Cookie Policy
Version: v1.0 β 2026-07-23 Effective date: 2026-07-23
This Cookie Policy explains how Vestibo
("Vestibo") uses cookies and similar technologies on the
website at https://vestibo.com (the
"Website") and the dashboard at https://app.vestibo.com
(the "Dashboard"). It supplements the Privacy Policy.
This Cookie Policy is written to satisfy our obligations under the EU ePrivacy Directive (Directive 2002/58/EC) as implemented in EU Member States, the UK Privacy and Electronic Communications Regulations 2003, and the consent-related provisions of the GDPR. Today we set strictly-necessary cookies plus a small number of consent-exempt preference cookies and browser-storage items (such as your language and theme choices and onboarding progress); we do not set analytics or advertising cookies. Because none of these require consent under the ePrivacy rules, we do not currently display a cookie-consent banner. If we later introduce non-essential cookies, we will add a consent mechanism and update this policy first.
1. What cookies are
Cookies are small text files that a website places on your device. "Similar technologies" include local storage, session storage, pixels (1Γ1 images), and SDKs. Throughout this policy we use "cookies" to refer to all of these.
2. Cookies we use
2.1 Strictly necessary (always on)
These cookies are essential for the Service to work and are set without consent on the basis of legitimate interests.
| Name | Purpose | Storage | Duration |
|---|---|---|---|
agentic_token | httpOnly session cookie that authenticates your signed-in dashboard session; JavaScript cannot read it, and our middleware uses it to protect signed-in routes. | Cookie (httpOnly, Secure in production, SameSite=Lax) | Up to 30 days. |
agentic_auth_user | Your non-sensitive profile (name, email, role) cached so the signed-in dashboard paints instantly. | localStorage | Until logout. |
During sign-up and Google sign-in we also set short-lived,
path-scoped httpOnly security cookies β vestibo_signup (sign-up
verification / anti-hijack binding, ~30 minutes) and, on the Google
flow, g_oauth_state and g_oauth_pkce (OAuth CSRF/PKCE protection,
~10 minutes). These are strictly necessary, carry no tracking value,
and expire within minutes.
2.2 Analytics
We do not set analytics cookies in your browser. We measure aggregate product usage β for example, how far accounts get through the sign-up flow β server-side, from your authenticated interactions with the Service, not through a browser tracking cookie or third-party analytics SDK. Because this measurement does not rely on cookies or similar device storage, it does not require a consent prompt.
2.3 Functional (preferences)
| Name | Purpose | Storage | Duration |
|---|---|---|---|
agentic-theme | Remembers your light/dark theme preference. | localStorage | Persistent (until cleared). |
agentic-onboarding | Remembers your progress through and dismissal of the onboarding checklist. | localStorage | Persistent (until cleared). |
agentic_locale | Remembers the language you chose (set when you choose a language from the switcher). | Cookie (SameSite=Lax) | 1 year. |
We also use other first-party browser storage β for example, a trial-notice dismissal and the embeddable widget's session id (both cleared when the browser tab closes). These carry no tracking value and are not shared with any third party.
2.4 What we do not use
We do not use:
- third-party advertising or remarketing cookies (Google Ads, Meta Pixel, etc.);
- cross-context behavioural advertising trackers;
- fingerprinting techniques;
- pixels from social networks on the public marketing surfaces.
3. Sub-processor cookies
No third-party sub-processor sets cookies through our website or dashboard today. The embeddable widget and its installer are served from our own infrastructure under the same cookie policy as the dashboard.
4. Managing your choices
- Nothing to opt out of today. Because we set only strictly-necessary cookies and preference storage (no analytics or advertising cookies), there are no optional cookies to toggle. If we add non-essential cookies in future, we will provide a consent banner and preference controls here.
- Browser controls. You can block or delete cookies via your browser settings. Blocking strictly necessary cookies will break parts of the Service (notably login).
- Do Not Track / Global Privacy Control. We do not respond to the
DNTheader because there is no industry standard. Because we do not sell or share personal information for behavioural advertising, a Global Privacy Control signal has no sale or sharing to opt out of; we would honour it as a CCPA opt-out to the extent any such activity ever applied.
5. Changes
We may update this Cookie Policy when we add, remove, or change cookies. We always publish the current version here with the Effective date at the top, and for material changes we will give notice β including a consent mechanism if we introduce any non-essential cookies β before the change takes effect.
6. Contact
privacy@vestibo.com for any question about this Cookie Policy.
Changelog
- v1.0 (2026-07-23) β first published version; rebranded to Vestibo and reconciled to the current product.
- v0.1 (2026-05-16) β initial internal draft.