Legal

Cookie Policy

This policy explains the cookies and similar browser technologies used by Chatduct, why they are used, how long they last, and how you can control optional analytics.

Last updated August 29, 2026

1. What this policy covers

“Cookies” are small values stored by a browser. This policy also covers similar device storage such as localStorage and access to information from a browser or device. These technologies may be first-party, meaning they are set through chatduct.com, even when a service provider helps us operate them.

2. Your choice

Strictly necessary storage works without consent because it is required to provide a service you request, such as signing in, securing the session, remembering your interface settings, or retaining your consent choice. Optional analytics is off by default and loads only after you choose “Accept analytics.” Refusing analytics does not prevent access to Chatduct.

You can change or withdraw your choice at any time. Withdrawal is as easy as acceptance: open the settings below or use the “Cookie settings” control available throughout the site. A withdrawal stops future analytics events but does not make earlier consent-based processing unlawful.

3. Strictly necessary cookies

chatduct-cookie-consent
Purpose: records the current consent-policy version and whether optional analytics is permitted. Duration: 180 days. Access: first-party JavaScript-readable cookie.
chatduct-auth
Purpose: provides the website's server-side authentication gate after sign-in. Duration: up to 30 days. Access: first-party JavaScript-readable cookie.
chatduct-access-token
Purpose: authenticates requests to the Chatduct backend. Duration: up to 1 day, or until logout/deletion. Access: first-party JavaScript-readable cookie.
refresh_token
Purpose: lets the authentication service renew an expired access token. Duration: set by the authentication service or until logout/expiry. Access: intended to be an HttpOnly first-party cookie restricted to the backend proxy path, so frontend JavaScript cannot read it.
sidebar_state
Purpose: remembers whether the application sidebar is open. Duration: 7 days. Access: first-party JavaScript-readable cookie.

4. Strictly necessary browser storage

chatduct-user
Technology: localStorage. Purpose: keeps the signed-in account state available in the browser. Duration: until logout, replacement, or browser-data deletion.
chatduct-locale
Technology: localStorage. Purpose: remembers the chosen interface language. Duration: until changed or browser-data deletion.
chatduct-currency
Technology: localStorage. Purpose: remembers the chosen display currency. Duration: until changed or browser-data deletion.

5. Optional analytics

With consent, Chatduct loads Vercel Web Analytics to produce aggregated statistics about page use. Vercel states that Web Analytics does not use third-party cookies, does not retain IP addresses with events, and uses a request-derived hash that is discarded after 24 hours. It may process the event timestamp, redacted URL and route, referrer, approximate geolocation, device type, operating system, browser, and analytics script version.

Chatduct removes all URL query parameters and replaces every dashboard path with the generic /dashboard path before sending an analytics event. We do not send custom analytics events or use analytics for cross-site advertising. The legal basis is consent. If consent is absent or withdrawn, the Vercel Analytics component is not rendered and future page-view events are not sent.

6. Browser controls

Browser settings can block or delete cookies and localStorage. Blocking strictly necessary storage may sign you out, prevent token renewal, or reset interface preferences. Browser controls do not replace the Chatduct setting for optional analytics, because Vercel Web Analytics is designed without third-party cookies; use Chatduct's Cookie settings to control whether the analytics script loads.

7. Changes and contact

We will update this list when we add, remove, or materially change a cookie, storage key, analytics service, or purpose. If a new non-essential purpose is introduced, it will remain disabled until valid consent is collected. Questions can be sent to help@chatduct.com.

We use cookies. Necessary storage keeps you signed in; with permission, we also use privacy-focused analytics. Cookie Policy · Privacy Policy