Current prelaunch behavior. Wildflower uses first-party cookies only where needed to complete sign-in, maintain a console session, and protect state-changing requests. The current website does not use advertising or browser analytics cookies.
1. What cookies are
Cookies are small values a website asks a browser to store and return with later requests. This notice covers cookies set by Wildflower’s browser control plane. Public documentation can be read without signing in.
2. Cookies Wildflower uses
| Cookie | Purpose | Duration and controls |
|---|---|---|
wildflower_login | Binds the start and callback of a Google sign-in transaction and helps prevent login forgery. | Expires after ten minutes. Restricted to the Google authentication route, HttpOnly, SameSite=Lax, and secure in production. |
wildflower_session | Identifies an authenticated browser session. | Browser duration up to thirty days; the server session expires after twenty-four hours of inactivity. HttpOnly, SameSite=Lax, and secure in production. |
wildflower_csrf | Supports double-submit protection for authenticated state-changing browser requests. | Browser duration up to thirty days. Readable by the browser application for the protection to work, SameSite=Lax, and secure in production. |
These are necessary cookies. Wildflower does not use them to build advertising profiles or track people across unrelated websites.
3. Google sign-in
The console uses Google Identity Services to support Google sign-in. Google may use cookies or similar technologies under its own terms and privacy practices. Those technologies are controlled by Google rather than Wildflower and are used only when the identity flow is loaded or used.
4. Operational telemetry is different
Wildflower records content-minimized API telemetry for reliability, security, error diagnosis, and abuse prevention. That server-side operational data is not browser analytics and does not require an analytics cookie. The Privacy Notice describes the data involved.
5. Future analytics
Wildflower may add privacy-conscious product or website analytics in the future. Before using any non-essential cookie or similar browser storage, we will update this notice and provide notice, controls, or consent where required. This draft does not authorize advertising or cross-site tracking.
6. Your controls
Browser settings can delete or block cookies. Blocking the necessary cookies above prevents Google sign-in and the authenticated console from working correctly, but the public website and documentation remain available. You can also sign out to end the active browser session.
7. Changes and contact
We will update this page when cookie behavior changes and date material revisions. For privacy or cookie questions, email legal@wildflower.computer. For product or security help, follow the support guidance.
