Cookies

Not yet reviewedThis page was drafted by the engineering team, not by a lawyer. It describes what this website actually does, accurately and in plain language, but it has not been reviewed by a qualified adviser and it is not legal advice. Anything still marked below needs a real answer before this goes live. Remove this note once the page has been reviewed.

This site does not use cookies.

No analytics cookies, no advertising cookies, no tracking pixels, no consent banner to dismiss. This page explains what the site does use instead, because “no cookies” is only half an answer.

Draft last edited 3 August 2026Applies to this website only

The short version

This website sets no cookies of its own. There is no analytics tool, no tag manager, no advertising network and no social media pixel anywhere on it. Nothing follows you to another site, and nothing builds a profile of you.

That is also why you were not asked to accept anything when you arrived. A consent banner exists to obtain permission for non-essential storage. There is none here to consent to — and the only cookies anywhere in our setup are the strictly necessary sign-in cookies of the staff tool described below, which would not require consent even where they do apply.

Two things are still worth knowing about: the browser storage the assistant uses, and a font this site loads from another provider. Both are below.

What the assistant stores in your browser

If you open the chat window, it saves two entries in your browser's local storage. Local storage is not a cookie: it is never attached to a network request and it is never sent anywhere automatically. It stays on your device, readable only by this site.

aivora.chat.session
A random identifier for your conversation, so that reloading the page continues it instead of starting again. It contains nothing about you. It stays until you clear it.
aivora.chat.transcript
A local copy of the most recent messages — up to the last 40 — so the conversation is still on screen after a reload. It is ignored and replaced after twelve hours, at which point a return visit starts a fresh conversation.

To clear both: clear site data for this domain in your browser's privacy or site settings. That removes the identifier and the local copy immediately, and the next message begins a new conversation.

The chat window has a Start over button that does the same thing, but it appears at the end of a conversation — once the assistant has closed the session, or the message allowance has run out — rather than part-way through one.

Clearing these removes the copy on your device. The conversation already sent to us stays on our servers — see Privacy for what is held and how to ask us to delete it.

If your browser blocks site data, or you are in a private window, the chat still works. It just will not survive a reload.

The web font

This site loads its typeface from a third-party font service rather than serving it from our own servers. That request sets no cookie and stores nothing on your device, but like any request to another domain it does reveal your IP address and browser to that provider.

We mention it because it is the only third-party request an ordinary page view makes, and a page claiming “no tracking” should say so.

To fill before publishing — the font providerName the font provider here and link its policy, or self-host the font files so the request never leaves this domain. Self-hosting removes this section entirely and is the cleaner outcome.

Cookies in the staff application

The studio has a separate, password-protected application for handling enquiries. It does use cookies — strictly necessary ones, purely to keep a signed-in member of staff signed in.

aivora_refresh
Keeps a staff member's session alive. Unreadable by page scripts and scoped so it is only ever sent to the sign-in routes.
aivora_csrf
A random value the application echoes back to prove a request came from its own pages. It identifies nobody.

Neither is set by anything you can do on this site. They appear only after a successful staff login, they are removed on logout, and they are strictly necessary for that tool to work — the kind of cookie that does not require consent. They are listed here for completeness rather than because a visitor is likely to have one.

One caveat, stated because it is the kind of thing a cookie policy usually glosses over: cookies are scoped to a hostname. If the staff tool is ever served from this same hostname, its sign-in cookies would technically be present here too — still strictly necessary, still nothing to do with tracking, but present.

To fill before publishing — confirm before publishingCheck where the staff application is deployed. If it runs on a separate hostname and the cookie domain setting is left unset — the default, which produces host-only cookies — the caveat above does not apply in practice and this section can say so plainly. If it shares a hostname with this site, or a shared parent cookie domain is configured, say that here instead.

If this changes

If the studio ever adds analytics, embedded video, a chat widget from another vendor, or anything else that stores data on your device beyond what is described above, this page will be updated first and a proper consent choice will be added where one is required.

To fill before publishing — before adding any analyticsThe moment a measurement, advertising or embedded third-party tool is added to this site, this page stops being accurate and a consent mechanism becomes necessary. Update this page and add the consent gate in the same change, not afterwards.

Controlling site data yourself

Every mainstream browser lets you view and delete cookies and local storage per site, and block them entirely. The controls sit under privacy or site settings, and the exact wording differs by browser.

Blocking site data for this domain costs you nothing except the assistant's ability to remember a conversation across a reload. Nothing else on the site depends on it.

Contact

If something here does not match what you see in your browser, we would genuinely like to know — email info@aivoralabs.tech.