Cookie Policy
Last updated: 2026-05-10
We use the minimum cookies needed to keep you signed in and protect you from cross-site request forgery. We do not run advertising or cross-site tracking cookies, and we do not embed third-party analytics that set cookies on this site.
| Name | Type | Purpose | Required |
|---|---|---|---|
| coagentic_session | Cookie | Holds the signed JWT for your authenticated session. Required to use the dashboard. HttpOnly + Secure in production. Expires after 30 days. | Strictly necessary |
| coagentic_oauth_state | Cookie | Short-lived (10 minutes) CSRF token used during Google / GitHub sign-in. Removed automatically after the OAuth callback completes. | Strictly necessary |
| coagentic_ref | Cookie | Records the referral code from a /r/<code> link so we can credit the referrer if you sign up later. Set only if you arrive via a referral link. HttpOnly. Expires after 30 days. | Optional |
| coagentic_impersonation | Cookie | Set only when an authorised support engineer impersonates your workspace to investigate a ticket — every privileged action taken under it is recorded in the admin audit log. HttpOnly. Expires after 1 hour. | Strictly necessary |
| coagentic.* (localStorage) | localStorage | UI preferences — onboarding wizard dismissed, sidebar collapsed state, agent panel open/closed and last-used mode, dismissed announcement banners, cookie-banner acknowledged. Stored only in your browser, never transmitted to us. | Optional |
Third-party cookies on hosted sites
If you connect Polar, Google Analytics, or another integration to a project, that provider's cookies may be set on your project's published site (not on coagentic.work). You are responsible for disclosing those cookies to your own visitors. Coagentic itself never sets third-party cookies on your behalf.
Disabling cookies
You can disable cookies in your browser, but the dashboard will not be able to keep you signed in without coagentic_session. For full data control, see our Privacy Policy.