Platform
Cookie Policy
This page lists the shared platform cookies and similar technologies. Product modules may add route-specific items, which are listed on their own cookie policy pages. You can update optional preferences from the Cookie Preferences control in the user menu or the public footer control.
Privacy Policy| Name | Provider | Purpose | Category | Duration | Technology |
|---|---|---|---|---|---|
| __Secure-authjs.session-token / authjs.session-token | NextAuth | Session authentication for signed-in users. | necessary | Session / configured auth session lifetime | cookie |
| authjs.callback-url | NextAuth | OAuth and authentication redirect handling. | necessary | Session | cookie |
| authjs.csrf-token | NextAuth | CSRF protection for authentication flows. | necessary | Session | cookie |
| authjs.pkce.code_verifier / authjs.state / authjs.nonce | NextAuth | Short-lived OAuth sign-in flow protection (PKCE verifier, state, and nonce) set only while completing a third-party sign-in. | necessary | Minutes (during the sign-in flow) | cookie |
| smuai_consent | App | Stores the user consent choices and consent registry version. | necessary | 365 days | cookie |
| theme | next-themes | Persists the user-selected light, dark, or system theme. Stored locally only, set by an explicit user action, and required for the interface to render consistently. | necessary | Until browser storage is cleared | localStorage |
| sidebar | App | Persists whether the shared application sidebar is open. | preferences | Until browser storage is cleared | localStorage |
| newChatId | App | Remembers which newly created chat should stay highlighted while the chat UI catches up. | preferences | Until browser storage is cleared | localStorage |
| smuai:show-feedback-buttons | App | Persists whether tester feedback buttons are shown across the interface. | preferences | Until browser storage is cleared | localStorage |
| smuai:demo-mode | App | Persists whether Sandbox/Demo Mode is active, hiding brand chrome and select module nav entries. | preferences | Until browser storage is cleared | localStorage |
| __stripe_mid / __stripe_sid | Stripe.js | Payment fraud-prevention cookies used only in payment flows the user starts. | necessary | Up to 1 year / 30 minutes per Stripe defaults | cookie |
| Revolut Checkout (embed.js) | Revolut | Embedded payment widget loaded only on checkout pages to process payments the user starts; Revolut may set its own fraud-prevention cookies while it runs. | necessary | Loaded per checkout session | third_party_script |