Kloy.ai
About Platform Intelligence Blog Contact Us
Navigation menu
About Platform Intelligence Blog Contact Us

Legal / Browser storage

Cookies Policy

The browser-storage inventory for the public Kloy.ai application and its Contact Us workflow.

Effective July 21, 2026 Cookie inventory / version 2.1
COOKIE03

On this page

  1. What cookies are
  2. Current inventory
  3. Why it is necessary
  4. Technologies not used
  5. Browser controls
  6. Privacy signals
  7. Changes and contact

Ordinary public pages do not start an application session. A session starts only when the Contact Us route is requested with GET or POST.

Current state

The Kloy.ai application sets one first-party, session-only cookie when you request the contact workflow. It does not currently set optional analytics, advertising, social-media, or personalization cookies.

01

What cookies and similar technologies are

A cookie is a small value a website asks a browser to store and return with later requests. A first-party cookie belongs to the site you are visiting. A session cookie normally expires when the browser session ends, while persistent storage has a scheduled expiry.

This inventory also covers comparable browser storage used by the public application. It should be reviewed together with the Privacy Notice.

02

Current application inventory

Cookie used by the current Kloy.ai application
NamePurposeCategoryDuration
kloy_sidA preview or mounted deployment may use a deployment-specific equivalent. Associates the browser with server-side anti-forgery state, expiry metadata, form continuity, and a one-time submission confirmation. First-party
Strictly necessary
Browser session. The server rejects an application session after 30 minutes of inactivity or 8 hours from creation.

The cookie contains a random identifier, not the contact fields. Contact data remains server-side. Network infrastructure may process ordinary request metadata independently of this browser cookie.

03

Why the cookie is strictly necessary

The cookie supports a contact feature you expressly request. It lets the application issue and validate a CSRF token, detect an expired session, preserve a safe form flow, and display confirmation after a valid submission. Without it, the application cannot reliably distinguish the protected form session and the submission will not complete.

SecureSent over HTTPS in production
HttpOnlyUnavailable to browser scripts
SameSite=LaxRestricts cross-site sending
Path-scopedLimited to the application mount

Many cookie laws provide an exception from opt-in consent for storage strictly necessary to provide a feature requested by the user. The application therefore does not display an optional-cookie banner for this single cookie, while still providing this notice.

04

Technologies the application does not currently use

As of the effective date, the public application does not intentionally set or load audience analytics, behavioral advertising, cross-site tracking, social-media embeds, marketing attribution, preference cookies, tracking pixels, browser fingerprinting, or third-party JavaScript. It does not intentionally use local storage.

If optional storage, analytics, or embedded services are introduced, Kloy.ai must update the inventory and deploy any notice, preference, withdrawal, and prior-consent controls required by applicable law before enabling them. Production edge or security configuration must also be checked against this inventory whenever providers change.

05

Your browser controls

Browsers generally allow you to inspect, block, or delete cookies and to clear them when the browser closes. Blocking this session cookie does not prevent reading ordinary public pages, but the Contact Us form will not complete because its anti-forgery state cannot be maintained.

Deleting the cookie removes the browser's association with the existing server session. Reload the Contact Us page to begin a new session and receive a new CSRF token.

A browser may restore a session cookie when it restores a previous browsing session. Regardless of the browser's display, the server rejects the associated application session after 30 minutes of inactivity or 8 hours from creation.

06

Do Not Track and opt-out preference signals

Browsers and extensions may send signals such as Do Not Track or Global Privacy Control. The current public application does not use optional tracking and does not sell or share personal information for cross-context behavioral advertising, so those signals do not change its use of the one strictly necessary session cookie.

If Kloy.ai later introduces processing for which applicable law requires recognition of an opt-out preference signal, that processing and its controls must be implemented and described before launch. This statement is limited to the public application and does not describe third-party websites reached through links.

07

Review, changes, and contact

Kloy.ai reviews this inventory when browser storage, embedded content, analytics, infrastructure, or the contact workflow changes. Provider and production-browser checks are required because a source-code inventory alone cannot prove the storage behavior of every deployed network layer. The effective date and version identify the latest published inventory.

Questions about cookies or browser storage may be sent to official@kloy.ai.

Kloy Lab

Kloy.ai develops proactive, defense-first zero‑day intelligence for the patch gap.

Public materials exclude payloads, reproduction steps, and weaponization details.

You can reach us at official@kloy.ai.

Terms of Use Terms and Conditions Cookies Policy Privacy Notice

© 2026 KLOYLAB Inc. All rights reserved.