Cookie Policy
This Cookie Policy explains which cookies and comparable storage technologies Klymeo uses, for what purpose, and on what legal basis. It supplements our Privacy Policy.
This page is legally binding in German only. The German text below is the authoritative version; this notice is informational and not a certified translation.
1. What Are Cookies and Comparable Technologies?
Cookies are small text files that are stored on your device when you visit a website. Comparable technologies such as local storage, session storage, pixels, or browser fingerprinting serve similar purposes. German law (§ 25 TDDDG) is technology-neutral and covers any storage of information on your device and any access to information already stored there — regardless of the specific technique used. In this policy, we therefore use the term "cookies" as shorthand for all of these techniques.
A distinction is made between first-party cookies, which are set by the website being visited itself, and third-party cookies, which originate from embedded third-party providers. Klymeo — as listed in the table in Section 5 — uses exclusively first-party entries.
2. Data Controller
The controller within the meaning of Art. 4 No. 7 GDPR is:
André Bäcker
Klymeo (sole proprietorship)
Hopstener Straße 25
49479 Ibbenbüren
Germany
Email: support@klymeo.com
Phone: +49 176 21878801
General information on the processing of personal data can be found in our Privacy Policy.
3. Legal Bases
The use of cookies is legally assessed on two levels. At the first level, § 25 TDDDG (German Telecommunications-Digital-Services-Data-Protection Act) governs the storage of information on your device and access to it: for cookies that are not technically necessary, your consent is generally required (§ 25(1) TDDDG), while cookies that are strictly technically necessary are permitted without consent (§ 25(2) No. 2 TDDDG). At the second level, the subsequent processing of personal data requires a legal basis under Art. 6(1) GDPR — for technically necessary cookies, typically our legitimate interest in a functioning, secure offering or the performance of a contract (lit. f or lit. b, respectively); for cookies requiring consent, your consent (lit. a).
Klymeo currently uses exclusively technically necessary cookies as well as functional first-party cookies you have actively chosen (see Section 5), and does not operate any analytics, marketing, or tracking services. Against this background, no consent-based cookie banner is currently required. The functional settings cookies (language, display) are set exclusively following your active selection and do not serve advertising or analytics purposes.
4. Cookie Categories
Cookies can be divided into four categories based on their purpose. What matters for the consent requirement is not the label, but the function:
- Technically necessary cookies keep the service you want running (e.g. login, session, security). They are generally exempt from consent insofar as they are strictly necessary for providing the service you have expressly requested (§ 25(2) No. 2 TDDDG).
- Functional cookies store settings you have chosen (e.g. language, display) and increase convenience.
- Statistics/analytics cookies measure the use of the website. They require consent. Not used by Klymeo.
- Marketing/tracking cookies serve advertising and cross-site recognition. They always require consent. Not used by Klymeo.
Klymeo currently uses exclusively cookies from the first two categories.
5. Cookies and Storage Technologies Used
The following overview lists the cookies and comparable storage technologies actually in use. For each entry, the provider, type, category, purpose, retention period, and origin (first- or third-party) are specified.
- __Secure-authjs.session-tokenProvider: Klymeo (own authentication)Type: HTTP cookie (HttpOnly, Secure)Category: Technically necessaryPurpose: Carries the active login (signed session token) in the logged-in area. Without this cookie, using the logged-in dashboard is not possible.Retention period: up to 30 days (renewed on a rolling basis)Origin: First-party
- __Host-authjs.csrf-tokenProvider: Klymeo (own authentication)Type: HTTP cookie (HttpOnly, Secure)Category: Technically necessaryPurpose: Protects the login and form submission process against cross-site request forgery (CSRF).Retention period: SessionOrigin: First-party
- __Secure-authjs.callback-urlProvider: Klymeo (own authentication)Type: HTTP cookieCategory: Technically necessaryPurpose: Remembers, during login, the destination page to redirect to after successful sign-in.Retention period: SessionOrigin: First-party
- __Secure-authjs.pkce.code_verifier, __Secure-authjs.state, __Secure-authjs.nonceProvider: Klymeo / Zitadel loginType: HTTP cookie (HttpOnly, transient)Category: Technically necessaryPurpose: Secure the OpenID Connect login handshake with the identity service Zitadel (PKCE, state, and nonce checks against attacks); deleted again immediately after login.Retention period: a few minutesOrigin: First-party
- klymeo.localeProvider: KlymeoType: HTTP cookieCategory: FunctionalPurpose: Stores your chosen interface language (German/English).Retention period: 1 yearOrigin: First-party
- klymeo-themeProvider: KlymeoType: Local StorageCategory: FunctionalPurpose: Stores the chosen appearance (light/dark/system default) so the interface doesn't flash on load. No personal data is stored.Retention period: persistent, until you clear your browser storageOrigin: First-party
- LiveKit (session storage)Provider: LiveKit (LiveKit Inc.)Type: Local StorageCategory: Technically necessary (voice interview only)Purpose: Used exclusively during a voice interview; the library used merely clears an earlier entry and does not itself store any persistent value.Retention period: not persistent (cleanup only)Origin: First-party
Note: In encrypted production operation (HTTPS), the Auth.js cookies are set with the security prefixes __Secure- or __Host-. In a local development environment without HTTPS, these prefixes are omitted (e.g. authjs.session-token). The login cookies mentioned serve exclusively to authenticate the logged-in service you have expressly requested and are therefore technically necessary and exempt from consent (§ 25(2) No. 2 TDDDG).
6. Third Parties and Recipients
No cookies from third-party providers are set in your browser. The login cookies come from our own, self-operated authentication (NextAuth/Auth.js with the identity service Zitadel, which we operate ourselves) and are first-party entries of our own domain.
The other services we use (including database, AI analysis, email delivery, speech processing) operate exclusively server-side and do not set any cookies in your browser. A complete list of these processors with purpose, location, and legal basis can be found in our Privacy Policy.
Booking a demo appointment via Cal.com takes place via an external link; no third-party cookie is set on Klymeo's pages in doing so. Fonts used are delivered locally; there is no connection to a third-party font network (CDN).
7. Transfers to Third Countries
The cookies and storage technologies referred to in this Cookie Policy do not result in any transfer of personal data to a third country: the login cookies are set by our own authentication, operated in Germany; the functional entries and the voice entry are likewise first-party. Insofar as we use server-side service providers based in a third country (e.g. the USA) as part of operating the platform, this is set out, together with the safeguards in place (in particular the EU Standard Contractual Clauses), in our Privacy Policy.
8. Withdrawal and Managing Your Settings
Since Klymeo currently only uses technically necessary and functional cookies, there is no consent to withdraw. You can view, restrict, or delete cookies that have been set and stored content at any time via your browser settings (e.g. by deleting website data). Please note that deleting the technically necessary login cookies will log you out of the logged-in area.
Should cookies requiring consent (e.g. for analytics or marketing purposes) be added in the future, we will obtain your consent in advance via a consent banner and provide a permanently accessible way for you to change your selection granularly at any time and withdraw it with effect for the future — as easily as you gave it.
9. Changes to This Cookie Policy
We will update this Cookie Policy if the technologies used or the legal framework changes. The version published here, marked with a date, applies in each case. You can find the current version date at the end of this page.
Stand: June 2026