Cookie and Browser Storage Policy
A source-based inventory of first-party browser storage and the currently known third-party cookie and storage boundaries.
- Version
- 1.0
- Effective date
- Last updated
- Operator status
- Requires legal confirmation
This page describes currently verified product and website behavior. The service operator’s legal identity, governing law, jurisdiction, and any binding liability allocation require confirmation by the operator and qualified counsel.
1. Scope
Current implementationThis policy explains the Cookie, localStorage, and sessionStorage behavior evidenced by the current SevenStars website source, plus deployment-dependent third-party boundaries that cannot be confirmed from source alone.
2. Storage Inventory
Current implementationThe table distinguishes verified first-party items from third-party or deployment-dependent items. “Unconfirmed” means the available technical record does not establish the exact lifetime or production behavior.
| Storage item | Type | Purpose | First/Third party | Duration | Required |
|---|---|---|---|---|---|
| authToken | localStorage | Keeps an authenticated account session available to the website. | First party | Until logout, browser-data removal, or another application removal event; the formal retention period is unconfirmed. | Required for signed-in pages |
| userInfo | localStorage | Caches the account information returned by the account service for the signed-in interface. | First party | Until logout, refresh, browser-data removal, or another application removal event; the formal retention period is unconfirmed. | Required for signed-in pages |
| sevenstars-language | localStorage | Remembers the selected interface language. | First party | Persistent until changed or browser data is cleared. | Functional preference |
| sevenstars-language-release | localStorage | Records the language-preference migration version. | First party | Persistent until replaced or browser data is cleared. | Functional preference |
| sevenstars-theme | localStorage | Remembers the light or dark theme. | First party | Persistent until changed or browser data is cleared. | Functional preference |
| sevenstars-consent-v1 | localStorage | Stores the necessary/analytics choice, consent-model version, and update time without a user identifier. | First party | Persistent until changed, withdrawn, the model version changes, or browser data is cleared. | Necessary consent record |
| sevenstars-attribution-first-v1 | localStorage | After analytics consent, stores only allowed UTM first-touch fields and a landing path. | First party | Up to 90 days, or until analytics consent is withdrawn or browser data is cleared. | Optional analytics |
| sevenstars-pending-language-navigation | sessionStorage | Carries a language choice across an eligible route transition. | First party | Consumed on navigation or removed when the browser session ends. | Functional preference |
| sevenstars-quote-duplicate-v1 | sessionStorage | Stores a request digest, an idempotency identifier, a timestamp, and a delivery state to reduce accidental duplicate quote submissions. It does not store the quote form text. | First party | Browser session; exact browser cleanup timing is outside the application’s control. | Required when a quote attempt is made |
| sevenstars-attribution-last-v1 | sessionStorage | After analytics consent, stores only allowed UTM last-touch fields and a session landing path. | First party | Up to 30 minutes in the current browser session, or until analytics consent is withdrawn. | Optional analytics |
| toplink_support_visitor_id | localStorage | Assigns a browser visitor identifier when the embedded support widget loads. | Third party | No explicit expiry was found; persists until browser data is cleared. | Support feature |
| toplink_support_conversation_<application> | localStorage | Remembers the support conversation associated with this website after a conversation is created. | Third party | No explicit expiry was found; the widget removes it when its conversation state is cleared, or it remains until browser data is cleared. | Created when support is used |
| toplink_support_widget_token_<application> | localStorage | Stores the support-widget token created after a support message. Treat this browser value as sensitive. | Third party | No explicit expiry was found; the widget removes it when its conversation state is cleared, or it remains until browser data is cleared. | Created when support is used |
| Cloudflare edge cookies | Cookie, if set | May support edge security or delivery controls on the production website. | Third party | Depends on the deployed Cloudflare configuration; the current technical record does not confirm the exact behavior. | Deployment dependent |
4. Third-Party Services
Current implementationThe embedded customer-support widget loads on website pages and creates a browser visitor identifier in localStorage. It creates conversation and widget-token entries after support messaging is used; no direct Cookie use was observed in the audited widget version. Cloudflare may set delivery or security Cookies depending on production configuration. Google Fonts receives network requests for font resources. Provider behavior can change and requires continued verification.
5. Browser Controls
Current implementationUsers can accept, reject, or later withdraw optional analytics through the privacy-choice controls. Withdrawal immediately stops analytics events and removes first- and last-touch attribution. Browser settings can also clear website data; clearing account-session storage may sign the user out.
6. Consent Boundary
Current implementationOptional analytics is off by default and is enabled only after an explicit choice. The consent record contains the choice, model version, and update time without a user identity. No production analytics provider is connected in this release. A future provider requires an updated third-party processing register and consent review. The embedded support widget remains a separately disclosed functional third-party boundary and is not controlled by the analytics preference.
7. Retention
Requires legal confirmationFirst-party preference storage persists until changed or cleared. Session storage generally ends with the browser session, but browser behavior can vary. Formal retention periods for account data and third-party storage remain unconfirmed and require operational and legal review.
8. Contact
Current implementationQuestions about Cookie or browser-storage use can be sent to the verified support address.
Send requests to support@sevenstarsai.com.