← Back to Legal Documents

Cookie & Local Storage Policy

Effective Date: 26 September 2026 — Last Updated: 26 September 2026

This policy explains how Trefnus CMMS uses storage on your device. The Application does not set cookies and does not use any storage for tracking, analytics, or advertising. It uses browser storage (localStorage, sessionStorage, IndexedDB, and the service worker cache) because an offline application has to keep its data and its own files on your device in order to work.

1. Technologies Used

1.1 localStorage

Persistent key-value storage that remains until it is cleared. Used for licence state, security settings, preferences, and small markers the Application needs between visits.

1.2 sessionStorage

Temporary key-value storage that is cleared when the browser tab or window is closed. Used to remember that you are signed in for the current session.

1.3 IndexedDB

A larger structured database in the browser. Used for your records, attachments, backups, and caches.

1.4 Service Worker Cache

A cache managed by the Application's service worker. It holds the Application's own files (HTML, CSS, JavaScript, icons, and these legal pages) so the Application can start without an internet connection.

2. What We Store — localStorage

Keys are grouped by purpose. Where several keys share a prefix, the prefix is shown.

Key(s) Purpose Category
licence_activated, licence_activated_at, licence_last_verified, licence_user_id, licence_revoked Whether and when the licence was activated and last verified on this device, and the licence account it belongs to Essential
licence_device_hash The randomly generated device identifier used for the device limit Essential
sb-* Sign-in session for the licence account, stored by the Supabase authentication library Essential
cmmsAuth, cmms_password_hash, cmms_crypto_wraps, cmms_auth_throttle, cmms_signin_mode, cmms_last_signin The device password check (a salted verifier, not the password), the encryption key in wrapped (encrypted) form, the wrong-password delay, and sign-in settings Essential (security)
cmms_legal_acceptance A record that the terms and policies were accepted on this device, which version, and when Essential
cmms_device_id, cmms_sync*, cmms_time_offset Coordinating several open tabs, and synchronising records between your devices Essential
cmms_cloud_pkce, cmms_cloud_oauth_result Short-lived values used only while you connect your Dropbox account, then removed Essential (only if you connect Dropbox)
cmms_app_version, cmms_initial_setup_complete, cmms_migration_complete, cmms_data_modified_at, cmms_backup_dirty_since, cmms_last_backup_date, and other cmms_* markers Version, setup and upgrade markers, and the timestamps the backup and sync features use to know what has changed Essential
cmms_emergency_*, cmms_idbq_pending, cmms_unreadable_* Temporary safety copies of unsaved changes, and notes of records that could not be read, used to prevent data loss Essential
cmms_known_peers, cmms_peer_secrets, cmms_p2p_* Device-to-device (peer-to-peer) sync. This feature is currently switched off; these keys are only present on devices that used it previously Functional
cmms_map_basemap, *ColumnWidths, cmms_dashboardViewAs, cmms_showAssetFinancials Display preferences you choose, such as the map style and table column widths Functional

3. What We Store — sessionStorage

Key Purpose Category
cmms_session_authenticated, cmms_signed_in_user, cmms_session_opened_by That the correct password has been entered in this session, and which person (if any) is signed in Essential
cmms_crypto_session_dek The encryption key for this session, so the Application can read your records until the tab is closed or you sign out Essential
cmms_last_activity, cmms_idle_signed_out Signing out automatically after a period without use, and telling you why you were signed out Essential (security)
pwaInstallBannerDismissed Stops the "install app" banner reappearing in the same session after you dismiss it Functional
cmms_stay_on_legacy_host Set only when the Application is opened at its former address (trefnus-cmms.pages.dev) with ?stay in the URL. It suppresses the automatic redirect to cmms.trefnus.com for the rest of the browser session, so data still held at the old address can be exported. Never set at the current address. Functional

4. What We Store — IndexedDB

Database Purpose Category
CMMS_FileStorage All of your records (assets, work orders, activities, defects, contracts, parts, users, settings, and history), encrypted where your browser supports it, and your attachments Essential
CMMS_Backup Automatic restore points and backup settings Essential
CMMS_Sync Change journal used to synchronise records between tabs and devices without losing edits Essential
CMMS_Cloud Your Dropbox connection (including its access token) and sync status, only if you connect Dropbox Essential (only if you connect Dropbox)
CMMS_ManualLibrary Offline copies of manuals and documents you have opened Functional
CMMS_MapTiles Map images already viewed, so maps work offline. Limited to about 60 MB and can be emptied in the Application Functional

5. What We Store — Service Worker Cache

The service worker caches the Application's files so it can start offline. This cache:

6. Categories Explained

7. Third Parties

8. What We Do NOT Use

This policy covers the Application at cmms.trefnus.com. Our marketing website, www.trefnus.com, is operated separately and may use cookies as described on that website.

9. Managing Stored Data

You can manage or delete stored data through your browser settings:

Warning: Clearing browser storage permanently deletes every record held on this device. Unless you have a backup or a copy in your own Dropbox, this cannot be undone. Always make and check a backup before clearing browser storage.

10. Legal Basis

Under the Privacy and Electronic Communications Regulations (PECR), storing information on your device is allowed without consent where it is strictly necessary to provide a service you have requested. All of the storage described here is used only to provide the Application and the features you choose to use, so we do not ask for separate consent. Where the stored information is personal data, our lawful basis under data protection law is set out in our Privacy Policy.

11. Changes to This Policy

We may update this policy to reflect changes in the Application's storage practices. Updates will be posted on this page with an updated date.

12. Contact

For questions about this Cookie & Local Storage Policy, contact:

Trefnus (Darren Jolley, sole trader)
Email: apps.trefnus@gmail.com