Cookie choices at a glance
DevProofs uses essential cookies and similar technologies that are required for secure login, sessions, consent choices, LinkedIn authentication, fraud prevention and core website operation. These cannot be disabled through our cookie choices because the Service may not function without them.
Non-essential technologies, including optional analytics, are intended to load only after you accept them. DevProofs does not use advertising cookies, retargeting pixels or behavioural advertising on the website.
1. What are cookies and similar technologies?
Cookies are small text files stored by a website on your device. They can help a website remember a login session, maintain security, remember a consent preference or understand how the service is used.
We also use or may use similar technologies, such as local storage, session storage, server-side session data, browser preferences, CAPTCHA signals and technical logs. Local storage and session storage are not technically browser cookies, but they can perform similar preference or functionality roles.
2. Categories we use
Essential and security
Required for account sessions, login, CSRF protection, email verification workflows, consent storage, LinkedIn OAuth, security controls, Cloudflare protections, CAPTCHA and rate limiting.
Non-essential analytics
Used to understand aggregate or unique visits and improve DevProofs. Optional analytics should not load if you decline non-essential cookies.
DevProofs does not currently use a marketing-cookie category on the website. If advertising or marketing tracking is introduced in the future, this policy and the consent controls will be updated before such technology is used where consent is required.
3. Cookies and storage technologies
Names and durations may vary according to browser, security configuration, provider updates and how you use the Service.
| Technology | Category | Purpose | Typical duration |
|---|---|---|---|
| PHPSESSID or equivalent session identifier | Maintains secure server-side session state, including login state and core account functionality. | Usually session-based; may end when the browser closes or when the session expires. | |
| cookie_consent | Stores your cookie choice so DevProofs can respect it and avoid repeatedly displaying the same consent request. | Up to 1 year or longer where legally permitted and appropriate. | |
| theme in local storage | Remembers your selected light/dark theme or interface preference. | Until changed, cleared by you, or browser storage is cleared. | |
| linkedin_state in server session | Helps validate and protect the LinkedIn OAuth sign-in process against request forgery. | Temporary session duration. | |
| csrf_token in server session | Helps protect forms and authenticated actions against cross-site request forgery. | Temporary session duration or until renewed. | |
| CV builder draft, UI settings and preview preferences in local/session storage | Supports drafts, interface choices, builder controls and preview preferences where enabled. | Varies; may remain until cleared or overwritten. | |
| Google Analytics cookies, such as _ga or related identifiers | May be used in the future to measure aggregate and unique visits. Google Analytics is not currently installed as a production analytics tool on DevProofs. | Commonly up to 2 years, subject to Google configuration. |
4. Cloudflare, CAPTCHA and security technologies
DevProofs uses Cloudflare for security, content delivery, traffic protection and analytics. Cloudflare may set security-related cookies or use equivalent signals to help distinguish legitimate visitors from malicious traffic, enforce rate limits and complete security challenges.
Depending on the security configuration, these may include:
- __cf_bm — may support bot management.
- cf_clearance — may be set after a Cloudflare challenge or CAPTCHA is completed.
- _cfuvid — may support rate limiting or traffic-management functions.
Cloudflare Turnstile or CAPTCHA may be used on login, registration or other sensitive forms. These technologies are used to protect users and infrastructure against automated abuse, account attacks, spam and fraud. Because they are security-related, they may be necessary even when optional analytics are declined.
5. LinkedIn OAuth
LinkedIn authentication is initiated only when you choose to continue, register or log in with LinkedIn. During this process, DevProofs creates and stores temporary session data needed to securely validate the OAuth request.
You may then be redirected through DevProofs' callback flow to official LinkedIn authentication services. LinkedIn may set its own cookies or use other technologies on LinkedIn-controlled pages. Those technologies are governed by LinkedIn's own policies, not this Cookie Policy.
For more information, review LinkedIn's Cookie Policy and Privacy Policy.
6. Analytics and non-essential technologies
DevProofs uses Cloudflare Analytics to understand broad website activity and performance. We may introduce Google Analytics in the future to understand metrics such as unique page visits, traffic sources and general usage patterns.
If Google Analytics or another non-essential analytics service is introduced, it will be identified in this policy and should load only after you accept non-essential cookies through the DevProofs consent controls. If you decline non-essential cookies, optional analytics scripts should not load.
DevProofs does not use marketing pixels, retargeting cookies, behavioural advertising, Meta Pixel, TikTok Pixel, Google Ads conversion tracking or comparable advertising technologies on the website at this time. DevProofs may advertise the Service on third-party advertising platforms, but that does not mean those platforms' tracking scripts are installed on DevProofs.
7. Third-party resources and browser storage
DevProofs may load third-party resources that help display or operate the website. These resources do not necessarily set cookies, but their providers may receive technical information such as your IP address, browser information, requested page and device/network metadata when your browser requests the resource.
| Resource | Typical purpose |
|---|---|
| Google Fonts | Loading website typography. |
| Tailwind CDN | Website styling and user-interface presentation. |
| Font Awesome CDN | Icons used in the interface. |
| unpkg / AOS and similar animation libraries | Interface animation and visual effects where enabled. |
| cdnjs resources such as html2canvas and jsPDF | CV builder and client-side document/image export features where enabled. |
| Cloudflare/CDN | Security, performance, content delivery, analytics and bot protection. |
Browser storage may also be used for CV-builder drafts, UI preferences, preview preferences and other functional settings. You can usually remove these through your browser's site-data controls, although doing so may reset preferences or delete unsaved drafts.
8. Managing your choices
8.1 DevProofs settings
You can manage non-essential cookie preferences through the cookie settings area in your account settings, where available. Your recorded preference is generally kept for up to one year or longer where legally permitted and appropriate. You may update your choice later.
8.2 Browser controls
You can also use browser settings to block, delete or limit cookies and clear local storage. Browser controls vary by provider. Be aware that blocking or deleting essential cookies can prevent you from logging in, using LinkedIn OAuth, saving preferences or accessing other core DevProofs functions.
9. GDPR, EEA/Schengen processing and contact
DevProofs is operated from Romania, within the European Union and the European Economic Area/Schengen area. Primary application and database infrastructure is hosted with OVHcloud in Germany. Occasional backups may be retained in Romania under access controls.
For information about how we process personal data, lawful bases, retention, international transfers and your GDPR rights, read our Privacy Policy. You may also review our Terms and Conditions and Pricing.
If you have a cookie, consent or privacy question, contact [email protected]. You may also have the right to complain to the Romanian data-protection authority, Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), or the relevant supervisory authority in your country of residence or work.
10. Updates to this policy
We may update this Cookie Policy when our technologies, providers, legal obligations or consent practices change. The current version will be published on this page with an updated effective date. If we add a new non-essential technology that requires consent, we will update the relevant controls before using it where required by law.
Cookie and privacy questions
Contact [email protected]
DevProofs · Pelea Raul-Daniel · Tureni, Cluj, Romania