Cookie Policy

Effective date: July 2, 2026

This Cookie Policy explains how Salf AI ("Salf", "we") uses cookies and similar browser storage on salf.ai and within the Salf application. It supplements our Privacy Policy.

1. What we use

Salf uses only cookies and browser localStorage that are strictly necessary to operate the Service. Specifically:

  • Authentication and session — an authentication cookie set by our identity provider so that you stay signed in across pages, and a session identifier used to power the Active Sessions screen and "sign out everywhere" control. Authentication cookies are issued with theSecure flag and a SameSite attribute to reduce the risk of cross-site request forgery.
  • Abuse prevention — Salf enforces rate limits server-side against your authenticated session and truncated IP address. We do not set a dedicated CSRF cookie; cross-site request protection is provided by theSameSite attribute on the authentication cookie together with the Content Security Policy served by the application.
  • In-app preferences — local storage entries that remember UI preferences such as the last campaign you were viewing or a collapsed sidebar state.
  • Third-party payment flow — when you open the Stripe-hosted checkout or billing portal, Stripe sets its own cookies on Stripe's domains as required to process payments securely. Those cookies are governed by Stripe's own privacy and cookie notice.

2. What we do not use

  • We do not set advertising or cross-site tracking cookies.
  • We do not currently run third-party web analytics (Google Analytics, Segment, Mixpanel, etc.).
  • We do not use cookies to build advertising or behavioural profiles.
  • We do not sell information collected through cookies.

3. Consent

Because Salf uses only cookies and browser storage that are strictly necessary to deliver the Service you have requested, we do not currently display a cookie consent banner. If we introduce optional analytics or advertising cookies in the future, we will update this policy and, where required by law, obtain your consent first.

4. Managing cookies

You can clear cookies and local storage at any time from your browser settings. Signing out clears your active session token. Deleting the authentication cookie or local storage entries will sign you out of Salf and may reset some in-app preferences.

5. Changes

We may update this Cookie Policy as the Service evolves. Material changes take effect on the date shown at the top of this page.

6. Contact

Questions about cookies: privacy@salf.ai.