All legal documents

Hivsy legal

Cookie Policy

Hivsy uses essential cookies and limited browser storage to authenticate users, protect sign-in flows, remember a requested session, preserve local inbox drafts, and remember inbox display preferences.

Effective

Hivsy does not currently use advertising cookies or third-party analytics cookies in the application, so there is no non-essential cookie category to opt into.

1. Cookies used by Hivsy

NamePurposeTypical duration
hsl_accessAuthenticates requests to the Hivsy application.Short-lived; normally about 15 minutes.
hsl_refreshRenews an authenticated session. It is persistent only when “Remember me” is selected.Session-only or up to the configured remember-me period.
hivsy_oauth_stateProtects Google and GitHub sign-in against request forgery and binds the authorization response to the browser.Up to 10 minutes.
hivsy_oauth_totpTemporarily completes multi-factor authentication after social sign-in.Short-lived and cleared after use.

Authentication cookies are set with security protections such as HttpOnly, Secure in production, and SameSite controls. Customer-branded inbox hostnames use host-specific cookies so one customer hostname does not receive another hostname’s session.

2. Local browser storage

The inbound inbox may store an unsent reply or forward draft and your most recently selected receiving-domain filter in your browser’s local storage. Draft keys identify the message and draft type; the filter is scoped to the active workspace and stores only the selected domain name. This data remains on that browser until you send or clear the draft, choose all domains, clear site data, or the application removes it. Do not use a shared device for sensitive drafts.

3. Your choices

Most browsers let you inspect, block, or delete cookies and local storage. Blocking essential authentication storage will prevent sign-in or cause the application to stop working correctly. Leaving “Remember me” unchecked keeps the refresh cookie session-only. You can also sign out and clear site data from your browser.

4. Email pixels and tracked links

Tracking pixels and redirect links in emails are not browser cookies, but they can record an open or click when a Hivsy customer enables those features. The Privacy Policy explains that processing. Recipients can generally block remote images in their mail client and should use the sender’s privacy and unsubscribe controls.

5. Changes and contact

Hivsy will update this Policy if storage practices materially change and will request consent before using non-essential cookies where law requires it. Questions may be sent to privacy@hivsy.com.

Questions about this document? Email privacy@hivsy.com.