Cookie Policy
Last Updated: July 29, 2026
This Cookie Policy explains how Entergram ("we," "us," or "our") uses cookies and similar technologies — including browser local storage, session storage, and IndexedDB — across our two websites. It should be read together with our Privacy Policy. For brevity we refer to all of these technologies as "cookies" below, except where the distinction matters.
The data controller is Entinel Technologies OÜ (reg. no. 17485993), Pärnu mnt. 139b - 14, Tallinn, 11317, Estonia, operating under the Entergram brand.
1. Our two websites — and why they differ
We operate two separate websites, and they use cookies very differently:
- entergram.com — our public marketing and information website. You can browse it without an account. It uses one optional analytics tool (Google Analytics), which is not loaded at all unless you accept analytics in the cookie banner.
- app.entergram.com — the Entergram application, which requires you to sign in. It uses only strictly necessary storage: what is required to sign you in, keep the app working, and remember your interface preferences. It contains no analytics, advertising, or tracking technologies of any kind, which is why it shows no cookie banner — there is nothing optional to consent to.
Because these are two separate domains, a cookie choice you make on entergram.com does not carry over to app.entergram.com, and vice versa.
2. What are cookies and similar technologies?
2.1 Cookies. Cookies are small text files that a website stores on your device and can read back on later visits. "First-party" cookies are set by the site you are visiting; "third-party" cookies are set by another organisation.
2.2 Similar technologies. Browsers offer other ways to store data on your device — local storage and session storage (simple key/value data) and IndexedDB (a larger structured database). These are not cookies, but the law treats them the same way, so we disclose them here too. The Entergram application relies heavily on these to work offline and to avoid re-downloading your data on every page load.
2.3 Consent. Under the EU ePrivacy Directive and the GDPR, storage that is strictly necessary to deliver a service you have actively requested does not require your consent. Everything else — including analytics — requires your prior, freely given consent. We apply that distinction strictly, and we do not classify analytics as "necessary".
3. Cookies on entergram.com (this website)
| Name | Provider | Purpose | Category | Duration |
|---|---|---|---|---|
eg_cookie_consent | Entergram (first-party) | Remembers your cookie choices so we do not ask you again on every page | Strictly necessary | 12 months |
_ga | Google (third-party) | Distinguishes one visitor from another so we can count unique visits | Analytics (optional) | 24 months |
_ga_<property-id> | Google (third-party) | Maintains Google Analytics 4 session and campaign state | Analytics (optional) | 24 months |
Analytics cookies are set only after you accept. If you reject or ignore the banner, the Google Analytics script is never downloaded and no request reaches Google. Google's advertising features are permanently disabled.
4. Local storage on entergram.com
None of the following are cookies, none are sent to a server, and none identify you. They stay in your browser until you clear them.
| Key | Purpose | Category |
|---|---|---|
eg_cookie_consent | A second copy of your cookie choice, so your preference survives even if cookies are restricted | Strictly necessary |
hs_theme | Remembers your light/dark theme preference on the main site | Functional |
starlight-theme | Remembers your light/dark theme preference in the Help Center | Functional |
bookmarks | Remembers which blog articles you have bookmarked, so you can find them again | Functional |
These entries are strictly necessary or purely functional: they store a preference you expressed yourself, on your own device, and are readable only by this website. They are not used to build a profile of you.
You may notice the cookie banner offers only two categories — Necessary and Analytics — while the tables above also mention these preference entries. That is deliberate, and here is the plain-language reason: each of these is created only when you yourself click something — the dark-mode toggle, or the bookmark button on an article — and it does nothing except remember that one click. Storing a choice you just made is part of carrying out your request, so the law does not require a consent toggle for it (and switching it off would simply mean the site forgets your choice). Analytics is the only thing on this website that needs your permission, which is why it is the only switch in the banner.
5. Cookies in the application (app.entergram.com)
The application sets only what is required to run it and keep you signed in. There are no analytics, advertising, marketing, profiling, or tracking cookies, and no third-party trackers are loaded.
| Name | Provider | Purpose | Category | Duration |
|---|---|---|---|---|
sb-<project>-auth-token (and its numbered parts, e.g. .0, .1) | Supabase (our authentication provider) | Keeps you securely signed in — holds your session and refresh tokens | Strictly necessary | Until you sign out (maximum 400 days) |
sb-<project>-auth-token-code-verifier | Supabase | Secures the sign-in handshake (PKCE) against interception | Strictly necessary | Duration of sign-in only |
workspaceInviteToken | Entergram (first-party) | Carries a workspace invitation across the sign-in redirect, so you join the right workspace afterwards | Strictly necessary | 7 days |
entergram_mcp_oauth_redirect | Entergram (first-party) | Remembers where to return you after you authorise an MCP connection | Strictly necessary | 30 minutes |
entergram_referral | Entergram (first-party) | Set only if you arrive through a referral link. Records which code referred you, so the referrer can be credited if you sign up. Never shared with any third party and never used for advertising or profiling. | Functional — referral attribution | 30 days |
__cf_bm, cf_clearance | Cloudflare (our security provider) | Distinguishes real users from bots and protects the service against automated abuse | Strictly necessary — security | 30 minutes / up to 1 year |
Because these are strictly necessary to deliver a service you have actively requested — signing in and using the application — they do not require consent under applicable law. If you block them, sign-in and core features will stop working.
6. Local storage and offline data in the application
Entergram is a working CRM, not a brochure. To stay responsive and to work when your connection drops, the application stores a substantial amount of data locally in your own browser using local storage and IndexedDB. This data lives on your device, is readable only by the application, and is never used for advertising or analytics.
This includes, in broad categories:
- Interface preferences — theme and colour variant, font size, language, sidebar and panel state, table column layout, sorting and filters, recently used emoji, and notification settings.
- Working data caches — cached Telegram chats, messages, contacts, avatars, media, stickers and analytics results, stored in IndexedDB and in the browser's Cache Storage (managed by our offline service worker), so the app does not re-download everything on every visit and remains usable offline.
- Unsent work — message drafts you have typed but not yet sent (kept for 7 days) and queued broadcast jobs.
- Security material — a device-specific encryption key used to protect locally cached data. It is stored encrypted and never leaves your device in readable form.
- Technical state — cache versions, connection and synchronisation state, a per-device identifier used to coordinate real-time connections, and your web push notification registration.
All of this is necessary to deliver the application you have signed in to use. You can clear it at any time through your browser, or by signing out — though doing so will mean the app has to re-download your data and you will lose any unsent drafts.
7. What we do not do
On either website, we do not:
- use advertising cookies, ad networks, ad targeting, or retargeting pixels;
- build behavioural profiles of you, or track you across other websites;
- run Meta/Facebook, LinkedIn, X/Twitter, TikTok, Reddit, or any other social media tracking pixels;
- record how you use the product for analytics or marketing (no analytics-style session recording);
- sell, rent, or share your personal data with data brokers.
The application contains no third-party analytics. Product analytics is limited to our public marketing website, where you can refuse it. The application does use error monitoring to detect and fix technical faults: when an error occurs, a technical report — and, for a small share of error sessions, a short reconstruction of the screen with all text masked and all media blocked — is sent through our own servers to our error-monitoring provider (see section 9). This exists solely to fix bugs, is never used to profile you, and sets no cookies.
8. Consent and your choices
8.1 On entergram.com. The first time you visit, we show a consent banner where you can accept or reject optional analytics cookies, or open "Customise" to choose in detail. Rejecting is as easy as accepting, and nothing optional is loaded until you actively accept. If you dismiss the banner without choosing, we treat that as a refusal.
8.2 Changing your mind. You can change or withdraw your choice at any time using the cookie button in the bottom-left corner of any page, or the "Cookie settings" link in the footer. Withdrawing consent is as easy as giving it.
8.3 In the application. The application sets only strictly necessary and functional storage, so there is no consent banner and nothing to switch off — there is no tracking to opt out of. You can still clear this storage through your browser, though doing so will sign you out and clear your cached data.
8.4 Browser settings. You can block or delete cookies and local storage through your browser settings (Chrome, Firefox, Safari, Edge and others all provide this). Blocking strictly necessary storage will break essential features such as signing in.
9. Third parties and international transfers
9.1 Google Analytics. If — and only if — you accept analytics on entergram.com, Google LLC (United States) acts as our processor and receives your IP address and usage events. Google Consent Mode is used to keep all advertising signals denied. Transfers to the United States rely on the EU–US Data Privacy Framework, in which Google participates, and on Standard Contractual Clauses. You can withdraw this consent at any time.
9.2 Cloudflare. Cloudflare protects the application (app.entergram.com) against automated abuse and sets the strictly necessary security cookies described in section 5. This processing is necessary to keep the service available and secure. The public website (entergram.com) is not served through Cloudflare and receives no Cloudflare cookies; its hosting provider (Vercel) sets no cookies either.
9.3 Supabase. Supabase provides authentication for the application and sets the sign-in cookie described in section 5.
9.4 Calendly. If you choose to book a call through the scheduling widget, Calendly loads inside that page and sets its own cookies under its own privacy policy and its own consent notice. This only happens if you open the booking step.
9.5 Fonts and assets. We serve our fonts from our own servers. Loading a page on entergram.com does not send your IP address to Google Fonts or any other font provider.
9.6 Sentry (error monitoring, application only). We use Sentry (Functional Software, Inc., United States) to detect and fix technical errors in the application. Error reports are sent through our own domain — your browser never contacts Sentry directly — and are aggressively scrubbed before sending: email addresses, tokens, message content, phone numbers, and long identifiers are removed or masked. For a small share of sessions in which an error occurs, a short screen reconstruction with all text masked and all media blocked may be included so we can reproduce the bug. Sentry sets no cookies and is not used for analytics, advertising, or profiling. Transfers to the United States rely on the EU–US Data Privacy Framework and Standard Contractual Clauses.
10. Data protection and your rights
10.1 Compliance. We process personal data in line with the EU General Data Protection Regulation (GDPR), the ePrivacy Directive as implemented in Estonia, the California Consumer Privacy Act (CCPA), and other applicable laws.
10.2 Legal basis. Strictly necessary and functional storage is used on the basis of our legitimate interest in delivering a working, secure service you have requested. Analytics on entergram.com is used solely on the basis of your consent.
10.3 Your rights. You have the right to access, rectify, erase, restrict, port, or object to the processing of your personal data, and to withdraw consent at any time without affecting the lawfulness of processing before withdrawal. To exercise these rights, contact us at hello@entergram.com. You also have the right to lodge a complaint with your local supervisory authority, or with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon).
10.4 More information. For full details on how we handle personal data, please see our Privacy Policy.
11. Changes to this policy
We may update this Cookie Policy to reflect changes to our services, the law, or technology. We will post updates here with a revised date. If we ever introduce a new category of optional cookie, we will ask for your consent again before setting it.
12. Contact
For questions about this Cookie Policy, contact us at hello@entergram.com.
Entinel Technologies OÜ (reg. no. 17485993), Pärnu mnt. 139b - 14, Tallinn, 11317, Estonia.
Entergram does not provide legal advice.