Verifex uses only strictly necessary cookies. These are first-party cookies required to sign you in securely and to protect authentication requests. They are not used for tracking or advertising.
Cookies we set
| Cookie | Purpose | Type | Duration |
|---|---|---|---|
verifex-csrf | Lets the app validate the x-csrf-token header on protected mutations. | First-party | 24 hours (Secure, SameSite=Lax, readable by the app for the double-submit CSRF check) |
__Secure-next-auth.session-token | Maintains your authenticated session when signed in to the dashboard. | First-party | Session / auth (httpOnly, secure) |
__Secure-next-auth.callback-url | Stores the URL to return to after sign-in. | First-party | Short-lived (secure) |
__Host-next-auth.csrf-token | Cross-site request forgery (CSRF) protection for authentication. | First-party | Session / short-lived (secure) |
What we do not use
The current public application build does not include Google Analytics, GA4, Firebase Analytics, advertising, or third-party tracking cookies, and it does not set an _gacookie. Verifex does not currently operate a consent-management platform. This policy will be updated before any non-essential cookie or tracking technology is introduced.
We may use a first-party, cookieless product-event signal with an allowlisted and scrubbed event vocabulary to understand aggregate product usage. It does not rely on cookies.
More information
For how we handle personal data more generally, see our Privacy Policy.