Cookies Policy
What Sinchao stores in your browser, why it is stored there, and which third parties see a request when a page loads.
Last updated 14 August 2026.
01The short version
Sinchao sets no advertising cookies and no analytics cookies. We do not track you across sites, and we show no consent banner because there is nothing non-essential to consent to.
What we do keep is a sign-in session in your browser’s local storage, and a small number of strictly necessary cookies that our infrastructure provider may set to keep the service secure.
02What Sinchao stores in your browser
- customer-support-ai:token
- the session token issued when you sign in, so the workspace knows the request is yours. Held in local storage.
- customer-support-ai:user
- the email address of the signed-in account, so the workspace can show who is signed in. Held in local storage.
Both are strictly necessary: without them you cannot stay signed in. They persist until you sign out or clear the site’s data, and they are never sent to a third party.
03Why local storage and not a cookie
Published sites can share a parent domain, and a cookie scoped to that parent domain would be readable by every other site on it. Keeping the session in local storage confines it to this origin. It is a security choice, not a way to avoid the cookie rules — the law treats storing and reading information on your device the same way whichever mechanism is used, and we describe it here for that reason.
04Cookies set by our infrastructure
Cloudflare serves and protects this site and may set strictly necessary cookies such as __cf_bm for bot management, or a cookie carrying a challenge result if one is shown to you. These exist to keep the service available and are not used to profile you. They expire within a short period, typically 30 minutes to a day.
05Requests to other providers
Loading a page makes your browser fetch assets from third parties. They set no cookies for us, but the request itself discloses your IP address, user agent and the page you are on:
- Cloudflare R2 and our asset domain (files.cname-beepflow.app) — page content, icons and fonts.
How the provider handles what it logs is set out in its own notice.
06Controlling what is stored
- Every browser lets you view, block and delete cookies and site data, usually under privacy or site settings.
- Clearing this site’s data removes the session and signs you out.
- Blocking storage for this site altogether will prevent sign-in from working, since the session has nowhere to live.
07If this changes
If we ever introduce analytics, advertising or any other non-essential storage, we will update this policy and ask for your consent before it is set. This version is dated 14 August 2026.
08Contact
Questions about this policy go to [email protected]. How we use the personal data behind these mechanisms is described in our Privacy Policy.