to show in the page | Strictly necessary (sign-in) | Until you sign out |
crm_site_cfg | Cached sign-in settings of the website | Strictly necessary (sign-in) | 10 minutes |
crm_site_lock | Stops several open tabs from renewing the sign-in at the same time | Strictly necessary (sign-in) | A few seconds |
Advertising cookies the widget reads
To show the website owner which ads brought a visitor, the widget reads — but never sets or changes — advertising cookies that are already present on that website because of other tools: _ga, _ga_*, _gcl_aw, _gcl_dc, _gcl_gb, _ym_uid, _fbp and _fbc.
Consent mode and Global Privacy Control
A website owner can turn on consent mode by adding data-consent="required" to the widget’s script tag and connecting it to their cookie banner. Until you agree, the widget then sends no analytics, reads no advertising cookies and does not create crm_vid, crm_sid or crm_sat; if you refuse or withdraw consent, these entries are deleted. Forms and chat, which you start yourself, keep working without analytics identifiers.
If your browser sends a Global Privacy Control signal, the widget never reads advertising cookies — in any mode and regardless of consent.
How to control cookies and storage
- Browser settings. Every modern browser lets you view and delete cookies and site data, block them for some or all websites, and use private mode. Look for “Cookies and site data” or “Privacy” in your browser’s settings.
- Clearing local storage. Deleting a site’s data in the browser settings also clears its local storage. Deleting the CRM’s data signs you out; deleting our widget’s data on a website makes it treat you as a new visitor.
- Global Privacy Control. Turn it on in your browser or a privacy extension to stop the widget from reading advertising cookies everywhere.
- Consent banners. On websites that use consent mode, you can change your choice through that website’s cookie banner or settings.
If you block strictly necessary storage, signing in to the CRM and the chat on websites may not work.
More information
How we handle personal data in general is described in the Privacy Policy. Questions about cookies? Write to us through our contact form.