Legal / browser storage

Cookie Notice

Prelaunch draft

Last updated July 28, 2026. Written for the current prelaunch product.

Version
2026-07-28
Effective
Not yet effective
Review by
Before public signup
View this exact version →

Current prelaunch behavior. Wildflower uses first-party cookies only where needed to complete sign-in, maintain a console session, and protect state-changing requests. The current website does not use advertising or browser analytics cookies.

1. What cookies are

Cookies are small values a website asks a browser to store and return with later requests. This notice covers cookies set by Wildflower’s browser control plane. Public documentation can be read without signing in.

2. Cookies Wildflower uses

CookiePurposeDuration and controls
wildflower_loginBinds the start and callback of a Google sign-in transaction and helps prevent login forgery.Expires after ten minutes. Restricted to the Google authentication route, HttpOnly, SameSite=Lax, and secure in production.
wildflower_sessionIdentifies an authenticated browser session.Browser duration up to thirty days; the server session expires after twenty-four hours of inactivity. HttpOnly, SameSite=Lax, and secure in production.
wildflower_csrfSupports double-submit protection for authenticated state-changing browser requests.Browser duration up to thirty days. Readable by the browser application for the protection to work, SameSite=Lax, and secure in production.

These are necessary cookies. Wildflower does not use them to build advertising profiles or track people across unrelated websites.

3. Google sign-in

The console uses Google Identity Services to support Google sign-in. Google may use cookies or similar technologies under its own terms and privacy practices. Those technologies are controlled by Google rather than Wildflower and are used only when the identity flow is loaded or used.

4. Operational telemetry is different

Wildflower records content-minimized API telemetry for reliability, security, error diagnosis, and abuse prevention. That server-side operational data is not browser analytics and does not require an analytics cookie. The Privacy Notice describes the data involved.

5. Future analytics

Wildflower may add privacy-conscious product or website analytics in the future. Before using any non-essential cookie or similar browser storage, we will update this notice and provide notice, controls, or consent where required. This draft does not authorize advertising or cross-site tracking.

6. Your controls

Browser settings can delete or block cookies. Blocking the necessary cookies above prevents Google sign-in and the authenticated console from working correctly, but the public website and documentation remain available. You can also sign out to end the active browser session.

7. Changes and contact

We will update this page when cookie behavior changes and date material revisions. For privacy or cookie questions, email legal@wildflower.computer. For product or security help, follow the support guidance.