Legal & terms
Cookie Policy
Summary
Evigate uses only strictly necessary cookies: the ones required to keep you logged in and to protect against cross-site request forgery (CSRF). We set no advertising cookies and no third-party analytics cookies. Because all of our cookies are essential to operate the service you asked for, no consent banner is required for them under the DPDP Act or GDPR/ePrivacy.
1. What cookies are
Cookies are small text files a website stores in your browser. They can be "session" (deleted when you close the browser) or "persistent" (kept until they expire or you remove them), and "first-party" (set by us) or "third-party" (set by another domain).
2. Cookies we use
All of Evigate's cookies are first-party and strictly necessary:
| Cookie | Purpose | Type | Lifetime |
|---|---|---|---|
session | Holds your authenticated login session. Set HttpOnly (not readable by page scripts), Secure (HTTPS only), SameSite=Lax. | First-party, necessary | Up to 7 days (session TTL) |
csrf_token | Anti-CSRF double-submit token; echoed in the X-CSRF-Token header on state-changing requests to prove the request came from you. | First-party, necessary | Tied to your session |
g_oauth_state, g_oauth_nonce | Set only during a "Sign in with Google" attempt (when that option is enabled) to protect the OAuth round trip against forgery and replay. HttpOnly, SameSite=Lax, scoped to the sign-in path. | First-party, necessary | A few minutes; cleared when sign-in completes |
Without these cookies you could not log in or safely perform actions, so they are exempt from consent requirements.
3. What we do not use
- No advertising or marketing cookies.
- No third-party analytics cookies (e.g. Google Analytics).
- No cross-site tracking, fingerprinting, or "sharing" of identifiers for
behavioral advertising.
If we ever introduce non-essential cookies, we will update this policy and, where required, present a consent mechanism before setting them.
4. Managing cookies
You can delete or block cookies in your browser settings. Blocking the cookies above will prevent you from logging in or using the authenticated parts of Evigate. API clients that authenticate with an Authorization: Bearer token do not rely on cookies at all.
5. Changes
We will update this policy if our cookie use changes, with a new "last updated" date and a note in the changelog.
6. Contact
Questions about cookies: privacy@logethos.com. See also the Privacy Policy.
*Effective date: July 31, 2026 · Last updated: 2026-06-28 · Version 1.0*