Skip to content

Cookie policy

Only the storage the product needs.

This page describes the current cookie implementation in VedoBox Web and identifies the review needed before any optional analytics or advertising technology is added.

Last updated: Draft — August 2026

1. Necessary session cookies

Authenticated access uses a server-managed, HttpOnly session cookie. Login also uses a short-lived state cookie during the identity-provider flow. These cookies support security and access continuity; they are not used for advertising.

2. No optional tracking in the current site

The current repository does not configure third-party analytics, advertising pixels, behavioral tracking, or non-essential cookie consent tooling. This statement must be revisited before any new vendor, script, embedded media, or analytics endpoint is introduced.

3. Browser storage boundaries

Service API keys, identity tokens, provider credentials, object keys, signed URLs, media, transcript text, and provider responses must not be placed in browser storage. Short-lived asset capabilities remain scoped to the transfer that needs them.

4. Changes requiring review

Adding optional cookies or similar technologies requires a documented purpose, vendor, data flow, retention period, regional consent behavior, opt-out path, and update to the final privacy and cookie policies.