Cookie notice
Version 2.0, effective 09.09.2026. One cookie is set without asking, and it is the one holding your answer to the question the banner asks. Everything else waits: analytics, and the support widget in the corner. Refuse both and this site stores nothing on your device but that single answer.
Last updated · Oktul OÜ · Registry code 17589681The cookie that records your answer
It records whether you accepted analytics, whether you accepted the support widget, when you answered, and which version of these categories you were shown. Nothing else. It is readable only by this site and is never sent to a third party.
It is set without asking because it exists only to remember your answer, which is what makes it strictly necessary under Article 5(3) of the ePrivacy Directive: a site that asked permission to remember your refusal would have to ask again on every page.
The version number is printed here so you can match it against what your browser holds. If we change what the categories are, that number goes up, your stored answer stops counting, and you are asked again. An answer given to a different set of questions is not an answer to these ones.
- Name
- oktul_consent
- Holds
- Your analytics answer, your support widget answer, the date, and the category version
- Current category version
- 2, in use since 09.09.2026, when the support widget became a category of its own
- Expires
- Six months, after which you are asked again
- Sent to
- Nobody. First-party, and never attached to a third-party request
Analytics, only if you accept
Google Analytics 4 tells us which pages are read and which are not, which is how we decide what documentation to write next. If you refuse, no request is made to Google at all: the script is not loaded rather than loaded and told to behave. Refusing costs you nothing on this site.
Google Ireland Limited is the processor and Google LLC may process the data outside the EEA, under the European Commission's adequacy decision for the EU-US Data Privacy Framework and Google's standard contractual clauses. Advertising features, Google Signals and data sharing with other Google products are all off. Google Analytics 4 does not record IP addresses at all: yours is used in transit to derive a coarse location and then discarded.
- What it sets
- Google Analytics cookies (_ga and _ga_*), only after you accept
- Expires
- Up to two years, set by Google rather than by us
- Processor
- Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
- Turning it off
- The cookie settings link in the footer of every page
The support widget, only if you accept
The question mark in the corner of every page is Jira Service Management's own widget. It opens a form that files a request in our Help Center, and it is the same service desk the contact page leads with. Atlassian Pty Ltd is the processor, and the instance has EU data residency, so a request raised through it is stored in the EU.
It stores an identifier that follows you from page to page, so it needs your permission and it now waits for it. Until 09.09.2026 it did not: it loaded on every page and set that identifier before anyone was asked. This notice used to explain that as a limitation of the widget rather than a choice, and that was the wrong answer twice over. It was not the only option, and a technical constraint is not a lawful basis under Article 5(3) in any case.
What it costs to refuse is worth saying plainly, because it is not nothing: with the widget off there is no support form on the page itself. The Help Center link in the footer and on the contact page opens the same service desk, and support@oktul.com reaches the same queue with the same response target, so the channel is one click away either way.
If you accept it, the widget also sends its own usage events to Atlassian and its error reports to Sentry, which is Atlassian's error-reporting service rather than ours. Both leave your browser rather than us. We receive neither, hold no account with Sentry, and cannot see what either collects.
- Name
- ajs_anonymous_id
- Set by
- The widget, on oktul.com, as a first-party cookie, only after you accept it
- Holds
- A random identifier the widget uses to tell one browser from another
- Processor
- Atlassian Pty Ltd, with EU data residency on the service desk it files into
The check on the contact form
Cloudflare Turnstile runs on the contact page only, and it establishes that a submission came from a person rather than a script. It is not gated behind consent, and the reason is the same Article 5(3) carve-out the consent cookie itself relies on: it is strictly necessary for a service you explicitly requested, which is the sending of the form you are filling in. It does not run on any other page, and it does not run until the contact page is opened.
Stated rather than left implied, because the previous version of this notice listed Turnstile among the third-party scripts and never said why it alone needed no permission. An unexplained exception on a page about permissions is the one thing a reviewer will stop at.
Measured on a clean browser rather than taken from its documentation: Turnstile sets no cookie on this site. It does process your IP address and browser signals in order to make its judgement, which is what the check is, and it returns us a pass or a fail and no personal data.
What your browser stores that is not a cookie
Local storage rather than a cookie. The difference that matters is that your browser never attaches local storage to a request on its own, the way it does a cookie. Two entries are ours and hold a preference you set, and they are written only if you use the control that sets them. Three belong to the support widget and exist only if you accepted it. Clearing your site data removes all of them, and the site works normally without them: you get the defaults again.
- starlight-theme
- Light or dark, if you used the theme switch
- oktul-docs-sidebar
- The width you dragged the documentation menu to
- ajs_anonymous_id
- The support widget's identifier, stored here as well as in the cookie above. Only if you accepted the widget
- awc.session.id
- The support widget's identifier for a single visit. Only if you accepted the widget
- awc.session.expiry
- When the support widget treats that visit as ended. Only if you accepted the widget
What is not here
No advertising identifier, no session recording, no A/B testing cookie, no social embed and no tag manager. Analytics goes straight to Google Analytics rather than through Google Tag Manager, so there is no container through which something else could be added later without this notice changing.
Three scripts on this site are somebody else's, and this notice describes all three: Google Analytics, which is not loaded until you accept it; the support widget, which is not loaded until you accept it; and Cloudflare Turnstile on the contact page, which is covered above. The content security policy served with every page is what refuses a fourth, which is a mechanism rather than a promise to notice.
- No advertising, and no Google advertising features.
- No session recording, heatmap or scroll-tracking service.
- No social embed, and no third-party script beyond the three named above.
- No profile built across visits, and no data enriched against another source.
When you leave for the Marketplace
Links to the Atlassian Marketplace and to Atlassian’s documentation take you to Atlassian, and Atlassian’s own cookie and privacy policies apply there. We have no visibility of what happens after you follow one of those links and no arrangement with Atlassian to receive anything about it.
Write to hello@oktul.com. A person reads it. Support has its own address and a response target measured against it; this one is for the document you are reading.
For what a specific application does with the data in your Atlassian instance, see the privacy policy in its own documentation. Every application is listed on the applications page. Those answers are decided per application, so this document does not attempt to give them.