AI.FO

AI.FO LEGAL

Cookie Policy

Last updated: August 22, 2026

This Cookie Policy explains how AI.FO uses cookies and similar local browser storage, why we use them, and how you can control them. It should be read together with our Privacy Policy.

1. What cookies and local storage are

Cookies are small text files a site can store in your browser. "Local storage" is a related browser mechanism that lets an application keep small amounts of data on your device. We use these terms together in this policy to describe the ways AI.FO keeps information in your browser so the Service can work.

2. How we use them

AI.FO uses cookies and local storage primarily to operate the Service. We do not use them for advertising, and we do not sell information collected through them.

CategoryPurpose
Strictly necessaryKeep you signed in, maintain your session, and protect the security of your account. The Service cannot function without these.

The specific cookie the Service sets and the browser storage keys it uses are itemized below. The list is checked automatically against the Service's source, so a key cannot be added to the Service without appearing here.

CookieSet byPurposeAttributesLifetime
connect.sidSign-in and registration responsesKeeps you signed in. The server holds the session; this cookie holds only its id.HttpOnly; Secure (production); SameSite=Lax7 days
Browser storage keyStorePurposeLifetime
aifo_public_diagnostic_sessionsessionStorageThe temporary token for a free-diagnostic upload made without an account, so the result page can read it back.Per tab; the server purges the session within 24 hours regardless
aifo.returnTosessionStorageThe in-app page to return to after sign-in.Per tab; cleared on use
aifo.checkout.pendingsessionStorageMarks a checkout started from this tab so the return page can confirm its outcome.Per tab; cleared when the outcome is known
aifo.decision.pendingOriginsessionStorageCarries the signal a decision is being recorded from into the decision ledger.Per tab; cleared on use
aifo.platform.create-client-draftsessionStoragePlatform-owner console: an unsent draft of the create-client form.Per tab; cleared on submit or when the tab closes
auth_tokenlocalStorageRead-only compatibility path from an earlier build: if present it is sent as a sign-in header. Nothing in the current Service writes it.Not written by the Service

Nothing above is sent to a third party or used for advertising or cross-site tracking.

3. Cookies set by our providers

Some functionality relies on the sub-processors described in our Privacy Policy (for example, payment processing and hosting). Those providers may set their own cookies when their functionality is used, subject to their own policies.

  • Stripe (checkout.stripe.com, billing.stripe.com): When you open Checkout or the Customer Portal, which are Stripe-hosted pages. Stripe's hosted pages set their own cookies on Stripe's domain under Stripe's Cookies Policy, which names __stripe_mid and __stripe_sid (essential and fraud-prevention cookies) and lists durations in Stripe's consent dashboard. The Service loads no Stripe script on its own pages.
  • Replit (hosting): On every page, as the host of the site and the API. No cookie set by the hosting layer is observed on the Service's responses; if Replit changes that, this row changes with it.
  • Google Fonts (fonts.googleapis.com, fonts.gstatic.com): On every page, to load the typefaces. Serves font files without setting cookies; the request carries your IP address to Google as described in the Privacy Policy.

4. Managing cookies

You can control and delete cookies through your browser settings, and clear local storage the same way. Because our strictly necessary cookies and storage are what keep you signed in and secure your session, blocking or deleting them will prevent you from logging in or using core parts of the Service.

5. Changes to this policy

We may update this Cookie Policy from time to time. When we do, we will revise the "Last updated" date above.

Contact us

Questions about this Cookie Policy can be sent to legal@getaifo.com.