Legal document

Cookie Policy

Effective
April 1, 2026
Last updated
August 25, 2026
On this page · 3 sections

Verifex uses only strictly necessary cookies. These are first-party cookies required to sign you in securely and to protect authentication requests. They are not used for tracking or advertising.

Cookies we set

CookiePurposeTypeDuration
verifex-csrfLets the app validate the x-csrf-token header on protected mutations.First-party24 hours (Secure, SameSite=Lax, readable by the app for the double-submit CSRF check)
__Secure-next-auth.session-tokenMaintains your authenticated session when signed in to the dashboard.First-partySession / auth (httpOnly, secure)
__Secure-next-auth.callback-urlStores the URL to return to after sign-in.First-partyShort-lived (secure)
__Host-next-auth.csrf-tokenCross-site request forgery (CSRF) protection for authentication.First-partySession / short-lived (secure)

What we do not use

The current public application build does not include Google Analytics, GA4, Firebase Analytics, advertising, or third-party tracking cookies, and it does not set an _gacookie. Verifex does not currently operate a consent-management platform. This policy will be updated before any non-essential cookie or tracking technology is introduced.

We may use a first-party, cookieless product-event signal with an allowlisted and scrubbed event vocabulary to understand aggregate product usage. It does not rely on cookies.

More information

For how we handle personal data more generally, see our Privacy Policy.