GeoInsight API Docs Log in Get an API key

Cookie Policy

Effective 15 August 2026

The short version

We set two cookies. Both are strictly necessary to log you in and to protect the forms you submit. We use no analytics, advertising or tracking cookies, and we load no third-party scripts that could set their own.

The bar you may have seen at the bottom of the page is a notice, not a consent request. Cookies that are strictly necessary to deliver a service you asked for are exempt from the consent requirement, so there is nothing here for you to opt into or out of. We show the notice because you deserve to know what is set in your browser — but we do not offer an "reject" button for cookies we cannot function without, because a choice we would not honour is theatre, not a choice. Dismissing the notice is remembered in your browser's local storage, not in a cookie.

The cookies we set

Name Purpose Lifetime Type
geoinsight-session Identifies your browser session so you stay logged in as you move between pages. The cookie holds only an identifier — the session contents live on our server, not in your browser. Marked HttpOnly, so scripts cannot read it. 2 hours Strictly necessary, first-party
XSRF-TOKEN Protects against cross-site request forgery: it lets our pages prove that a form submission came from you and not from another site acting in your name. Readable by our own scripts, which is what makes the check work. 2 hours Strictly necessary, first-party

Both are set with SameSite=Lax, so they are not sent on cross-site requests initiated by other websites. Both are set on public pages too, including the documentation, because the anti-forgery protection has to be in place before you reach a login form.

Cookies during payment

When you buy credits you are taken to Stripe's own checkout pages. Stripe sets its own cookies there, on Stripe's domain, to run the payment and to detect fraud. Those cookies are outside our control and are governed by Stripe's privacy and cookie policies. We receive the outcome of the payment, not the cookies.

The API sets no cookies

Calls to /v1/* authenticate with the X-API-Key header. If you are integrating with GeoInsight from your own backend, no cookie handling is required at all.

How to control cookies

Every major browser lets you view, block and delete cookies, per site or globally. Look for "Cookies and site data" in your browser's privacy settings.

Be aware of the trade-off: because both of our cookies are strictly necessary, blocking them means you will not be able to log in, and form submissions will be rejected by the anti-forgery check. Browsing the public documentation will still work.

Changes to this policy

If we ever add a cookie, this page changes before the cookie does, and the effective date at the top moves. Should we ever introduce a cookie that is not strictly necessary, we will ask for your consent first — properly, with a real choice.

If that ever happens, the notice at the bottom of the page becomes a real consent banner, with a genuine reject option that actually blocks the cookie.

Questions: privacy@geoinsight.dev. See also our Privacy Policy.