NexosaDownload

Cookies and storage

Cookies and storage

What this site stores on your device, what it asks your consent for, what its host may set, and how to change your answer. It follows the ten points Datatilsynet sets out for cookies and consent, and it is kept true by the site's own build checks, described at the end.

What the banner asks

Norwegian law, section 3-15 of the Electronic Communications Act, says nothing may be stored on or read from your device without your consent unless it is strictly necessary to deliver what you asked for. This site asks for one thing that is not necessary: to count your visit.

With your consent, the page loads Cloudflare Web Analytics, a small script from Cloudflare that counts the visit for the publisher: the page you are on, the site that linked to it, your browser and operating system family, the country your connection comes from, and how quickly the page loaded. It sets no cookie and writes nothing to your browser, it does not try to recognise you on a later visit, and the publisher sees totals, never a person. It reports tocloudflareinsights.com; Cloudflare processes it for the publisher under the agreement named on About this site, and may do so in its data centres in the United States under the transfer terms of its own privacy policy. Until you press Accept, nothing is loaded and nothing is counted. Press Reject and the page is exactly the same page without the count.

The basis for counting is your consent alone, under section 3-15 and GDPR Article 6(1)(a), given in the banner and taken back the same way; see "Consent, and taking it back" below.

What this site stores itself

One thing, and only after you have answered the banner: your answer.

NameSet byWhat forLastsConsent
nexosa-consentThis site, in the browser's local storageYour answer to the banner, yes or no, with the date you gave it, so the question is not put again on every page.A year, or until you change it or clear the site's data.Strictly necessary to honour the answer you gave; none needed.

Nothing else. The pages set no cookie, write nothing to session storage or IndexedDB, and load nothing from anywhere but their own address and, after a yes, Cloudflare's statistics script; the fonts are served from here. The one address that is not a static file,/premium/link, exists only to link a device to Nexosa Premium, shows no banner and stores nothing in your browser.

The host's cookies

The site is served by Cloudflare Pages, and Cloudflare can set cookies of its own, depending on how the publisher's Cloudflare account is configured. None of them is set by anything this site contains. Cloudflare's own cookie documentation calls each of them strictly necessary to provide the service its customer asked for, and asks its customers to disclose them. They are security measures that keep the site up under abuse, exempt from consent under section 3-15, and this is where they are declared, each with the setting that makes it appear.

NameSet byWhat forLastsConsent
cf_clearanceCloudflareStores the proof that your browser passed a challenge, so one is not issued again while it lasts, and, while Bot Fight Mode is on, the result of Cloudflare's JavaScript detections. Set only after a challenge is passed. It is marked Secure, SameSite=None and Partitioned, so it is kept for this site alone.Until Cloudflare's challenge passage period ends, which the publisher sets; thirty minutes unless changed.Strictly necessary; none needed.
__cf_bmCloudflareTells automated traffic from people, so the site stays up when something hammers it. Set on every visit while Bot Fight Mode, Super Bot Fight Mode or Bot Management is on. It holds an encrypted bot score that only Cloudflare can read, is made separately for each site, and corresponds to no identifier of yours.Thirty minutes of inactivity.Strictly necessary; none needed.
cf_chl_rc_i, cf_chl_rc_ni, cf_chl_rc_mCloudflareCloudflare's own diagnostics for its challenge pages, so it can find faults in them. Set only while a challenge is being solved.Cloudflare publishes no lifetime; clearing the browser's cookies removes them.Strictly necessary; none needed.
_cfuvidCloudflareTells apart visitors who share one address, such as a household behind one router, so a rate limit counts each of them rather than all of them together. Set only while a rate limiting rule that counts unique visitors is on.The browser session.Strictly necessary; none needed.

Which of them you receive follows from those settings, which the publisher keeps to what the site needs to stay up. None of them identifies you to the publisher or is used for anything but the security purpose named. Cloudflare's other cookies belong to products this site does not use: its load balancer (__cflb), sequence rules (__cfseq), Always Online (cf_ob_info and cf_use_ob), Waiting Room (__cfwaitingroom), the earlier rate limiting (__cfruid) and Cloudflare Access. They cannot appear here, and taking one of those products into use would mean updating this page first. Cloudflare describes each of them in its owncookie documentation, may process cookie data in its data centres in the United States under the transfer terms of its own privacy policy, and processes them for the publisher under the agreement named onAbout this site.

One more thing Cloudflare does while Bot Fight Mode is on: it inserts a small detection script of its own into each page, served from this site's own address under /cdn-cgi/challenge-platform/. Bot Fight Mode is off for this site. If it were turned on, that script would run, because the site's Content Security Policy allows scripts from the site's own address, and this page would say so first.

No cookie from anybody else can appear on this site: it loads nothing from any other host but Cloudflare's statistics script, that script sets none, and the build check below would fail if one did.

The apps

The desktop and phone apps are not browsers and use no cookies; what each keeps on a device, all of it strictly necessary and none of it read by the publisher, and how to clear it, is in section 6 of the privacy notice.

The browser client a server serves

A Nexosa server also serves a small client for a web browser, so a household can use it from a PC with nothing installed. It keeps your sign-in token in the browser's session storage, under the name nexosa.token, so you stay signed in while the tab is open; it is gone when the tab closes, and signing out removes it sooner. It sets no cookie and stores nothing else. That client is served by the server you signed in to, whose operator is the controller for it.

Consent, and taking it back

The banner is answered with one click either way, Reject or Accept, the two buttons the same size and the same colour, and "Choose what to allow" behind them shows each purpose with its own switch, off until you turn it on; there is one. Scrolling, waiting or reading on stores nothing and counts nothing. The page is not closed off behind the banner: everything on it works while the question stands.

To change or withdraw your answer, press "Change or withdraw cookie consent" at the bottom of any page. The banner opens on the choices, showing what is on, and Reject or Accept selected records the new answer at once. Withdrawing takes effect from the next page you open, because a count already sent cannot be unsent; nothing further is counted. Clearing this site's data in your browser removes the answer too, and the question is put again on your next visit, as it is after a year in any case.

How this page stays true

Datatilsynet's tenth point is to keep your own house in order: know what is set, and by whom. The site's build opens every page in a real browser and fails if any response sets a cookie, or if a page leaves anything in local storage, session storage or IndexedDB before the banner is answered. Then it answers the banner every way there is, and fails unless Reject and Accept are the same size and the same colour, the switch starts off, scrolling stores nothing, Reject stores the one entry above and loads nothing, Accept stores it and loads Cloudflare's script and nothing else, the footer button reopens the choices showing the answer given, and a withdrawn answer stops the script on the next page.

The site's Content Security Policy, the rule the browser enforces on every page, allows the site's own script and Cloudflare's statistics script, and lets the page report to Cloudflare's collection address and nowhere else. Nothing from any other host can load, and no inline script can run. A host can also add scripts of its own at the edge, after the build, for analytics, email obfuscation, Rocket Loader or Zaraz, which no build check can see; they are switched off for this site, and the publisher's Cloudflare settings are reviewed together with this page.

Last reviewed 17 September 2026. The guidance this page follows is Datatilsynet'suse of cookies and other tracking technologies.