What is stored
- Local storage for your Daily NAP Planner entries, so your plan survives a page refresh. This never leaves your device.
- Local storage for interface preferences, such as low-energy mode.
- A secure first-party cookie named session-id with a random value and a lifetime of up to 30 minutes, used to relate page views in one short website visit.
- Cloudflare, which serves and protects the website, currently sets a secure __cf_bm cookie for bot detection. Cloudflare documents it as expiring after 30 minutes of continuous inactivity. It is separate from NAP's page-view session identifier.
Website page-view analytics
On the website only, NAP's hosting layer loads a first-party, privacy-minimal analytics script from /~flock.js. For a page view it sends the page URL and path, referring page, browser user-agent, locale, a country derived from the browser's time zone, and a random session identifier to the same-site /~api/analytics endpoint. The identifier is stored in a secure first-party cookie for up to 30 minutes. The deployed tag does not enable the script's performance or Web Vitals reporting. This website mechanism is separate from NAP's product-event contract, whose transmission remains switched off, and from the native iOS and Android apps, which contain no analytics transmission.
What is not used
- Advertising or cross-site tracking cookies.
- Third-party profiling scripts.
- NAP product analytics events or native-app analytics transmission.
Your control
You can clear NAP's browser storage at any time through your browser settings, or by using “Delete my local planner data” in the planner. Clearing it removes your saved plan permanently.
Clearing cookies removes the current website analytics session identifier. A later page view may create a new short-lived identifier.
Published for the NAP limited beta. Last updated 22 September 2026. This text describes how NAP currently works, written in plain language by the founder. It is not legal advice.