Vestibo
All legal documents

Legal

Cookie policy

Cookie Policy

Version: v1.0 β€” 2026-07-23 Effective date: 2026-07-23

This Cookie Policy explains how Vestibo ("Vestibo") uses cookies and similar technologies on the website at https://vestibo.com (the "Website") and the dashboard at https://app.vestibo.com (the "Dashboard"). It supplements the Privacy Policy.

This Cookie Policy is written to satisfy our obligations under the EU ePrivacy Directive (Directive 2002/58/EC) as implemented in EU Member States, the UK Privacy and Electronic Communications Regulations 2003, and the consent-related provisions of the GDPR. Today we set strictly-necessary cookies plus a small number of consent-exempt preference cookies and browser-storage items (such as your language and theme choices and onboarding progress); we do not set analytics or advertising cookies. Because none of these require consent under the ePrivacy rules, we do not currently display a cookie-consent banner. If we later introduce non-essential cookies, we will add a consent mechanism and update this policy first.

1. What cookies are

Cookies are small text files that a website places on your device. "Similar technologies" include local storage, session storage, pixels (1Γ—1 images), and SDKs. Throughout this policy we use "cookies" to refer to all of these.

2. Cookies we use

2.1 Strictly necessary (always on)

These cookies are essential for the Service to work and are set without consent on the basis of legitimate interests.

NamePurposeStorageDuration
agentic_tokenhttpOnly session cookie that authenticates your signed-in dashboard session; JavaScript cannot read it, and our middleware uses it to protect signed-in routes.Cookie (httpOnly, Secure in production, SameSite=Lax)Up to 30 days.
agentic_auth_userYour non-sensitive profile (name, email, role) cached so the signed-in dashboard paints instantly.localStorageUntil logout.

During sign-up and Google sign-in we also set short-lived, path-scoped httpOnly security cookies β€” vestibo_signup (sign-up verification / anti-hijack binding, ~30 minutes) and, on the Google flow, g_oauth_state and g_oauth_pkce (OAuth CSRF/PKCE protection, ~10 minutes). These are strictly necessary, carry no tracking value, and expire within minutes.

2.2 Analytics

We do not set analytics cookies in your browser. We measure aggregate product usage β€” for example, how far accounts get through the sign-up flow β€” server-side, from your authenticated interactions with the Service, not through a browser tracking cookie or third-party analytics SDK. Because this measurement does not rely on cookies or similar device storage, it does not require a consent prompt.

2.3 Functional (preferences)

NamePurposeStorageDuration
agentic-themeRemembers your light/dark theme preference.localStoragePersistent (until cleared).
agentic-onboardingRemembers your progress through and dismissal of the onboarding checklist.localStoragePersistent (until cleared).
agentic_localeRemembers the language you chose (set when you choose a language from the switcher).Cookie (SameSite=Lax)1 year.

We also use other first-party browser storage β€” for example, a trial-notice dismissal and the embeddable widget's session id (both cleared when the browser tab closes). These carry no tracking value and are not shared with any third party.

2.4 What we do not use

We do not use:

  • third-party advertising or remarketing cookies (Google Ads, Meta Pixel, etc.);
  • cross-context behavioural advertising trackers;
  • fingerprinting techniques;
  • pixels from social networks on the public marketing surfaces.

3. Sub-processor cookies

No third-party sub-processor sets cookies through our website or dashboard today. The embeddable widget and its installer are served from our own infrastructure under the same cookie policy as the dashboard.

4. Managing your choices

  • Nothing to opt out of today. Because we set only strictly-necessary cookies and preference storage (no analytics or advertising cookies), there are no optional cookies to toggle. If we add non-essential cookies in future, we will provide a consent banner and preference controls here.
  • Browser controls. You can block or delete cookies via your browser settings. Blocking strictly necessary cookies will break parts of the Service (notably login).
  • Do Not Track / Global Privacy Control. We do not respond to the DNT header because there is no industry standard. Because we do not sell or share personal information for behavioural advertising, a Global Privacy Control signal has no sale or sharing to opt out of; we would honour it as a CCPA opt-out to the extent any such activity ever applied.

5. Changes

We may update this Cookie Policy when we add, remove, or change cookies. We always publish the current version here with the Effective date at the top, and for material changes we will give notice β€” including a consent mechanism if we introduce any non-essential cookies β€” before the change takes effect.

6. Contact

privacy@vestibo.com for any question about this Cookie Policy.


Changelog

  • v1.0 (2026-07-23) β€” first published version; rebranded to Vestibo and reconciled to the current product.
  • v0.1 (2026-05-16) β€” initial internal draft.

Questions? Email legal@vestibo.com.