Public storage notice
Cookies and browser storage
Fluxion Portal uses cookies and the browser's localStorage and sessionStorage. Necessary storage secures shared work. Quick works and other convenience storage start only with your consent.
You can change your choice at any time through the cookie icon at the bottom left of the screen. Necessary-only use does not prevent you from opening or acknowledging shared work.
Effective from 24 July 2026
Necessary storage
These items are used only to deliver the secure service you requested, remember the privacy choice, or apply an explicit language selection.
__Host-fluxion_share_<browser-specific identifier> (fluxion_share_dev_<…> in development)
- Category
- Necessary
- Technology
- First-party cookie; Secure, HttpOnly, SameSite=Strict, Path=/ in production
- Purpose
- Authenticates access to shared work and binds the session to this browser.
- Data
- Opaque random session identifier; no password or raw share token.
- Duration
- Until share expiry or 7 days by default, whichever comes first; the server also ends a session after 24 hours idle.
- Access and recipients
- Sent only to the first-party Portal API and inaccessible to JavaScript. ProduXion and its Google Cloud infrastructure process the request.
fluxion_portal_locale
- Category
- Necessary for the requested language
- Technology
- First-party cookie; SameSite=Lax and Secure over HTTPS
- Purpose
- Remembers the language explicitly selected by the user.
- Data
- Language code en, fi, or sv.
- Duration
- 1 year.
- Access and recipients
- Read by Portal on the server and in the browser; no third-party access.
fluxion.portal.binding.v1 and fluxion.portal.csrf.v1
- Category
- Necessary security
- Technology
- sessionStorage
- Purpose
- Binds the session to the browser and prevents cross-site forged action requests.
- Data
- Random 256-bit browser binding and CSRF token.
- Duration
- Browser-tab session; also cleared on logout where applicable.
- Access and recipients
- Only Portal in the same tab; security values are sent to the first-party API when required.
fluxion.portal.pending-actions.v1 and fluxion.portal.in-flight-actions.v1
- Category
- Necessary action reliability
- Technology
- sessionStorage
- Purpose
- Prevents duplicate user acknowledgements and recovers an in-progress submission after a network interruption.
- Data
- Tracking reference, action and target type, idempotency/action ID, time, and status.
- Duration
- Tab session or until a terminal action status is confirmed.
- Access and recipients
- Only Portal in the same tab; action IDs are verified through the first-party API.
fluxion.portal.storage-consent.v1
- Category
- Necessary privacy-choice memory
- Technology
- localStorage
- Purpose
- Remembers whether optional storage was allowed and prevents use without permission.
- Data
- Schema and policy version, random receipt ID, yes/no choice, times, method, and language.
- Duration
- Portal uses the choice for 180 days or until it is replaced. An expired localStorage record is deleted and a new choice requested on the next Portal visit.
- Access and recipients
- Only Portal in this browser; the record is not sent to the server.
Optional convenience storage
These items are neither read nor written before consent. Refusing or withdrawing consent removes every optional key below.
fluxion.portal.quick-works.v2 (previous fluxion.portal.recent-works.v1 is removed on migration)
- Category
- Optional – quick works
- Technology
- localStorage
- Purpose
- Shows up to 10 recently opened or pinned shared works in the home-page quick-work list.
- Data
- Tracking code, safely bounded work title, sharing company, optional recipient name, status text, open time, pin state, and completion state.
- Duration
- Portal uses the item for no more than 180 days from opening and only while consent is valid. An expired localStorage item is deleted on the next Portal visit; the user may remove it earlier.
- Access and recipients
- Only Portal in this browser. The data is not sent to the server to provide the list.
fluxion.portal.remembered-access.v1
- Category
- Optional – secure return
- Technology
- localStorage
- Purpose
- Reconnects a return visit to an existing protected HttpOnly session without re-entering the password.
- Data
- Tracking code, random browser binding, and saved time; no more than 10 entries.
- Duration
- Portal uses the item for no more than 7 days, until the session is removed, or until consent is withdrawn. An expired localStorage item is deleted on the next Portal visit.
- Access and recipients
- Only Portal in this browser. The binding is sent to the first-party API to verify the session; no password is stored.
fluxion.portal.demo-access.v1
- Category
- Optional – remembered demo
- Technology
- localStorage
- Purpose
- Remembers that the local Portal demo was opened.
- Data
- Demo tracking code and saved time; no more than 10 entries.
- Duration
- Portal uses the item for no more than 180 days or until consent is withdrawn. An expired localStorage item is deleted on the next Portal visit.
- Access and recipients
- Only Portal in this browser; not sent to the server.
Analytics, advertising, and third parties
Portal currently has no Google Analytics, Tag Manager, advertising pixels, heat maps, session replay, user profiling, or third-party tracking scripts. It therefore does not present fictional consent categories. If such a purpose is added, it will be blocked by default, this notice will be updated, and fresh consent will be requested before activation.
Application code, images, fonts, and API calls load from the first party. Google Cloud is the server-environment processor but does not receive the local quick-work list. Ordinary Portal requests separately create security and service logs as described in the privacy notice.
Camera and external links
The QR reader asks for camera access only after a button press. Images are processed in device memory and are not stored or sent. The browser or operating system may remember the device permission; manage it in browser or device settings.
The FluXion.fi link opens an external site only after a click and includes campaign parameters through which the destination can recognise Portal as the traffic source. Portal does not preload destination tracking.
Changing the choice and deleting data
The cookie icon is available at the bottom left of every Portal page after a choice. Turning optional storage off immediately clears quick works, remembered return, demo access, and the legacy quick-work key. Settings can also clear these items while keeping consent for future quick works.
The necessary HttpOnly session ends on logout. You can also delete every browser-held item through your browser's site-data settings. Blocking storage in the browser may prevent quick works and the secure session from operating.
Contact
Storage is managed by ProduXion Oy, Business ID 3605230-4, Amerintie 1, 04320 Tuusula, Finland. Send questions and rights requests to the address below.
Privacy and cookie contact: support@fluxion.fi
In Finland, terminal-equipment storage is supervised by Traficom