A complete, current list of what Armalo sets, why, and how to manage it. Last updated July 22, 2026.
This Cookie Policy covers cookies, local storage, IndexedDB entries, and comparable client-side storage set by app.armalo.ai or its subprocessors when you visit, register for, or use Armalo. It supplements the Privacy Policy §12 (Cookies and tracking). This table is the single canonical inventory; the Privacy Policy §13 links here instead of keeping a second copy. See the Privacy Policy for the legal basis, retention, and rights.
Armalo uses three categories: necessary (set without consent because the product cannot operate without them), preference (remember display choices such as light or dark mode), and analytics (aggregated usage metrics behind the consent gate). Armalo does not use advertising cookies or cross-context behavioral targeting on app.armalo.ai.
Armalo gates optional categories behind an explicit consent decision recorded as a single cookie (`armalo_consent`). The default for first-time visitors is necessary-only. Until you choose, no preference, analytics, or non-essential cookie is set, and no usage data is sent. You can withdraw or change your selection at any time from the in-product consent banner.
When your browser sends the Sec-GPC: 1 header, Armalo treats it as a deny decision for optional categories. Armalo honors legally recognized browser-level opt-out signals where required.
Session cookies expire when you close the browser or sign out. Necessary persistent cookies live for the period stated in the table below. Preference cookies live up to 12 months. Optional analytics cookies live up to 13 months in pseudonymous form and are then aggregated or deleted.
Browser controls can block or delete cookies, but blocking necessary cookies will break core features such as authentication, room access, and consent persistence. Use the in-product consent banner to manage optional categories; use your browser controls to clear local storage.
Material changes receive at least 30 days' notice through the in-product banner or email. The current table below reflects cookies Armalo sets today. We will not introduce advertising cookies without updating this policy and the consent banner.
Privacy questions: privacy@armalo.ai. Do not include passwords, OAuth codes, or API keys.
The set below is the canonical reference. Cookies marked Analytics (consent) are only set when the consent gate is granted.
| Name | Type | Purpose | Duration | Provider |
|---|---|---|---|---|
| armalo_consent | Necessary | Stores your cookie consent decision | 1 year | Armalo |
| armalo_consent_at | Necessary | Records when you gave or changed consent (audit log) | 1 year | Armalo |
| __Host-armalo_room (armalo_room in development) | Necessary | Keeps you signed in to your workspace | About 4 hours | Armalo |
| armalo_account (__Host-armalo_account) | Necessary | Keeps you signed in to your account | About 4 weeks | Armalo |
| armalo_oauth_state | Necessary | Protects the sign-in flow against forgery | 10 minutes | Armalo |
| armalo_oauth, armalo_oauth_pkce | Necessary | Carries the sign-in handshake | Minutes; cleared when sign-in completes | Armalo |
| armalo_oauth_csrf | Necessary | Protects the sign-in callback against forgery | Session | Armalo |
| __Host-armalo_session_issuer | Necessary | Session-issuer token for your session | About 8 hours | Armalo |
| __Host-armalo_guest | Necessary | Anonymous guest workspace key | 1 year | Armalo |
| armalo_default_project | Preference | Remembers the workspace you opened last | Until cleared | Armalo |
| armalo.theme | Preference | Remembers your light/dark choice (local storage) | 1 year | Armalo |
| ab_visitor_id | Analytics (consent) | Anonymous visitor analytics — set only after you consent | 1 year | Armalo |
| _cfuvid, __cf_bm, cf_clearance | Necessary | Cloudflare bot and abuse protection | Session / 30 minutes / 30 days | Cloudflare |
| _ga, _ga_<container> | Analytics (consent) | Anonymous usage analytics — set only after you consent | Up to 13 months | Google Analytics |
| ph_*, ajs_* | Analytics (consent) | Anonymous usage analytics — set only after you consent | Up to 13 months / session | PostHog |
Use the in-product consent banner to change your selection, or contact privacy@armalo.ai for help.