Legal
Cookie Information
Last updated August 2026
Essential authentication
chAIn uses an HTTP-only, same-site session cookie to keep a signed-in user authenticated. Staff administration uses a separate cookie and a separate identity boundary. These cookies are necessary to deliver the service and cannot be used by browser scripts to read the underlying bearer value.
Security and preferences
Short-lived browser state may preserve security-flow context or interface preferences. It is not used to bypass organization permissions, and the server remains authoritative for authentication, authorization, MFA, billing, and policy decisions.
Analytics and advertising
The current service does not set non-essential advertising cookies. Product analytics is not enabled merely because a configuration key exists. If non-essential analytics or advertising cookies are introduced, chAIn must present any consent controls required in the user's jurisdiction before setting them and update this notice.
Managing cookies
Browser controls can remove or block cookies, but blocking the essential session cookie prevents sign-in. Signing out revokes the server-side session; deleting the browser cookie alone does not grant or preserve access.