Skip to content

Legal

Cookie Policy

Last updated 20 September 2026

This is a short page, because there is not much to say. Humainbox sets three cookies that are strictly necessary — two for the application to work and one to remember the choice below. We also count visits to this website with Google Analytics, but only if you accept. If you decline, the script is never loaded and nothing is sent to Google at all. There is no advertising and no cross-site tracking either way.

A cookie is a small piece of text that a website asks your browser to store and send back on your next request. It is how a site can tell that two requests came from the same browser. That is all either of ours is used for.

2. The cookies we set

session cookie

Purpose: keeps you signed in. It holds an opaque identifier that links your browser to your signed-in session on the server. Without it, every page you opened would treat you as a stranger.

Set by: Humainbox (first party). Category: strictly necessary. Expires: when the session ends or the session lifetime elapses; it is removed when you sign out.

The cookie’s name is derived from the application name, so in this deployment it appears as something like humainbox-session. It contains no personal details — not your name, not your email address — only a reference the server resolves.

XSRF-TOKEN

Purpose: lets forms be submitted safely. It carries a token that the page returns with each form submission so the server can confirm the request came from our own page, and not from another site acting in your name. This is standard cross-site request forgery protection.

Set by: Humainbox (first party). Category: strictly necessary. Expires: with the session.

humainbox_cookie_choice

Purpose: remembers whether you accepted or declined analytics. It holds one word — granted or denied — and nothing else. Remembering a refusal is the only way to honour it, which is why this one is set whichever way you answer.

Set by: Humainbox (first party). Category: strictly necessary. Expires: six months, and then we ask again.

Set only if you accept

_ga

Purpose: lets Google Analytics tell one browser from another, so two visits from you are not counted as two people.

Set by: Google (third party). Category: analytics. Expires: two years.

_ga_0DEYQ68RYL

Purpose: holds the state of your current visit to this site specifically. The characters after the underscore are our property identifier.

Set by: Google (third party). Category: analytics. Expires: two years.

That is the complete list. Inspect your browser storage on this domain and you should find the first three; the last two appear only if you accepted, and never at all if you did not.

3. Why both are strictly necessary

“Strictly necessary” is a legal category, not a marketing adjective. It means the service you asked for cannot be delivered without the cookie. Signing in requires a session; submitting a form securely requires a token. Neither is set for our convenience, neither is used for advertising, profiling or measurement, and neither is shared with anyone.

Because they are strictly necessary and first party, they do not require consent under the rules that govern cookies. We still list them here so you can see them.

4. What we do not set

  • No third-party advertising cookies.
  • No cross-site tracking cookies, and no advertising pixels or tags.
  • No analytics cookies unless you accept them. Decline and the script is never loaded.
  • No social media embeds or share widgets that would set cookies of their own.
  • No third-party advertising, analytics or social scripts. Web fonts are served by Bunny Fonts, which sets no cookies and logs no personal data; nothing else on the page is loaded from another domain.

We are not selling this as a virtue; it is simply what the application does today, and if it changes this page changes with it.

5. Analytics, and your choice

An earlier version of this page said that if analytics were introduced we would update it before or at the time they went live, name what is set, and ask where asking is required. This section is us keeping that.

We use Google Analytics 4 to count visits to this website — which pages are read, where people arrive from, what they open next. It runs on the public website only. It is never loaded inside the application, because the pages you see when signed in carry message identifiers and your workspace name, and those are not ours to hand to anybody.

Nothing loads until you answer.

  • If you accept — the Google script loads and sets the two cookies named above. Google receives your IP address, your browser's user agent, the page you are on and the page you came from.
  • If you decline — the script is never loaded. No request is made to Google, no cookie is set, and nothing about your visit is sent anywhere. Not a reduced form of tracking: none of it.

Your answer is remembered for six months and then we ask again, because consent is not permanent. You can change it whenever you like with Cookie settings at the bottom of any page. If your browser sends a Global Privacy Control signal we treat that as a decline and do not ask at all.

6. Controlling cookies in your browser

Every major browser lets you see the cookies a site has set, delete them, and block them — either everywhere or for one site. The setting is usually under privacy or site settings:

  • Chrome — Settings, then Privacy and security, then Third-party cookies and Site settings.
  • Safari — Settings, then Privacy; per-site data is under Manage Website Data.
  • Firefox — Settings, then Privacy & Security, then Cookies and Site Data.
  • Edge — Settings, then Cookies and site permissions.

Most browsers also offer a private or incognito window, which discards cookies when you close it. That works fine with Humainbox; you will simply be signed out at the end of the session.

7. What happens if you block them

Blocking these two cookies prevents you from signing in. There is no workaround, and no degraded mode that still works: without the session cookie the server cannot tell that you have authenticated, and without the token cookie the sign-in form itself will be rejected as unsafe.

Public marketing pages like this one will still read normally.

8. Your website’s visitors

Worth being clear about, because it is easy to assume otherwise: Humainbox sets nothing in the browsers of the people who fill in your contact form. They never load a page of ours. Their submission reaches us by email, after it has left their browser. Any cookies on your own site are yours, and belong in your own cookie notice.

What we do with the contents of their submission is set out in the Privacy Policy.

9. Changes to this policy

If the set of cookies changes, this page and the date at the top change with it.

10. Contact

Questions about cookies, or something you found in your browser that is not listed above, can go through the contact page. We would genuinely like to know about the second one.

Related documents

We would like to count visits with Google Analytics, which sets two cookies. Decline and nothing is loaded and nothing is sent. What these are.