Cookie Policy

Effective April 30, 2026

This Cookie Policy explains how Aiden Risk uses cookies and similar browser storage on aidenrisk.com and our app at app.aidenrisk.com.

1. What are cookies?

Cookies are small text files stored in your browser. They allow a website to recognize your browser between page loads and across visits. Similar technologies include localStorage and sessionStorage — for the purposes of this policy, we treat these the same as cookies.

2. What we use today

Aiden Risk currently uses only essential cookies — the ones necessary to operate the platform. We do not use analytics cookies, advertising cookies, or third-party trackers.

Essential cookies

  • Session (auth-token): keeps you signed in. HTTP-only, secure in production, expires after seven days of inactivity.
  • OAuth state (oauth_state, oauth_mfa): short-lived tokens used to complete a Google or Microsoft sign-in flow safely. Cleared as soon as the flow completes.
  • CSRF protection: a per-session token set on first load to defend against cross-site request forgery.
  • Cookie consent record (localStorage keyaiden.cookieConsent): remembers your acknowledgement of this banner so we don't show it again.

3. What we do not use

We do not currently use any of the following. If we add them in the future, we will update this policy and obtain consent where required:

  • Analytics cookies (e.g., Google Analytics, Mixpanel).
  • Advertising or retargeting cookies.
  • Cross-site tracking pixels.
  • Social media embed cookies.

4. Managing cookies

Because the cookies we set are essential, disabling them will prevent you from signing in or using core features. You can clear cookies for aidenrisk.com at any time using your browser's privacy settings. Doing so will sign you out.

5. Updates

We'll revise this page when our use of cookies changes. The effective date at the top reflects the most recent update.

6. Contact

Questions about cookies? Email [email protected].