G

GUARDYX AI

AI Agent Control Plane

Legal

Cookie Policy

Effective:
May 11, 2026
Last updated:
May 11, 2026
Version:
1.0

1. What this policy covers

This Cookie Policy explains how Guardyx AI ("Guardyx AI," "we," "us") uses cookies and similar browser storage technologies — including localStorage, sessionStorage, and pixel tags — when you visit our marketing site or use our product. It complements, but does not replace, our Privacy Policy, which describes how we process personal data more broadly.

2. What cookies are

Cookies are small text files that a site stores in your browser. "Similar technologies" means anything else used for the same purpose — localStorage, sessionStorage, and pixel tags. Throughout this policy we use "cookies" as a shorthand for all of the above.

Some technologies described in this policy — such as localStorage and sessionStorage — are browser storage mechanisms rather than HTTP cookies, but we treat them under the same consent framework.

3. Categories we use

We group cookies into four categories. Only "Strictly necessary" is on by default.

  • Strictly necessary — required for the product to function: authentication, session, CSRF protection, and storage of your cookie preferences themselves. These cannot be disabled.
  • Functional — remembers your preferences (e.g. last selected organization, theme) so the product feels less stateless between visits. Off until you opt in.
  • Analytics — first-party product analytics that help us understand which flows work and which break. Off until you opt in. Analytics events are designed to minimize use of directly identifying resource identifiers — we aggregate by route template where practical.
  • Marketing — currently unused. We do not run advertising cookies or cross-site retargeting. If marketing or advertising technologies are introduced in the future, they will remain disabled until you explicitly opt in where required by applicable law.

4. Inventory of cookies in use

NameCategoryProviderPurposeRetention
__session, __client_uat (and similar)Strictly necessaryClerk (authentication provider)Maintains an authenticated session and verifies your identity on each request.Determined by Clerk authentication configuration; cleared on sign-out.
guardyx_consent_v1Strictly necessaryGuardyx AI (first-party, localStorage)Stores your cookie preferences so we do not ask again on every visit.Persists in browser storage until you clear it, change your preferences, or we bump the consent schema version.
guardyx_wizard_stateStrictly necessaryGuardyx AI (first-party, localStorage)Saves your in-progress answers in the setup wizard so a page refresh or session reload does not lose your work.Cleared when you complete or skip the wizard, or when you clear browser storage.
guardyx_wizard_doneStrictly necessaryGuardyx AI (first-party, localStorage)Records that onboarding is complete so the wizard overlay does not re-appear on every visit.Persists until you clear browser storage or sign out.
guardyx_pending_invite_urlStrictly necessaryGuardyx AI (first-party, localStorage)Holds the destination URL across a sign-in / SSO round-trip when you arrive via an invite link.Cleared on successful sign-in or invite acceptance.
guardyx_analytics_eventsAnalyticsGuardyx AI (first-party, localStorage, development only)Local-only ring buffer used during development to inspect analytics events in DevTools. Not present in production builds.Up to 100 most-recent events; cleared on demand.

We will update this table whenever we add or remove cookies, and bump the policy version so prior consent decisions are re-confirmed.

5. Third parties

As of the effective date of this policy, the only third-party service that may set cookies in our product is Clerk, our authentication provider. Clerk's cookies are strictly necessary for sign-in to work. We do not embed advertising networks, social-media widgets, or session-replay tools.

Guardyx AI does not sell personal information and does not use cookies for cross-context behavioral advertising. We will update this section and bump the policy version if that changes.

6. Global Privacy Control (GPC)

If your browser exposes navigator.globalPrivacyControl = true, we treat that as an opt-out of all non-essential categories on your first visit. You can still grant specific categories afterwards through the preferences panel — GPC is a signal, not a lock.

8. Server-side telemetry & operational logging

The Cookie Policy governs what happens in your browser. It does not govern server-side processing that is necessary to operate the Guardyx AI platform itself.

Disabling analytics cookies does not disable server-side operational logging, security monitoring, fraud prevention, audit trails, tenant isolation enforcement, or usage metering necessary to operate the Guardyx AI platform. Those processing activities are described in the Privacy Policy and are conducted under legitimate interest, contractual necessity, legal obligation, or comparable legal bases depending on the processing activity, applicable law, and jurisdiction.

9. Security & abuse prevention

Guardyx AI may use strictly necessary storage and server-side telemetry mechanisms to detect abuse, enforce platform security, prevent fraud, maintain tenant isolation, and preserve audit-log integrity. These mechanisms operate regardless of your cookie preferences because they are required for the safe operation of the service.

10. Your rights by region

  • European Economic Area & United Kingdom (GDPR / UK GDPR)

    Right to access, rectify, erase, restrict processing, object, data portability, and withdraw consent. To exercise any of these, contact privacy@guardyx.ai. You may also lodge a complaint with your local supervisory authority.

  • Switzerland (nFADP)

    Right to information, access, rectification, erasure, and to object to processing. Complaints may be filed with the Federal Data Protection and Information Commissioner (FDPIC).

  • California (CCPA / CPRA)

    Right to know, delete, correct, opt out of sale or sharing for cross-context behavioral advertising, and limit use of sensitive personal information. We do not sell or share personal information for cross-context behavioral advertising. We honor the Global Privacy Control browser signal.

  • Virginia, Colorado, Connecticut, Utah (VCDPA / CPA / CTDPA / UCPA)

    Right to access, correct, delete, port, opt out of targeted advertising, sale, and profiling. We honor the Global Privacy Control browser signal. We do not engage in targeted advertising.

  • Canada (PIPEDA)

    Right to access, correct, withdraw consent, and complain to the Office of the Privacy Commissioner of Canada.

  • Brazil (LGPD)

    Right to confirm processing, access, correct, anonymize, port, delete, and revoke consent. Complaints may be filed with the ANPD.

  • South Africa (POPIA)

    Right to access, correct, delete, object to processing, and lodge complaints with the Information Regulator.

  • Saudi Arabia (PDPL)

    Right to be informed, access, request correction, request destruction, and withdraw consent. Regulator: Saudi Data and Artificial Intelligence Authority (SDAIA).

  • Singapore (PDPA)

    Right to access, correct, and withdraw consent. Regulator: Personal Data Protection Commission (PDPC).

  • Australia (Privacy Act)

    Right to access and correct personal information held about you. Complaints may be filed with the Office of the Australian Information Commissioner (OAIC).

  • United Kingdom (Data Protection Act 2018)

    In addition to UK GDPR rights above, the DPA 2018 supplements rights around criminal-offence data, automated decision-making, and direct marketing.

This section summarizes certain regional privacy rights. Applicable laws and regulations govern in the event of conflict.

11. How to manage or withdraw consent

You can change your decision at any time from the Cookie preferences panel. The trigger appears in the left sidebar inside the signed-in app. Most browsers additionally let you block or delete cookies through their own settings; doing so may break sign-in or other strictly-necessary functions.

Changes to your preferences apply prospectively and do not affect processing that occurred before your updated choice was recorded.

Although Guardyx AI does not currently sell or share personal information for cross-context behavioral advertising, California residents and users in similar jurisdictions may still exercise applicable opt-out rights through the preferences panel.

12. Changes to this policy

We will revise this page whenever the categories, vendors, or retention periods change materially. Material changes are accompanied by a bump to the consent schema version, which invalidates prior consent decisions stored in your browser and prompts you to choose again on your next visit.

13. Contact

Privacy questions: privacy@guardyx.ai. For EEA/UK residents, this address also serves as the contact point under Articles 13–14 GDPR.