Legal
Cookie Policy
Effective March 23, 2026
1. What this policy covers
This Cookie Policy explains how Aktara (“we”, “our”, “us”) uses cookies and similar browser-based storage technologies on aktara.ai and any associated subdomains (collectively, “the Site”).
A cookie is a small text file that a website places on your device. We also use functionally equivalent technologies such as session storage. This policy covers all of them.
2. Legal basis for cookies
Under the EU ePrivacy Directive, UK PECR, and equivalent regulations, cookies that are strictly necessary for a service you have requested do not require your prior consent. All other cookies require opt-in consent before being set.
At present, Aktara uses only strictly necessary cookies. No advertising, tracking, or non-essential analytics cookies are set. If this changes, we will obtain your consent first and update this policy with at least 14 days' notice.
3. Cookies we set
The following cookies are set when you sign in to Aktara. They are all strictly necessary and cannot be disabled while you remain signed in.
| Name | Type | Duration | Purpose |
|---|---|---|---|
| authjs.session-token | Strictly necessary | Up to 30 days | Maintains your authenticated session. Contains a signed, encrypted token — no personal data is stored in plaintext. Deleted when you sign out or after 30 days of inactivity. |
| authjs.csrf-token | Strictly necessary | Browser session | A double-submit CSRF token that protects sign-in and sign-out form submissions from cross-site request forgery attacks. Expires when the browser tab or window is closed. |
| authjs.callback-url | Strictly necessary | Browser session | Stores the URL you were trying to reach before being redirected to sign in, so you can be returned there after authentication. Contains only a path string. |
If you access a preview deployment of the Site (not production), Vercel may additionally set a __vercel_live_token session cookie for deployment authentication. This is not present on the live site.
4. Third-party cookies
When you choose to sign in using Google, your browser is temporarily redirected to Google's domain to complete the OAuth flow. During this redirect, Google may set its own cookies under its domain. These are governed solely by Google's Privacy Policy — we have no control over them and they are not covered by this policy.
Phone sign-in uses Twilio to send an SMS verification code. Twilio does not set any cookies in your browser.
We do not embed third-party advertising networks, social media widgets, or pixel trackers on the Site.
5. Analytics and performance cookies
We do not currently use analytics or performance cookies. If we introduce them in future, we will use a privacy-first tool (such as Plausible Analytics) that does not track individuals across sites, does not share data with advertising networks, and complies with GDPR without requiring a consent banner where applicable.
Any future analytics cookies will be opt-in. You will be informed via an in-app notice before they are set and can withdraw consent at any time through your account settings.
6. How to manage or delete cookies
You can view, manage, and delete cookies at any time through your browser settings. Note that deleting the session cookie will sign you out of Aktara, and blocking it entirely will prevent sign-in from working.
- Chrome — Settings → Privacy and security → Cookies and other site data
- Safari — Settings → Privacy → Manage Website Data
- Firefox — Settings → Privacy & Security → Cookies and Site Data
- Edge — Settings → Cookies and site permissions → Manage and delete cookies and site data
You can also use Aktara in demo mode without signing in, in which case no session cookies are set at all.
7. Retention
The session cookie expires after 30 days of inactivity or immediately upon sign-out, whichever comes first. CSRF and callback cookies expire at the end of the browser session. We do not store cookie data server-side beyond what is necessary to maintain your session.
8. Changes to this policy
We will post any changes to this policy on this page and update the effective date. If we introduce non-essential cookies, we will notify you at least 14 days in advance via email or an in-app banner and obtain your consent before setting them.
9. Contact
Questions about our use of cookies? Email privacy@aktara.ai or use our contact form.