Legal & transparency
Cookies and similar technologies
In short: Acutic sets three strictly-necessary first-party cookies — one on acutic.io that remembers the language version you opened, two on .acutic.io that carry your login to the product app — and, once you are signed in, a small number of browser-storage keys that contain only interface settings you chose yourself. Our analytics tools (Plausible + PostHog) and our bot check (Cloudflare Turnstile) are cookieless. No tracking cookies, no advertising cookies, no fingerprinting, no third-party script persists anything on your device. Under § 25 (2) Nr. 2 TDDDG (the German implementation of Art. 5 (3) ePrivacy Directive), strictly-necessary storage does not require prior consent, so we do not display a cookie banner.
Analytics — Plausible (cookieless)
We use Plausible Analytics, an EU-hosted (Hetzner, Falkenstein, Germany) cookieless web-analytics service. The Plausible script does not set any cookies, does not use localStorage or fingerprinting, and does not collect personal data: it counts page views and computes a daily-rotating hash from your IP address and User-Agent that is discarded after 24 hours. See the Plausible data policy for details.
Analytics — PostHog (cookieless)
We additionally use PostHog on PostHog Cloud EU (eu.posthog.com — servers in Frankfurt, Germany) for product analytics — page views, web vital metrics, and feature-usage events on the dashboard. The PostHog browser SDK runs in persistence: 'memory' mode: it does not set cookies, does not use localStorage or sessionStorage, and does not fingerprint your device. On the dashboard, once you are signed in, we attach your internal account ID (a UUID — not your email or name) to subsequent events so we can measure per-user feature usage and retention. The dashboard sends nothing on the public marketing site; only anonymous pageviews flow from acutic.io.
When you delete your account, we propagate the deletion to PostHog within minutes via an authenticated server-side call. You can also email privacy@acutic.io to request immediate erasure.
Bot protection — Cloudflare Turnstile (cookieless)
The cancellation form (acutic.io/cancel) and the withdrawal form (acutic.io/withdraw) on this website, as well as account registration and the withdrawal form in the product app, embed Cloudflare Turnstile as a frame from challenges.cloudflare.com to distinguish people from automated submissions. In our integration Turnstile sets no cookie and writes nothing to browser storage; Cloudflare's “pre-clearance” option, which would set one, is not enabled. Cloudflare processes only the signals needed for the check (IP address, TLS and browser characteristics). Cloudflare is listed as a sub-processor on /legal/subprocessors.
Cookies in use
All three cookies are first-party and strictly necessary. The two __Secure-better-auth.* cookies are set by our API (api.acutic.io) for the domain .acutic.io and only exist once you sign in to the product app; outside a production deployment (plain HTTP) the same cookies carry the name without the __Secure- prefix.
| Name | Type | Purpose | Duration | Set by | Legal basis |
|---|---|---|---|---|---|
| NEXT_LOCALE | Cookie | Remembers which language version of acutic.io you opened (EN / DE / TR) so the next page loads in the same language. Set by the language routing of the website. | Session — deleted when you close the browser. | Acutic — acutic.io (first-party) | § 25 (2) no. 2 TDDDG; Art. 6 (1) (f) GDPR (setting you chose yourself) |
| __Secure-better-auth.session_token | Cookie | Your login session for the product app (app.acutic.io). HttpOnly, Secure, SameSite=Lax. Without it every request would be treated as signed out. | 7 days; extended while you use the app, deleted at sign-out. | Acutic — api.acutic.io, valid for .acutic.io (first-party) | § 25 (2) no. 2 TDDDG; Art. 6 (1) (b) GDPR (performance of the contract) |
| __Secure-better-auth.state | Cookie | Only when you sign in with Google or Apple: a signed one-time value that ties the return from the provider to the browser that started the sign-in (protection against forged sign-in responses). | 5 minutes. | Acutic — api.acutic.io, valid for .acutic.io (first-party) | § 25 (2) no. 2 TDDDG; Art. 6 (1) (f) GDPR (security of the sign-in) |
Browser storage (localStorage / sessionStorage)
Besides cookies, our sites write a few keys to your browser's own storage. Two of them exist on acutic.io and only for the current tab; the rest are set by the product app after you sign in. They contain interface settings and no analytics identifiers, never leave your device, and disappear when you clear the site data in your browser.
| Name | Type | Purpose | Duration | Set by | Legal basis |
|---|---|---|---|---|---|
| locale-banner-dismissed | sessionStorage | Set when you close the "this page is available in your language" notice so it does not reappear on every page of the same visit. | Until you close the browser tab. | Acutic — acutic.io (first-party) | § 25 (2) no. 2 TDDDG; Art. 6 (1) (f) GDPR (setting you chose yourself) |
| acutic.referredByCode | sessionStorage | Only when you arrive through a referral link (?ref=…): keeps the referral code for the duration of the visit so it can be passed on when you sign up. | Until you close the browser tab. | Acutic — acutic.io (first-party) | § 25 (2) no. 2 TDDDG; Art. 6 (1) (b) GDPR (performance of the contract) |
| acutic_theme_preference | localStorage | Your display theme (light / dark / system), mirrored from your account settings so the first paint after a reload already uses it. | Until you clear the site data in your browser. | Acutic — app.acutic.io (first-party) | § 25 (2) no. 2 TDDDG; Art. 6 (1) (f) GDPR (setting you chose yourself) |
| acutic_sidebar_collapsed | localStorage | Whether you collapsed the navigation sidebar. | Until you clear the site data in your browser. | Acutic — app.acutic.io (first-party) | § 25 (2) no. 2 TDDDG; Art. 6 (1) (f) GDPR (setting you chose yourself) |
| acutic_has_session | localStorage | A flag ("1") noting that you signed in on this browser, so the sign-in page can skip a needless session check after you sign out. It is not a session token and grants no access; the real session lives in the __Secure-better-auth.session_token cookie. | Removed when you sign out or when a session check fails; otherwise until you clear site data. | Acutic — app.acutic.io (first-party) | § 25 (2) no. 2 TDDDG; Art. 6 (1) (b) GDPR (performance of the contract) |
| datatable.pageSize.<table> | localStorage | Rows per page you selected in a data table, one key per table (for example the portfolio table). | Until you clear the site data in your browser. | Acutic — app.acutic.io (first-party) | § 25 (2) no. 2 TDDDG; Art. 6 (1) (f) GDPR (setting you chose yourself) |
| recentResearchSymbols | localStorage | The last ten instruments you opened in Research (symbol, name, type, time), shown as your recent list. You can clear it from the app. | Until you clear the list in the app or clear the site data in your browser. | Acutic — app.acutic.io (first-party) | § 25 (2) no. 2 TDDDG; Art. 6 (1) (f) GDPR (setting you chose yourself) |
| acutic_seen_tours | localStorage | Which product tours you have already seen — a local copy of the same record in your account, so a tour is not shown twice while the account record loads. | Until you clear the site data in your browser. | Acutic — app.acutic.io (first-party) | § 25 (2) no. 2 TDDDG; Art. 6 (1) (f) GDPR (setting you chose yourself) |
| acutic_cross_route_tour | sessionStorage | Step position of a product tour that spans several pages, so the tour continues after a page change. | At most 1 hour; removed when the tour ends or you close the tab. | Acutic — app.acutic.io (first-party) | § 25 (2) no. 2 TDDDG; Art. 6 (1) (f) GDPR (setting you chose yourself) |
| acutic_force_show_getting_started | localStorage | Set when you choose "Replay Getting Started" in Settings; keeps the Getting Started item visible in the sidebar. | Until you switch the option off again or clear the site data in your browser. | Acutic — app.acutic.io (first-party) | § 25 (2) no. 2 TDDDG; Art. 6 (1) (f) GDPR (setting you chose yourself) |
| acutic_aiNudge_dismissed_<symbol> | localStorage | Set when you dismiss the journal reminder on a research page, one key per instrument, so the reminder stays closed for that instrument. | Until you clear the site data in your browser. | Acutic — app.acutic.io (first-party) | § 25 (2) no. 2 TDDDG; Art. 6 (1) (f) GDPR (setting you chose yourself) |
| acutic.lastDataExportAt | localStorage | Time of your last data export (GDPR Art. 20), shown in Settings as "last exported on …". | Until you clear the site data in your browser. | Acutic — app.acutic.io (first-party) | § 25 (2) no. 2 TDDDG; Art. 6 (1) (f) GDPR (setting you chose yourself) |
Third-party services that store nothing on your device
- Plausible Analytics (
plausible.io) — Public website acutic.io. Sets no cookie and writes nothing to localStorage or sessionStorage. Counts page views with a daily-rotating hash that is discarded after 24 hours. - PostHog (
eu.posthog.com) — Public website acutic.io and product app app.acutic.io. Runs in persistence: memory mode — no cookie, no localStorage, no sessionStorage. Identifiers live only for the lifetime of the tab; the script and its configuration are loaded from eu-assets.i.posthog.com. - Cloudflare Turnstile (
challenges.cloudflare.com) — Cancellation form (acutic.io/cancel) and withdrawal form (acutic.io/withdraw) on the website; account registration and the withdrawal form in the product app. Bot check embedded as a frame. In our integration it sets no cookie (the Cloudflare "pre-clearance" option, which would set one, is not used). Cloudflare processes only the signals needed for the check.
Why no consent banner?
§ 25 (2) TDDDG exempts storage that is strictly necessary for the service the user actively requested. Every entry in the tables above qualifies under that exemption: your login session, the language version you chose, and interface settings you set yourself. The analytics tools and the bot check store nothing on your device, so they are also outside the scope of § 25 (1) TDDDG. We therefore display no banner.
If we ever add tracking technology that is not strictly necessary (for example, third-party advertising pixels or product analytics that set cookies), we will publish an updated version of this page and add a TDDDG-compliant consent banner with three equal-prominence options (Accept all / Reject all / Settings).
Inventory last verified against the code and the live sites on 2026-09-03.
Related pages
Cookies — Deutsche Fassung
Kurzfassung: Acutic setzt drei technisch notwendige Erstanbieter-Cookies — eines auf acutic.io, das sich die von Ihnen geöffnete Sprachversion merkt, und zwei auf .acutic.io, die Ihre Anmeldung in der Produktanwendung tragen — sowie nach der Anmeldung einige wenige Einträge im Browser-Speicher, die ausschließlich von Ihnen selbst gewählte Oberflächeneinstellungen enthalten. Unsere Analyse-Werkzeuge (Plausible für die Marketing-Site, PostHog für Site und Produktanwendung, beide EU-gehostet) und unsere Bot-Prüfung (Cloudflare Turnstile) arbeiten cookielos. Tracking-Cookies, Werbe-Cookies, Fingerprinting und externe Analyse-Skripte, die etwas auf Ihrem Gerät speichern, werden nicht eingesetzt. Im eingeloggten Dashboard übermittelt PostHog zusätzlich Ihre interne Konto-ID (eine UUID, weder E-Mail noch Name), damit wir Funktionsnutzung pro Konto messen können — gespeichert wird auf Ihrem Gerät dennoch nichts. Bei Kontolöschung werden die zugehörigen PostHog-Daten innerhalb weniger Minuten entfernt. Da § 25 Abs. 2 Nr. 2 TDDDG für technisch notwendige Speichervorgänge keine Einwilligung verlangt, zeigen wir kein Cookie-Banner.
Verwendete Cookies
Alle drei Cookies sind Erstanbieter-Cookies und technisch notwendig. Die beiden __Secure-better-auth.*-Cookies werden von unserer API (api.acutic.io) für die Domain .acutic.io gesetzt und existieren erst, wenn Sie sich in der Produktanwendung anmelden; außerhalb einer Produktionsumgebung (unverschlüsseltes HTTP) tragen dieselben Cookies den Namen ohne das Präfix __Secure-.
| Name | Art | Zweck | Speicherdauer | Gesetzt von | Rechtsgrundlage |
|---|---|---|---|---|---|
| NEXT_LOCALE | Cookie | Merkt sich, welche Sprachversion von acutic.io Sie geöffnet haben (EN / DE / TR), damit die nächste Seite in derselben Sprache lädt. Gesetzt durch die Sprachweiche der Website. | Sitzung — wird beim Schließen des Browsers gelöscht. | Acutic — acutic.io (Erstanbieter) | § 25 Abs. 2 Nr. 2 TDDDG; Art. 6 Abs. 1 lit. f DSGVO (von Ihnen gewählte Einstellung) |
| __Secure-better-auth.session_token | Cookie | Ihre Login-Sitzung für die Produktanwendung (app.acutic.io). HttpOnly, Secure, SameSite=Lax. Ohne dieses Cookie würde jede Anfrage als abgemeldet behandelt. | 7 Tage; wird bei Nutzung verlängert und beim Abmelden gelöscht. | Acutic — api.acutic.io, gültig für .acutic.io (Erstanbieter) | § 25 Abs. 2 Nr. 2 TDDDG; Art. 6 Abs. 1 lit. b DSGVO (Vertragserfüllung) |
| __Secure-better-auth.state | Cookie | Nur bei der Anmeldung mit Google oder Apple: ein signierter Einmalwert, der die Rückkehr vom Anbieter an den Browser bindet, der die Anmeldung gestartet hat (Schutz vor gefälschten Anmeldeantworten). | 5 Minuten. | Acutic — api.acutic.io, gültig für .acutic.io (Erstanbieter) | § 25 Abs. 2 Nr. 2 TDDDG; Art. 6 Abs. 1 lit. f DSGVO (Sicherheit der Anmeldung) |
Browser-Speicher (localStorage / sessionStorage)
Neben Cookies schreiben unsere Seiten einige wenige Schlüssel in den eigenen Speicher Ihres Browsers. Zwei davon existieren auf acutic.io und nur für den aktuellen Tab; die übrigen setzt die Produktanwendung nach Ihrer Anmeldung. Sie enthalten Oberflächeneinstellungen und keine Analyse-Kennungen, verlassen Ihr Gerät nicht und verschwinden, wenn Sie die Website-Daten in Ihrem Browser löschen.
| Name | Art | Zweck | Speicherdauer | Gesetzt von | Rechtsgrundlage |
|---|---|---|---|---|---|
| locale-banner-dismissed | sessionStorage | Wird gesetzt, wenn Sie den Hinweis „Diese Seite ist in Ihrer Sprache verfügbar" schließen, damit er im selben Besuch nicht auf jeder Seite erneut erscheint. | Bis Sie den Browser-Tab schließen. | Acutic — acutic.io (Erstanbieter) | § 25 Abs. 2 Nr. 2 TDDDG; Art. 6 Abs. 1 lit. f DSGVO (von Ihnen gewählte Einstellung) |
| acutic.referredByCode | sessionStorage | Nur wenn Sie über einen Referral-Link (?ref=…) kommen: bewahrt den Referral-Code für die Dauer des Besuchs auf, damit er bei der Registrierung übergeben werden kann. | Bis Sie den Browser-Tab schließen. | Acutic — acutic.io (Erstanbieter) | § 25 Abs. 2 Nr. 2 TDDDG; Art. 6 Abs. 1 lit. b DSGVO (Vertragserfüllung) |
| acutic_theme_preference | localStorage | Ihr Anzeige-Design (hell / dunkel / System), gespiegelt aus Ihren Kontoeinstellungen, damit die erste Darstellung nach einem Neuladen bereits passt. | Bis Sie die Website-Daten in Ihrem Browser löschen. | Acutic — app.acutic.io (Erstanbieter) | § 25 Abs. 2 Nr. 2 TDDDG; Art. 6 Abs. 1 lit. f DSGVO (von Ihnen gewählte Einstellung) |
| acutic_sidebar_collapsed | localStorage | Ob Sie die Navigationsleiste eingeklappt haben. | Bis Sie die Website-Daten in Ihrem Browser löschen. | Acutic — app.acutic.io (Erstanbieter) | § 25 Abs. 2 Nr. 2 TDDDG; Art. 6 Abs. 1 lit. f DSGVO (von Ihnen gewählte Einstellung) |
| acutic_has_session | localStorage | Eine Markierung („1“), dass Sie sich in diesem Browser angemeldet haben, damit die Anmeldeseite nach dem Abmelden keine unnötige Sitzungsprüfung ausführt. Kein Sitzungs-Token, gewährt keinen Zugriff; die eigentliche Sitzung liegt im Cookie __Secure-better-auth.session_token. | Wird beim Abmelden oder bei einer fehlgeschlagenen Sitzungsprüfung entfernt; sonst bis Sie die Website-Daten löschen. | Acutic — app.acutic.io (Erstanbieter) | § 25 Abs. 2 Nr. 2 TDDDG; Art. 6 Abs. 1 lit. b DSGVO (Vertragserfüllung) |
| datatable.pageSize.<table> | localStorage | Von Ihnen gewählte Zeilen pro Seite in einer Datentabelle, ein Schlüssel pro Tabelle (zum Beispiel die Portfolio-Tabelle). | Bis Sie die Website-Daten in Ihrem Browser löschen. | Acutic — app.acutic.io (Erstanbieter) | § 25 Abs. 2 Nr. 2 TDDDG; Art. 6 Abs. 1 lit. f DSGVO (von Ihnen gewählte Einstellung) |
| recentResearchSymbols | localStorage | Die letzten zehn Instrumente, die Sie in Research geöffnet haben (Symbol, Name, Typ, Zeitpunkt), angezeigt als Ihre Verlaufsliste. In der App löschbar. | Bis Sie die Liste in der App leeren oder die Website-Daten in Ihrem Browser löschen. | Acutic — app.acutic.io (Erstanbieter) | § 25 Abs. 2 Nr. 2 TDDDG; Art. 6 Abs. 1 lit. f DSGVO (von Ihnen gewählte Einstellung) |
| acutic_seen_tours | localStorage | Welche Produkt-Touren Sie bereits gesehen haben — eine lokale Kopie desselben Eintrags in Ihrem Konto, damit eine Tour nicht doppelt erscheint, während der Konto-Eintrag lädt. | Bis Sie die Website-Daten in Ihrem Browser löschen. | Acutic — app.acutic.io (Erstanbieter) | § 25 Abs. 2 Nr. 2 TDDDG; Art. 6 Abs. 1 lit. f DSGVO (von Ihnen gewählte Einstellung) |
| acutic_cross_route_tour | sessionStorage | Schrittposition einer Produkt-Tour über mehrere Seiten hinweg, damit die Tour nach einem Seitenwechsel fortgesetzt wird. | Höchstens 1 Stunde; wird entfernt, wenn die Tour endet oder Sie den Tab schließen. | Acutic — app.acutic.io (Erstanbieter) | § 25 Abs. 2 Nr. 2 TDDDG; Art. 6 Abs. 1 lit. f DSGVO (von Ihnen gewählte Einstellung) |
| acutic_force_show_getting_started | localStorage | Wird gesetzt, wenn Sie in den Einstellungen „Erste Schritte erneut anzeigen" wählen; hält den Eintrag „Erste Schritte" in der Seitenleiste sichtbar. | Bis Sie die Option wieder ausschalten oder die Website-Daten in Ihrem Browser löschen. | Acutic — app.acutic.io (Erstanbieter) | § 25 Abs. 2 Nr. 2 TDDDG; Art. 6 Abs. 1 lit. f DSGVO (von Ihnen gewählte Einstellung) |
| acutic_aiNudge_dismissed_<symbol> | localStorage | Wird gesetzt, wenn Sie den Journal-Hinweis auf einer Research-Seite schließen, ein Schlüssel pro Instrument, damit der Hinweis für dieses Instrument geschlossen bleibt. | Bis Sie die Website-Daten in Ihrem Browser löschen. | Acutic — app.acutic.io (Erstanbieter) | § 25 Abs. 2 Nr. 2 TDDDG; Art. 6 Abs. 1 lit. f DSGVO (von Ihnen gewählte Einstellung) |
| acutic.lastDataExportAt | localStorage | Zeitpunkt Ihres letzten Datenexports (Art. 20 DSGVO), in den Einstellungen angezeigt als „zuletzt exportiert am …". | Bis Sie die Website-Daten in Ihrem Browser löschen. | Acutic — app.acutic.io (Erstanbieter) | § 25 Abs. 2 Nr. 2 TDDDG; Art. 6 Abs. 1 lit. f DSGVO (von Ihnen gewählte Einstellung) |
Drittdienste, die nichts auf Ihrem Gerät speichern
- Plausible Analytics (
plausible.io) — Öffentliche Website acutic.io. Setzt kein Cookie und schreibt nichts in localStorage oder sessionStorage. Zählt Seitenaufrufe über einen täglich wechselnden Hash, der nach 24 Stunden verworfen wird. - PostHog (
eu.posthog.com) — Öffentliche Website acutic.io und Produktanwendung app.acutic.io. Läuft im Modus persistence: memory — kein Cookie, kein localStorage, kein sessionStorage. Kennungen existieren nur für die Lebensdauer des Tabs; Skript und Konfiguration werden von eu-assets.i.posthog.com geladen. - Cloudflare Turnstile (
challenges.cloudflare.com) — Kündigungsformular (acutic.io/cancel) und Widerrufsformular (acutic.io/withdraw) auf der Website; Registrierung und Widerrufsformular in der Produktanwendung. Bot-Prüfung als eingebetteter Frame. In unserer Einbindung setzt sie kein Cookie (die Cloudflare-Option „Pre-Clearance", die eines setzen würde, wird nicht genutzt). Cloudflare verarbeitet nur die für die Prüfung nötigen Signale.
Warum kein Cookie-Banner?
§ 25 Abs. 2 TDDDG nimmt Speichervorgänge aus, die für den vom Nutzer ausdrücklich gewünschten Dienst unbedingt erforderlich sind. Jeder Eintrag in den obigen Tabellen fällt unter diese Ausnahme: Ihre Login-Sitzung, die von Ihnen gewählte Sprachversion und von Ihnen selbst vorgenommene Oberflächeneinstellungen. Analyse-Werkzeuge und Bot-Prüfung speichern nichts auf Ihrem Gerät und liegen damit auch außerhalb von § 25 Abs. 1 TDDDG. Wir zeigen daher kein Banner.
Wenn künftig nicht-notwendige Tracking-Technologien hinzukommen, ergänzen wir diese Seite und stellen ein TDDDG-konformes Banner mit gleichwertigen Auswahloptionen (Alle akzeptieren / Alle ablehnen / Einstellungen) bereit.
Inventar zuletzt gegen Code und Live-Systeme geprüft am 2026-09-03.