Cookie Notice
Effective August 6, 2026 · Last updated August 6, 2026
Draft — pending legal review. Accurate to how the product works today. If analytics or marketing cookies are added later, this page and the consent approach both have to change.
Short version: we set the cookies needed to keep you signed in, and nothing else.
The dashboard
| Cookie | Purpose | Expires |
|---|---|---|
| Session cookie | Keeps you signed in and identifies your session | On sign-out, or after the session lifetime |
| CSRF token | Prevents another site submitting forms as you | With the session |
| OAuth state | Protects the sign-in redirect against tampering | Minutes, during sign-in only |
These are strictly necessary. The service cannot work without them, so under the ePrivacy Directive and equivalent rules they don't require consent. That's why you aren't being asked to click a banner.
Analytics and advertising
We don't currently run any analytics, advertising or session-recording scripts on the marketing site or in the dashboard. There are no third-party tracking cookies, no pixels, no fingerprinting.
If that changes, we'll update this page and add a proper consent mechanism before setting anything non-essential.
The chat widget
The widget that customers embed on their own sites doesn't use cookies. It stores a small amount of data in the visitor's browser via localStorage:
- a visitor token, so someone returning to the site sees their own past conversations
- which conversations they've already read, so unread badges are accurate
- a cached copy of the workspace's branding, so the widget doesn't visibly change colour while it loads
This stays in the visitor's browser. Clearing site data removes it, and the widget will simply treat them as a new visitor.
Managing cookies
Your browser can block or delete cookies. Blocking the session cookie will stop you being able to sign in — there's no way around that, since being signed in is the cookie.
Questions
[CONTACT EMAIL]