Cookie policy

Last updated 2026-10-02

GroundedReply uses no analytics, advertising or tracking cookies, and no third-party trackers. The only third-party files it loads are on the API documentation page. Because of that, this page explains what we do use instead of asking you to accept a cookie banner.

1. What we use, and why no banner

Cookie consent banners exist because most sites use non-essential cookies (analytics, advertising) that require opt-in consent. GroundedReply doesn't set any: we don't run analytics, we don't advertise, and no third party can track you across sites through this service. What little browser storage we do use is strictly necessary to sign you in or to provide a feature you asked for, such as connecting an app or keeping the API key you typed into the API documentation page. That is exempt from consent requirements under the ePrivacy rules. That's why there is no cookie banner on this site.

2. What we actually store, item by item

ItemWherePurposeCleared
Sign-in tokens (ID token, access token, refresh token) Browser sessionStorage, not a cookie Keeps you signed in while you use the dashboard. The refresh token renews the session without asking you to sign in again, so you are not signed out while you are working When you close the browser tab, or when you sign out
OAuth consent request Browser sessionStorage (key appcore.oauth.pending.v1), not a cookie Only when you connect an AI app to your account. Remembers which app's request you are answering while you sign in, so the consent screen can come back after sign-in When you allow or decline, after 10 minutes, or when you close the tab
Swagger UI authorization Browser localStorage (key authorized), not a cookie, only on the API documentation page Only if you enter an API key in Swagger UI: remembers it so you do not have to paste it again on the API documentation page Until you log out in Swagger UI or clear site data for groundedreply.com
PKCE verifier and state Browser sessionStorage, not a cookie Only when you choose "Continue with Google". Strictly necessary: proves the sign-in redirect came back to the same browser that started it (PKCE, part of the OAuth sign-in flow) Once sign-in completes, or when you close the tab
Cognito sign-in session cookies Cookies, set by AWS on our Amazon Cognito sign-in domain (a *.amazoncognito.com subdomain), only when you choose "Continue with Google" and the sign-in redirect passes through that domain Strictly necessary: completes the sign-in redirect Per Amazon Cognito's own session lifetime

Signing in, creating an account or resetting a password with email and password happens on this site's own pages, which send your details directly to Amazon Cognito over an encrypted connection and set no cookie.

None of the above is used for analytics, profiling, or advertising, and none of it is shared with a third party for those purposes.

3. API documentation page

Our API documentation page at /api/public/docs is built with Swagger UI. It loads Swagger UI's stylesheet and script from cdnjs.cloudflare.com, a public code library service run by Cloudflare. Both files are pinned to one version and checked with Subresource Integrity hashes, so your browser refuses a changed copy. Your browser sends a request to cdnjs when it opens that page, and cdnjs sees your IP address and browser details as it would for any file. cdnjs sets no cookie for us. No other page on this site loads a file from a third party.

If you enter an API key in Swagger UI, it keeps the key in localStorage on this site, as listed in the table above. That storage stays on your device. We do not read it, and it is not sent anywhere but with your own API requests from that page.

4. How you can manage cookies

Since we don't use non-essential cookies, there is nothing to opt out of. If you'd still like to review or clear what your browser holds, every modern browser lets you inspect and delete site data from its settings (often under "Privacy" or "Site settings"). Clearing site data for groundedreply.com will sign you out.

5. Changes to this policy

If that ever changes — for example, if we add an optional feature that needs a non-essential cookie — we will update this page and add a consent mechanism before doing so, not after.

6. Contact

Questions about this policy: hello@groundedreply.com.