{"preferenceLocale": "en-US", "requestedLocale": "en-US", "contentLocale": "en-US", "fallbackReason": "", "source": "default"}
{"schemaVersion": "1.0.0", "pageId": "legal:cookies", "locale": "en-US", "contentLocale": "en-US", "status": "native", "fallbackReason": "", "canonicalPath": "/legal/cookies", "routePath": "/legal/cookies", "family": "legal_trust", "title": "Cookie Policy", "description": "", "editionDigest": "e1932fcbf8c3e7992209a98267b2b1b267215727a31d7247ae3f5594b5400d8f", "revision": "e1932fcbf8c3e7992209a98267b2b1b267215727a31d7247ae3f5594b5400d8f", "canonicalContentDigest": "8375052e525cc573ce043132988fce23d0bf29426bc76b33ca3bd8c9852d39b9", "anchors": ["cdn-analytics", "cookies-we-do-not-use", "cookies-we-use", "future-analytics-consent", "managing-cookies"], "serverOwned": true, "metadata": {"title": "Cookie Policy", "description": "", "canonicalPath": "/legal/cookies", "htmlLang": "en"}, "payload": {"page": "cookies", "content": {"title": "Cookie Policy", "kicker": "Legal", "lead": "XMemo uses cookies only for sign-in, security, OAuth handshakes, and one optional public language preference. Public pages also load a cookieless Cloudflare Web Analytics beacon, which stores nothing in your browser.", "last_reviewed": "August 2026", "source_note": "Aligned with the public locale cookie, session/CSRF cookie handling, OAuth state protection, and the Cloudflare edge configuration for public XMemo hostnames.", "commitments": ["Necessary cookies protect account sessions, CSRF boundaries, invite flows, and OAuth authorization redirects.", "The memory_os_locale cookie stores the public language preference only, such as en-US, zh-CN, ja-JP, ko-KR, or es-ES.", "No advertising, retargeting, or cross-site profiling cookies are set, and no analytics cookies are set.", "The Cloudflare Web Analytics beacon on public pages sets no cookie and writes nothing to browser storage.", "If a cookie-setting or otherwise non-essential tracking script is introduced later, XMemo will add consent controls before it loads."], "sections": [{"id": "cookies-we-use", "title": "Cookies we use today", "body": "Current cookies are limited to service operation, account security, and language preference. They are not used to sell data or track users across unrelated sites.", "items": ["Session cookies keep signed-in account, console, invite, and enterprise sessions active and are configured with route-appropriate HttpOnly, Secure, and SameSite protections.", "CSRF cookies let browser clients submit protected account and console requests without exposing bearer tokens in public pages.", "OAuth state and sign-in-flow cookies protect authorization redirects, device handoffs, invite sign-in, and account creation.", "memory_os_locale stores the selected public language so product, legal, and trust pages can render in English, Japanese, Chinese, Korean, or Spanish.", "The cookie notice acknowledgment is stored in browser localStorage and is not used for advertising or cross-site tracking."]}, {"id": "cdn-analytics", "title": "Cloudflare Web Analytics", "body": "Public XMemo pages load a Cloudflare Web Analytics beacon. Cloudflare enables it automatically for hostnames proxied through its network, and it measures page views and page-load performance.", "items": ["The beacon script is served from static.cloudflareinsights.com and reports to the /cdn-cgi/rum path on the XMemo domain.", "It reports the page URL, referrer, page-load and performance timings, and coarse browser, device, and country signals to Cloudflare.", "It sets no cookie and writes nothing to cookies, localStorage, sessionStorage, or IndexedDB.", "It is not used for advertising, retargeting, cross-site profiling, or building a profile of an identified user, and it never receives memory content.", "Separately from this beacon, the Cloudflare edge processes connection and request data as our proxy, as described on the Subprocessors page."]}, {"id": "cookies-we-do-not-use", "title": "Cookies and scripts we do not use", "body": "Apart from the Cloudflare Web Analytics beacon described above, public XMemo pages carry no third-party scripts.", "items": ["No advertising, retargeting, affiliate, or cross-site profiling cookies are set by the public website.", "No Google Analytics, PostHog browser analytics, Meta Pixel, or ad-network scripts are loaded on public pages.", "No public page asks users to paste OAuth codes, bearer tokens, API keys, or raw credentials into browser storage."]}, {"id": "managing-cookies", "title": "Managing cookies", "body": "Users can clear or block cookies through their browser settings. Blocking necessary cookies may prevent sign-in, OAuth connection, CSRF-protected actions, or language preference persistence from working correctly.", "items": ["Clearing cookies signs the browser out of active sessions and resets the public language preference.", "Authenticated users can reconnect OAuth or MCP clients after clearing browser state.", "Blocking scripts from static.cloudflareinsights.com stops the analytics beacon without affecting sign-in or any other XMemo function.", "Privacy requests can be sent to [email protected] without including cookies, tokens, authorization headers, or raw memory content."]}, {"id": "future-analytics-consent", "title": "Future analytics consent", "body": "If XMemo later adds product analytics, advertising pixels, or other non-essential browser storage, those scripts should be gated behind a consent banner and preference center.", "items": ["Non-essential tracking that stores data on the device should stay disabled until the user grants consent where required.", "Consent choices should be changeable without affecting necessary security cookies.", "This Cookie Policy, the Privacy Notice, and the Subprocessors page should be updated before any new browser tracking category is enabled."]}]}, "nav": [{"path": "/trust", "label": "Trust", "active": false}, {"path": "/legal/privacy", "label": "Privacy", "active": false}, {"path": "/legal/cookies", "label": "Cookies", "active": true}, {"path": "/legal/tos", "label": "Terms", "active": false}, {"path": "/legal/dpa", "label": "DPA", "active": false}, {"path": "/legal/subprocessors", "label": "Subprocessors", "active": false}, {"path": "/support", "label": "Support", "active": false}], "contentLocale": "en-US", "requestedLocale": "en-US", "fallbackReason": "", "decision": {"preferenceLocale": "en-US", "requestedLocale": "en-US", "contentLocale": "en-US", "fallbackReason": "", "source": "default"}, "labels": {"product": "Home", "docs": "Docs", "mcp": "MCP", "skills": "Skills", "trust": "Trust", "login": "Log in / Sign up", "start": "Get started", "publicNavigation": "XMemo public navigation", "publicResources": "XMemo public resources", "brandHome": "XMemo home", "language": "Language", "loadingTrustContext": "Loading trust context", "trustContextUnavailable": "Trust context unavailable", "cachedTrustShell": "Showing the cached trust shell while the context API recovers.", "loadingLegalContext": "Loading legal context", "legalContextUnavailable": "Legal context unavailable", "cachedLegalTrustShell": "Showing the cached legal and trust shell while the context API recovers.", "startPilot": "Start pilot", "openProductNavigation": "Open public navigation", "pageMetadata": "Page metadata", "lastReviewed": "Last reviewed", "sourceBackedPublicSummary": "Source-backed public summary", "legalAndTrust": "Legal and trust", "commitments": "Commitments", "memoryOsLegalTrustCenter": "XMemo legal and trust center", "footerLegalLinks": "Footer legal links"}}, "prefixedRoutesActive": false}
{"schemaVersion": "1.0.0", "pageId": "legal:cookies", "locale": "en-US", "contentLocale": "en-US", "status": "native", "fallbackReason": "", "canonicalPath": "/legal/cookies", "routePath": "/legal/cookies", "family": "legal_trust", "title": "Cookie Policy", "description": "", "editionDigest": "e1932fcbf8c3e7992209a98267b2b1b267215727a31d7247ae3f5594b5400d8f", "revision": "e1932fcbf8c3e7992209a98267b2b1b267215727a31d7247ae3f5594b5400d8f", "canonicalContentDigest": "8375052e525cc573ce043132988fce23d0bf29426bc76b33ca3bd8c9852d39b9", "anchors": ["cdn-analytics", "cookies-we-do-not-use", "cookies-we-use", "future-analytics-consent", "managing-cookies"], "serverOwned": true, "metadata": {"title": "Cookie Policy", "description": "", "canonicalPath": "/legal/cookies", "htmlLang": "en"}, "payload": {"page": "cookies", "content": {"title": "Cookie Policy", "kicker": "Legal", "lead": "XMemo uses cookies only for sign-in, security, OAuth handshakes, and one optional public language preference. Public pages also load a cookieless Cloudflare Web Analytics beacon, which stores nothing in your browser.", "last_reviewed": "August 2026", "source_note": "Aligned with the public locale cookie, session/CSRF cookie handling, OAuth state protection, and the Cloudflare edge configuration for public XMemo hostnames.", "commitments": ["Necessary cookies protect account sessions, CSRF boundaries, invite flows, and OAuth authorization redirects.", "The memory_os_locale cookie stores the public language preference only, such as en-US, zh-CN, ja-JP, ko-KR, or es-ES.", "No advertising, retargeting, or cross-site profiling cookies are set, and no analytics cookies are set.", "The Cloudflare Web Analytics beacon on public pages sets no cookie and writes nothing to browser storage.", "If a cookie-setting or otherwise non-essential tracking script is introduced later, XMemo will add consent controls before it loads."], "sections": [{"id": "cookies-we-use", "title": "Cookies we use today", "body": "Current cookies are limited to service operation, account security, and language preference. They are not used to sell data or track users across unrelated sites.", "items": ["Session cookies keep signed-in account, console, invite, and enterprise sessions active and are configured with route-appropriate HttpOnly, Secure, and SameSite protections.", "CSRF cookies let browser clients submit protected account and console requests without exposing bearer tokens in public pages.", "OAuth state and sign-in-flow cookies protect authorization redirects, device handoffs, invite sign-in, and account creation.", "memory_os_locale stores the selected public language so product, legal, and trust pages can render in English, Japanese, Chinese, Korean, or Spanish.", "The cookie notice acknowledgment is stored in browser localStorage and is not used for advertising or cross-site tracking."]}, {"id": "cdn-analytics", "title": "Cloudflare Web Analytics", "body": "Public XMemo pages load a Cloudflare Web Analytics beacon. Cloudflare enables it automatically for hostnames proxied through its network, and it measures page views and page-load performance.", "items": ["The beacon script is served from static.cloudflareinsights.com and reports to the /cdn-cgi/rum path on the XMemo domain.", "It reports the page URL, referrer, page-load and performance timings, and coarse browser, device, and country signals to Cloudflare.", "It sets no cookie and writes nothing to cookies, localStorage, sessionStorage, or IndexedDB.", "It is not used for advertising, retargeting, cross-site profiling, or building a profile of an identified user, and it never receives memory content.", "Separately from this beacon, the Cloudflare edge processes connection and request data as our proxy, as described on the Subprocessors page."]}, {"id": "cookies-we-do-not-use", "title": "Cookies and scripts we do not use", "body": "Apart from the Cloudflare Web Analytics beacon described above, public XMemo pages carry no third-party scripts.", "items": ["No advertising, retargeting, affiliate, or cross-site profiling cookies are set by the public website.", "No Google Analytics, PostHog browser analytics, Meta Pixel, or ad-network scripts are loaded on public pages.", "No public page asks users to paste OAuth codes, bearer tokens, API keys, or raw credentials into browser storage."]}, {"id": "managing-cookies", "title": "Managing cookies", "body": "Users can clear or block cookies through their browser settings. Blocking necessary cookies may prevent sign-in, OAuth connection, CSRF-protected actions, or language preference persistence from working correctly.", "items": ["Clearing cookies signs the browser out of active sessions and resets the public language preference.", "Authenticated users can reconnect OAuth or MCP clients after clearing browser state.", "Blocking scripts from static.cloudflareinsights.com stops the analytics beacon without affecting sign-in or any other XMemo function.", "Privacy requests can be sent to [email protected] without including cookies, tokens, authorization headers, or raw memory content."]}, {"id": "future-analytics-consent", "title": "Future analytics consent", "body": "If XMemo later adds product analytics, advertising pixels, or other non-essential browser storage, those scripts should be gated behind a consent banner and preference center.", "items": ["Non-essential tracking that stores data on the device should stay disabled until the user grants consent where required.", "Consent choices should be changeable without affecting necessary security cookies.", "This Cookie Policy, the Privacy Notice, and the Subprocessors page should be updated before any new browser tracking category is enabled."]}]}, "nav": [{"path": "/trust", "label": "Trust", "active": false}, {"path": "/legal/privacy", "label": "Privacy", "active": false}, {"path": "/legal/cookies", "label": "Cookies", "active": true}, {"path": "/legal/tos", "label": "Terms", "active": false}, {"path": "/legal/dpa", "label": "DPA", "active": false}, {"path": "/legal/subprocessors", "label": "Subprocessors", "active": false}, {"path": "/support", "label": "Support", "active": false}], "contentLocale": "en-US", "requestedLocale": "en-US", "fallbackReason": "", "decision": {"preferenceLocale": "en-US", "requestedLocale": "en-US", "contentLocale": "en-US", "fallbackReason": "", "source": "default"}, "labels": {"product": "Home", "docs": "Docs", "mcp": "MCP", "skills": "Skills", "trust": "Trust", "login": "Log in / Sign up", "start": "Get started", "publicNavigation": "XMemo public navigation", "publicResources": "XMemo public resources", "brandHome": "XMemo home", "language": "Language", "loadingTrustContext": "Loading trust context", "trustContextUnavailable": "Trust context unavailable", "cachedTrustShell": "Showing the cached trust shell while the context API recovers.", "loadingLegalContext": "Loading legal context", "legalContextUnavailable": "Legal context unavailable", "cachedLegalTrustShell": "Showing the cached legal and trust shell while the context API recovers.", "startPilot": "Start pilot", "openProductNavigation": "Open public navigation", "pageMetadata": "Page metadata", "lastReviewed": "Last reviewed", "sourceBackedPublicSummary": "Source-backed public summary", "legalAndTrust": "Legal and trust", "commitments": "Commitments", "memoryOsLegalTrustCenter": "XMemo legal and trust center", "footerLegalLinks": "Footer legal links"}}, "prefixedRoutesActive": false}