Skip to content

Legal

Cookie Policy.

Every cookie and storage key, listed by name — including the ones that aren’t technically cookies.

This website

nsixhub.com — the site you’re reading now — sets no cookies. None at all: no analytics, no advertising, no tracking, and nothing stored in your browser. It makes no requests to third parties either; even the fonts are served from our own site rather than fetched from Google. That’s why you haven’t been asked to click through a consent banner — there is genuinely nothing to consent to.

The platform: three cookies, all of them sign-in

The N Six Hub platform sets exactly three cookies, and an ordinary user only ever receives the first — the other two belong to N Six’s own administration console. All are first-party, all exist to keep a session signed in, and none is used for analytics, advertising or tracking of any kind.

CookieWhat it doesLastsParty
nsixhub_refreshKeeps you signed in. HttpOnly (scripts can’t read it) and sent only to the sign-in refresh endpoint.7 days, or 30 days with “remember me”First party
nsixhub_admin_refreshKeeps an N Six platform administrator signed in to the separate admin console. Never set for ordinary users.12 hoursFirst party
nsixhub_admin_sessionIdentifies that admin-console session. Never set for ordinary users.12 hoursFirst party

Browser storage that isn’t cookies

UK law (PECR) covers everything a service stores on your device, not just cookies — so here is the rest of it. The platform keeps some data in your browser’s local storage. All of it is functional: it either makes the app work or remembers a choice you made. None of it is used for tracking, and none of it is readable by other websites.

KeyWhat it doesLasts
nsixhub_device_idA random ID for this browser, so you can see and revoke individual devices in Settings → Security.Until you clear it
nsix.hmrc.device-idA random device ID that HMRC’s fraud-prevention rules require us to send with VAT traffic. Created only the first time you use an HMRC-connected screen; sent only to HMRC.Until you clear it
portal_access_token, portal_userKeeps customer-portal visitors signed in to the portal.Until sign-out or cleared
nsix.themeRemembers your theme choice.Until you clear it
nsix.draft.*Unsent form drafts, saved locally so a closed tab doesn’t lose your work.Until sent or discarded
nsixhub.chat.*Your chat device identity for end-to-end encryption — an ID for this browser and which account owns it. The encryption keys themselves live in IndexedDB, described below.Until you clear it
nsixhub.lists.cacheOwner, nsixhub.chat.cacheOwnerRecord which account the local caches below belong to, so a different sign-in on the same browser wipes them rather than reads them.Until you clear it
nsixhub.wakeword.armedRemembers that you switched the voice wake-word on. Off unless you opted in, and removed when you switch it off.Until you clear it
nsix.drive.*, nsix.nav.float, nsix.bookings.setupDone, crafting.symbols.* and similarSmall interface preferences and switches — layouts, toggles, “don’t show me this again”, a debug flag you can set yourself.Until you clear it

Session storage

A few things live in session storage, which your browser wipes when the tab closes: a guest’s ticket when they join a meeting by link, the unlocked state of a protected share link, an in-progress form step, and an onboarding selection. Nothing in session storage outlives the tab.

Bigger things: IndexedDB

Alongside the small keys above, the platform keeps three larger stores in IndexedDB — a browser database only our own site can read. nsixhub-chat holds a local copy of your conversations and messages, so chat opens instantly instead of waiting for the server, and its keystore holds your message-encryption keys — kept on your device precisely so that we can’t read your messages. nsixhub-meeting-keys holds your private key for end-to-end-encrypted meetings, stored so this browser can use it but not export it. nsixhub-lists holds a local copy of your calls and meetings lists so those screens open without a spinner.

These caches are tied to the account that made them: if a different account signs in on the same browser, they are wiped before they are read, not shared.

The HMRC device identifier, honestly

One entry above deserves its own paragraph. When your organisation connects VAT to HMRC, the law — HMRC’s Making Tax Digital fraud-prevention specification — requires software like ours to send a stable device identifier with every HMRC-connected request, including read-only views of obligations and payments, not just filing a return. That’s what nsix.hmrc.device-id is. It isn’t our choice and it isn’t tracking for our benefit: it goes only to HMRC, travels only with HMRC-bound traffic, and is never created unless you use those screens.

Because it lives in your browser, UK law (PECR) applies to it like any cookie: storing it needs your consent unless it is strictly necessary for a service you have asked for. This one is exempt as strictly necessary — it is created only when you use the HMRC-connected VAT screens, someone who never touches the VAT connection never gets one, and HMRC’s specification makes the identifier mandatory, so the service you asked for cannot be provided without it. The lawful basis for sending the data itself is legal obligation, and our Privacy Policy at nsixhub.com/legal/privacy lists everything the fraud-prevention headers contain.

Third-party requests the platform makes

The signed-in platform loads fonts from Google Fonts, and — only when you use map features — Google Maps. Those requests go to Google’s servers, so your IP address reaches Google, along with the map area and address searches when you use Maps. Google’s own privacy policy applies to what Google does with that.

Some map screens draw their background from open-data tile servers instead: they load map tiles directly from OpenStreetMap and OpenFreeMap. Those requests carry your IP address and the coordinates of the map area you are viewing — nothing more.

When you subscribe, the card form is Stripe’s own, loaded from Stripe’s servers into the page — what you type in it goes to Stripe directly and never touches our systems. Stripe stores its own identifiers in your browser as part of its fraud prevention while you use that form; that storage is Stripe’s, governed by Stripe’s privacy policy, and it exists to keep the payment you asked for secure. Managing billing later happens on Stripe’s own pages.

That is the honest extent of it. There are no analytics scripts, tag managers, tracking pixels or advertising networks anywhere in the product, and calls and meetings connect to media servers we run ourselves rather than to a third-party service.

How to refuse or clear what we store

PECR gives you the right to refuse storage on your device, so here is what you can actually do — starting with the easy half: this website stores nothing, so there is nothing to manage here. Everything below concerns the signed-in platform.

Every browser lets you see, block or delete cookies and site data for a single site — usually under Settings → Privacy, or via the padlock or tune icon next to the address bar. Deleting our site data is always safe in the sense that nothing of your organisation’s is lost: your records live on the server, not in your browser.

What clearing does cost you: you are signed out (that is all the cookies do, so that is all that breaks — sign back in and you are where you were), unsent drafts saved on that device are gone, preferences revert to defaults, and the local chat and list caches are simply rebuilt from the server. The one thing to know before you clear: your chat encryption identity lives on this device, and clearing it resets that identity — the app registers a fresh one next time you open chat, and messages encrypted only to the old identity may no longer be readable on this device.

Can you refuse the strictly-necessary items and keep using the platform? No — and we would rather say that plainly than imply a choice that doesn’t exist. The sign-in cookie is how a session works: block it and you cannot stay signed in. The HMRC device identifier can be deleted at any time, but it is recreated the next time you use the VAT connection, because HMRC requires it — the real choice there is whether to use the VAT connection at all. Everything optional — the wake word, the theme, the interface toggles — can be switched off where you set it, and switching off removes or resets the stored item.

Why there’s no consent banner

Consent banners exist because most software stores things that need consent — analytics, advertising, cross-site tracking. We don’t. Everything on this page is either strictly necessary to provide something you asked for (keeping you signed in, encrypting your chats, taking a payment securely, meeting a legal requirement from HMRC) or a preference you set yourself. If we ever introduce something that genuinely needs consent, we’ll ask for it properly before anything is stored — not bury it here and hope.

Changes & questions

If what we store changes, this page changes with it. Questions: privacy@nsixhub.com. Last updated: 3 September 2026.