Cookie Guidelines
How We Deploy Local Storage & Session Identifiers
1. Why We Use Tracking and Session Identifiers
Candy AI utilizes browser cookies, local web storage objects (`localStorage`), and session keys to authenticate authorized accounts, deliver continuous conversational turns, and retain user UI preferences (such as audio volume or layout state).
2. Categories of Storage Technologies
| Identifier Type | Classification | Duration | Functionality |
|---|---|---|---|
| __candy_sess | Strictly Necessary | Session-bound | Secures the TLS token connection between your browser and LLM worker clusters. |
| auth_token | Functional Security | 30 Days | Maintains authenticated status across page reloads and tab navigations. |
| ui_mode_pref | Preference | 1 Year | Caches dark-mode rendering configurations and audio volume sliders. |
| cf_clearance | Security Mitigation | Session / Cloudflare | Prevents distributed denial-of-service (DDoS) requests from malicious bots. |
3. Third-Party Advertising Cookies
We do not deploy third-party advertising tracking pixels (such as Meta Pixel or Google Ads Remarketing) within active conversational workspaces. All cookies are first-party and scoped directly to en-candyai-us.com.
4. Cookie Control and Browser Management
You can configure your browser to reject cookies or flush local storage keys upon exit. However, doing so will require you to re-authenticate credentials upon every browser refresh, and may reset ephemeral conversation buffers.