Skip to content

Cookie policy

A short list, because there is not much on it

Every cookie and browser-storage entry Itya sets, what it does, how long it lasts, and why none of it needs a consent banner with toggles.

Effective
September 2, 2026
Last updated
September 2, 2026

At a glance

A short summary of the complete document below.

No tracking
No advertising, profiling, cross-site or session-recording storage. None.
No third-party scripts
Nothing on an Itya page writes storage on behalf of another company.
Everything listed
All 10 entries are named below with purpose, duration and category.

Everything Itya stores in your browser

Itya sets 10 browser entries in total: 5 strictly necessary and 5 that remember a preference. There is no advertising cookie, no cross-site tracking cookie, and no third-party analytics or session-recording script on any Itya page.

Every cookie and browser-storage entry Itya sets, what it is for, how long it lasts, and its category.
NameStored asPurposeDurationCategory
__Host-refreshCookieHolds the session refresh token so a signed-in member stays signed in. HttpOnly, Secure, SameSite, and scoped to this origin only.7 days, rotated on every refreshStrictly necessary
__Host-csrfCookieCross-site request forgery token bound to the session.7 days, rotated with the refresh tokenStrictly necessary
__Host-oauth-txCookieBinds one in-flight OAuth sign-in or integration-connect round trip to the browser that started it.Minutes — cleared when the OAuth round trip finishesStrictly necessary
itya_localeCookieRemembers the language you picked so pages render in it.1 yearPreference
sidebar_stateCookieRemembers whether the workspace sidebar is expanded or collapsed.7 daysPreference
itya_themeLocal storageRemembers your light or dark appearance choice.Until you clear site dataPreference
itya_csrf_tokenLocal storageMirror of the CSRF token, used when the web app and API are served from different origins and the cookie cannot be read from script.Until you sign out or clear site dataStrictly necessary
itya_session_hintCookieA flag saying "this browser probably has a session", so the app can send you to your workspace and attempt a silent refresh instead of bouncing you to sign-in. Holds no credential. Kept as a cookie on this origin and mirrored in local storage.7 days, refreshed on every sign-in or token refresh; cleared when you sign outStrictly necessary
itya:job-brief-draft:v1Local storageKeeps an unsent job-brief draft so a reload does not lose your work.Until the draft is submitted or you clear site dataPreference
itya_cookie_noticeLocal storageRecords that you dismissed the cookie notice on the public site so it stays dismissed.Until you clear site dataPreference

The public marketing, legal, pricing, support and status pages set nothing at all until you interact with them. Signing in is what creates the session cookies; changing language, theme or the sidebar is what creates the preference entries.

Why we do not ask for consent

Under the ePrivacy rules, consent is needed for storage that is not strictly necessary for a service the user has actively requested. Itya only stores two kinds of thing:

  • Strictly necessary. Authentication, cross-site request forgery protection, and binding one OAuth round trip to the browser that started it. Without these you cannot sign in, and the service cannot be delivered securely. These are exempt from consent.
  • Preferences you set on purpose. Language, light or dark appearance, sidebar state, an unsent draft, and the fact that you dismissed the cookie notice. Each one is written only because you performed the action that asks for it to be remembered, and each is exempt on the same basis.

Because nothing here is used for advertising, profiling or cross-context behavioural tracking, Itya does not show a consent wall with toggles that would not change anything. We show a short notice with a link to this page instead. If that ever stops being true, this page and the notice change first.

Your controls

  • Clearing site data in your browser removes every entry in the table above. The next page load starts from defaults, and you will be asked to sign in again.
  • Blocking cookies for this site will stop you from signing in. The public pages will still work.
  • Signing out clears the session cookies immediately from both your browser and our server, and revokes the session.
  • Every stored preference is per-browser and per-device. Nothing in the table is shared with a third party.

Changes and contact

If we add browser storage that is not strictly necessary or a straightforward preference, we will update this page before it ships and put a real consent choice in front of you.

The privacy policy covers everything else we process, and the subprocessor list names every third party involved. Questions go to security@itya.ai.

Something missing from the table?

If you see storage on an Itya page that is not listed here, tell us and we will fix the page or the policy.

Email security@itya.ai and include enough context for us to route your question. Do not include passwords, API keys, or unnecessary candidate information.