All policies

Legal & terms

Cookie Policy

Version 1.0Effective July 31, 2026Updated 2026-06-28

Summary

Evigate uses only strictly necessary cookies: the ones required to keep you logged in and to protect against cross-site request forgery (CSRF). We set no advertising cookies and no third-party analytics cookies. Because all of our cookies are essential to operate the service you asked for, no consent banner is required for them under the DPDP Act or GDPR/ePrivacy.


1. What cookies are

Cookies are small text files a website stores in your browser. They can be "session" (deleted when you close the browser) or "persistent" (kept until they expire or you remove them), and "first-party" (set by us) or "third-party" (set by another domain).

2. Cookies we use

All of Evigate's cookies are first-party and strictly necessary:

CookiePurposeTypeLifetime
sessionHolds your authenticated login session. Set HttpOnly (not readable by page scripts), Secure (HTTPS only), SameSite=Lax.First-party, necessaryUp to 7 days (session TTL)
csrf_tokenAnti-CSRF double-submit token; echoed in the X-CSRF-Token header on state-changing requests to prove the request came from you.First-party, necessaryTied to your session
g_oauth_state, g_oauth_nonceSet only during a "Sign in with Google" attempt (when that option is enabled) to protect the OAuth round trip against forgery and replay. HttpOnly, SameSite=Lax, scoped to the sign-in path.First-party, necessaryA few minutes; cleared when sign-in completes

Without these cookies you could not log in or safely perform actions, so they are exempt from consent requirements.

3. What we do not use

  • No advertising or marketing cookies.
  • No third-party analytics cookies (e.g. Google Analytics).
  • No cross-site tracking, fingerprinting, or "sharing" of identifiers for

    behavioral advertising.

If we ever introduce non-essential cookies, we will update this policy and, where required, present a consent mechanism before setting them.

4. Managing cookies

You can delete or block cookies in your browser settings. Blocking the cookies above will prevent you from logging in or using the authenticated parts of Evigate. API clients that authenticate with an Authorization: Bearer token do not rely on cookies at all.

5. Changes

We will update this policy if our cookie use changes, with a new "last updated" date and a note in the changelog.

6. Contact

Questions about cookies: privacy@logethos.com. See also the Privacy Policy.


*Effective date: July 31, 2026 · Last updated: 2026-06-28 · Version 1.0*