Foxy Audit
← Back to home
This policy explains the cookies and similar local-storage Foxy Audit uses, why, and how you control them. We use no advertising or third-party tracking cookies — an auditing product has no business embedding trackers. The one third-party cookie on this site is Google's own, set only if you choose "Sign in with Google" (Section 3) — it is functional, not advertising or tracking, and we do not set it, Google does.
Cookies are small text files a site stores in your browser to remember things between requests — for example, that you're securely logged in, or that you dismissed a banner. "Local storage" and "session storage" work similarly but are read only by the site's own code. We call all of these "cookies" below.
Required for the site to work securely: without them you couldn't log in, stay logged in, or be protected against cross-site request forgery. These can't be switched off.
Help us see which pages are used and whether anything is slow or broken. Ours are first-party and cookieless: we count page views on our own servers and, only with your permission, keep an anonymous visitor id locally. Nothing goes to a third party.
Remember interface state so the site doesn't repeat itself — for example, that you closed the intro card on our home page. These live in your browser's local storage and never reach our servers.
Loaded only if you click "Sign in with Google": Google's Identity Services script sets its own cookie in your browser to support that sign-in flow. This is not under our control and is governed by Google's own privacy policy, not this one. If you sign in with email and password instead, this script and cookie are never loaded.
| Name | Category | Purpose | Expiry | Flags |
|---|---|---|---|---|
session | Necessary | Keeps you logged into your dashboard | 30 days | HttpOnly · Secure · SameSite=Lax |
foxy_staff_session | Necessary | Keeps staff logged into the admin console | 2 hours | HttpOnly · Secure · SameSite=Strict |
foxy_csrf | Necessary | Anti-CSRF double-submit token | 180 days | Secure · SameSite=Lax |
foxy_consent | Necessary | Remembers your cookie choices | 12 months | Secure · SameSite=Lax |
foxy_vid (local storage) | Analytics | Anonymous first-party visitor id | Until cleared | Set only with consent |
foxy_sid (session storage) | Analytics | Anonymous session id | Ends with the tab | Set only with consent |
foxy_onboard_dismissed (local storage) | Functional | Remembers that you closed the intro card, so it is not shown again | Until cleared | First-party, never sent to us |
foxy_welcome (session storage) | Necessary | Carries your new API key from sign-up to the welcome page, which shows it once | Deleted as soon as that page reads it | First-party, never sent to us |
g_state (third-party) | Third-party | Supports Google's "Sign in with Google" button | Set by Google, per their policy | Only loaded if you use Google sign-in |
When analytics is enabled, each page view sends a small first-party request to our own backend with the page path and, if you consented, an anonymous visitor/session id. Your IP address and browser user-agent are one-way hashed on our server and never stored raw. There is no third-party analytics provider.
On your first visit you choose. You can change your mind anytime via the "Cookie preferences" link in our footer, which reopens the consent panel. You can also block or delete cookies in your browser, though strictly-necessary cookies are required for login.
EU / EEA / UK (GDPR): analytics is off until you opt in, and rejecting is as easy as accepting.
California (CCPA/CPRA): we don't sell or share personal information; you can opt out of analytics anytime in the preferences panel.
We may update this policy as the product changes; the version and date above will move. Questions? Email privacy@foxyaudit.tech or call +92 3398123944.
This document describes our current practices in good faith and is not legal advice; have it reviewed by counsel before relying on it.