1. Scope
This policy covers the Lectora marketing website at lectora.io. Cookies and analytics inside the Lectora application are described in the Privacy Policy.
Fjordbyte AS (organisation number 933 773 477) is responsible for the website and for the choices described in this policy.
2. What cookies and similar technologies are
A cookie is a small text file stored by your browser. The website also uses localStorage and sessionStorage, which let the browser retain information without using a cookie. This policy uses “browser storage” to cover all three mechanisms and also describes analytics or security services that send data without setting a browser-storage key.
“First party” means that the value is stored for lectora.io. “Third party” means that it is stored for a provider's domain.
3. Cookies and similar technologies used on the website
The tables combine the current website code with the production provider configuration and clean-browser observations recorded on 31 August 2026, updated for the Google Analytics entries on 2 September 2026. The category shown is Lectora's consent category, which may differ from the provider's own terminology. Services that store or read anything on your device are loaded only after consent to the corresponding category. Vercel Web Analytics and Speed Insights are the exception and are explained under Analytics below.
Strictly necessary
These mechanisms support requested preferences, remember the consent decision or protect a submitted form. They do not depend on Analytics or Marketing consent.
| Name | Provider | Purpose | Duration | Type |
|---|---|---|---|---|
NEXT_LOCALE | Lectora (next-intl) | Remembers the selected or detected website language | Browser session | First-party cookie |
lectora.consent | Lectora | Stores the consent version, Analytics and Marketing choices, and the time of the choice | Until browser data is cleared; there is no time-based expiry. A consent-version change makes the record invalid and prompts for a new choice | First-party localStorage |
lectora-theme | Lectora | Remembers a light or dark theme selected by the visitor | Until changed or browser data is cleared | First-party localStorage |
lectora_admin_session | Lectora | Keeps a Fjordbyte administrator signed in to the internal investor-brief admin area. Only set for Fjordbyte administrators on /admin, never for website visitors | 8 hours | First-party cookie |
lectora_admin_oidc_state, lectora_admin_oidc_nonce, lectora_admin_oidc_verifier | Lectora | Protect a Fjordbyte administrator's Microsoft sign-in against forged or replayed responses, and are deleted when sign-in completes. Only set for Fjordbyte administrators on /admin | 10 minutes | First-party cookie |
Vercel BotID performs an invisible, same-origin security check when a protected pilot-request form is submitted. The Basic check tested for this policy did not set a cookie, localStorage key or sessionStorage key. It does not run merely because a page is viewed.
Analytics
Vercel Web Analytics records page views and events using a daily request-derived identifier and processes the path, referrer, coarse location and browser/device metadata. Vercel Speed Insights records real-user performance measurements. In this website configuration they set no cookie or browser-storage key, and Vercel discards its derived visitor session after 24 hours.
Because neither service stores or reads anything on your device, they run without asking for consent. The consent rule in ePrivacy Article 5(3), and its implementation in Norwegian electronic-communications law, attaches to storing or accessing information on your equipment, and these two do neither. Everything below that does touch your device stays behind the Analytics or Marketing switch.
Consent is not the only question. The measurement itself is still processing of personal data, and Fjordbyte's lawful basis for it is legitimate interests under GDPR Article 6(1)(f): understanding in aggregate how the website is used and how quickly it loads. It is not used to identify you, to build a profile, or for advertising. You can object to it under Article 21 using the contact details in section 6.
Google Analytics 4 is off until Analytics consent is given. It is a different case: it writes first-party cookies on your device, so it waits for your choice. Withdrawing Analytics deletes the _ga cookies below and tells Google that analytics storage is denied, so no new ones are written. A Google script already running in the open page is not removed by the withdrawal; the next page load does not load it at all.
| Name | Provider | Purpose | Duration | Type |
|---|---|---|---|---|
_ga | Google Analytics 4 | Distinguishes visitors so page views can be grouped into sessions | 2 years | First-party cookie |
_ga_JWKDCZWNRC | Google Analytics 4 | Holds the session state for this website's GA4 stream | 2 years | First-party cookie |
HubSpot's browser tracker is not part of Analytics. It is loaded only after Marketing consent and is listed in the Marketing table below.
Marketing
Marketing is off until consent is given. After Marketing consent the website loads HubSpot's tracking code, which in turn installs the Google Ads, LinkedIn and Meta advertising pixels. Google, LinkedIn and Meta act as independent controllers for their own advertising processing. The pixels are administered in HubSpot rather than embedded separately in the website, so all three appear and disappear together with the Marketing choice. The Google Analytics 4 property is loaded under Analytics rather than Marketing, so declining Marketing does not switch it off, and accepting Marketing does not switch it on.
Some advertising keys are conditional: they are created only when a matching click identifier is present, a provider feature is used, or the visitor's region and browser permit them. Keys marked “conditional” below are part of the current provider tag families but were not all present in the clean Norwegian test.
| Name | Provider | Purpose | Duration | Type |
|---|---|---|---|---|
lectora.attribution | Lectora | Stores first-touch campaign parameters, advertising click identifiers, external referrer, first path and timestamp for a pilot request | Page or tab session | First-party sessionStorage |
hubspotutk | HubSpot | Identifies the browser so page views can be joined to a later form submission, which is what links a request to the campaign that brought you | 6 months | First-party cookie |
__hstc | HubSpot | Main visitor tracking record: domain, first visit, previous visit and current session | 6 months | First-party cookie |
__hssc | HubSpot | Counts the current session and its page views | 30 minutes | First-party cookie |
__hssrc | HubSpot | Records whether the visitor restarted the browser, so a new session can be recognised | Browser session | First-party cookie |
_gcl_au | Google Ads | Measures advertising and campaign performance and conversions | 90 days | First-party cookie |
_gcl_ls | Google Ads | Stores conversion-linker click and attribution information | Until cleared; individual records expire after about 5 minutes to 90 days | First-party localStorage |
_gcl_aw | Google Ads | Associates a Google Ads click with later activity or conversion; conditional on a Google click identifier | 90 days | First-party cookie |
GCL_AW_P | Google Ads | Partitioned Google Ads click and conversion attribution; conditional on a Google click identifier | 90 days | Partitioned third-party cookie on Google service domains |
_gcl_gs | Google Ads | Stores Google advertising click information; conditional | 90 days | First-party cookie |
_gcl_gb | Google Ads | Stores Google advertising click and conversion information; conditional | 90 days | First-party cookie |
_gcl_ag | Google Ads | Stores Google advertising click and conversion information; conditional | 90 days | First-party cookie |
GCL_AU_P | Google Ads | Partitioned advertising and conversion measurement; conditional | 90 days | Partitioned third-party cookie on Google service domains |
test_cookie | Google Ads (DoubleClick) | Tests whether the browser permits cookies; conditional | 15 minutes | Third-party cookie |
bcookie | Browser identifier used for abuse detection and diagnostics | 1 year | Third-party cookie on .linkedin.com | |
bscookie | Remembers two-factor verification for a signed-in LinkedIn member; conditional | 1 year | Third-party cookie | |
JSESSIONID | Cross-site request-forgery protection and URL-signature validation; conditional | Browser session | Third-party cookie | |
lang | Remembers a signed-in LinkedIn member's language setting; conditional | Browser session | Third-party cookie | |
li_gc | Stores a guest's LinkedIn consent state for non-essential LinkedIn cookies | 6 months | Third-party cookie on .linkedin.com | |
lidc | Selects the LinkedIn data centre serving a request | 24 hours | Third-party cookie on .linkedin.com | |
sdsc | Supports consistent routing after a database change; conditional | Browser session | Third-party cookie | |
li_mc | Temporarily caches a LinkedIn member's consent state; conditional | 6 months | Third-party cookie | |
li_fat_id | Indirect member identifier for conversion tracking, retargeting and analytics; conditional on a matching click identifier | 30 days | First-party cookie | |
UserMatchHistory | Limits how often LinkedIn Ads identifier synchronisation occurs; conditional | 30 days | Third-party cookie | |
AnalyticsSyncHistory | Records when a synchronisation with lms_analytics occurred; conditional | 30 days | Third-party cookie | |
lms_ads | Identifies LinkedIn members outside LinkedIn for advertising; conditional | 30 days | Third-party cookie | |
lms_analytics | Identifies LinkedIn members outside LinkedIn for analytics; conditional | 30 days | Third-party cookie | |
li_sugr | Makes a probabilistic identity match; conditional | 90 days | Third-party cookie | |
_fbp | Meta | Identifies the browser so advertising and conversions can be measured and audiences built | 90 days | First-party cookie |
_fbc | Meta | Stores a Meta advertising click identifier for later conversion attribution; created only when arriving from a Meta ad | 90 days | First-party cookie |
_guid | Identifies a LinkedIn member for advertising through Google Ads; conditional | 90 days | Third-party cookie | |
li_giant | Indirect group identifier for conversion tracking; conditional | 7 days | First-party cookie | |
BizographicsOptOut | Remembers a non-member's LinkedIn opt-out status; conditional | 10 years | Third-party cookie | |
ar_debug | Supports attribution reporting where browser signals are restricted; conditional | Browser session | First-party cookie | |
li_adsid | Advertising identifier fallback; conditional and not used for visitors in the EU/EEA, UK or Quebec | Not stated by LinkedIn; until cleared or provider-managed | First-party localStorage or cookie fallback | |
__cf_bm on .linkedin.com | Cloudflare, for LinkedIn | Protects LinkedIn endpoints against automated abuse | 30 minutes after inactivity | Third-party cookie |
Provider-controlled tags can change without a website release. This inventory records the configuration tested on the date shown below.
4. Consent
On a first visit, Strictly necessary mechanisms are available and Analytics and Marketing are off. The banner provides Accept and Reject choices. Accept enables both optional categories; Reject keeps both off. This page also provides separate Analytics and Marketing controls.
The choice is stored in lectora.consent until you clear browser data. There is no fixed time expiry. If Lectora changes the consent version, the saved record becomes invalid and the website asks for a new choice. Saving a choice does not itself send the stored consent record to Fjordbyte's server. If you submit a pilot-request form, the current Marketing cookie-category setting—not the form's separate marketing-communications choice—is sent with the form, and campaign attribution is included only when Marketing is enabled.
You can change or withdraw consent at any time using the controls on this page. A permanent Cookie settings link in the website footer returns you here using a new document load. This preferences page does not load Marketing tags. If another client-side navigation brings you here from a page where those tags already ran, the page reloads on arrival before you use the controls. Disabling Analytics stops the events Lectora sends itself (such as opening the demo or submitting a request) and, for Google Analytics, denies analytics storage and deletes its cookies. Vercel Web Analytics and Speed Insights are not affected, because they are not consent-gated: they set nothing on your device, and section 3 explains the basis for running them. Disabling Marketing denies further Google Ads storage and removes known first-party advertising storage and lectora.attribution; other open website tabs receive the changed choice and reload if Marketing tags had run there. Cookies on Google, LinkedIn or other third-party domains cannot be deleted by lectora.io; they may remain until their stated expiry or until you delete them in your browser. A later page load does not load any consent-gated service whose category is disabled.
5. Processing outside the EU/EEA
An endpoint's address does not by itself determine where every part of a provider's processing occurs.
| Provider | Processing location and transfer safeguards |
|---|---|
| Vercel | Vercel states that its primary processing facilities are in the United States and that processing may occur worldwide. Vercel is certified under the EU–US Data Privacy Framework and includes the EU Standard Contractual Clauses (SCCs) in its Data Processing Addendum. |
| Google Analytics | Google processes analytics data globally, including in the United States, as Fjordbyte's processor under the Google Ads Data Processing Terms, which Fjordbyte has accepted. Google relies on the EU–US Data Privacy Framework for covered US transfers and the EU Standard Contractual Clauses where it does not apply. |
| Google Ads | Google processes advertising data globally, including in the United States, and acts as an independent controller. Google relies on the DPF for covered US transfers and SCCs where the framework does not apply, as described in its Ads data-transfer terms. |
| LinkedIn states that Insight Tag data is stored on servers in the United States and acts as an independent controller. LinkedIn relies on the DPF and, where necessary, controller-to-controller SCCs under its Independent Controller Addendum. | |
| Cloudflare | Cloudflare protects endpoints used by LinkedIn and may process the related security-cookie data globally, including in the United States. LinkedIn's onward-transfer arrangement applies; Cloudflare also states that it uses the DPF and SCCs in its Data Processing Addendum. |
6. Further information and contact
For information about Fjordbyte's processing of personal data, see the Privacy Policy. The Subprocessors page describes providers used to deliver the Lectora application; Google Ads and LinkedIn's advertising processing on this website is instead governed by their independent-controller terms described above.
Questions about cookies or tracking can be sent to lectora@fjordbyte.no.
If the English and Norwegian versions differ, the English version prevails.
7. Last updated
2 September 2026.