1Scope
This Cookie Policy explains how Neox uses cookies and similar local storage technologies on the neox-dev.com website and cloud console. Read it alongside the Privacy Policy: that document covers what data we collect, this one covers how it is stored in your browser.
It does not cover the Neox desktop client or command-line tools. Those are local applications and do not use browser cookies; how they store local configuration and credentials is described in the Privacy Policy.
2What Cookies and Local Storage Are
- Cookie
- A small piece of text a website stores in your browser and that is sent back automatically with later requests to that site. It is how a server recognizes that it is still the same browser.
- Session cookie
- Exists only for your current browser session and disappears when you close the browser.
- Persistent cookie
- Has an expiry date and survives until it expires or is cleared, so you do not have to sign in again on your next visit.
- localStorage
- Browser key-value storage. Unlike cookies, its contents are not sent to the server automatically — only page scripts on your own device read it.
- First-party vs third-party
- First-party is set by the domain you are visiting. Third-party is set by another domain embedded in the page.
This page refers to all of these as "cookies" unless the distinction matters.
3The Categories We Actually Use
The table below is the complete list of categories in use on the site. We do not use categories that are not listed.
| Category | Purpose | Type | Duration |
|---|---|---|---|
| Strictly necessary — session and auth | Keeps you signed in, identifies your account and entitlements, makes protected pages accessible | First-party cookie, HttpOnly + Secure + SameSite | Session, or until the login expires |
| Strictly necessary — CSRF protection | Issues and verifies one-time tokens so a cross-site request forgery cannot submit forms as you | First-party cookie | Session |
| Functional — language and theme | Remembers the interface language you chose (中文 / English) and light/dark theme, under the keys neox.locale.v2 and neox.theme | First-party localStorage | Until you clear browser data |
| Functional — interface state | Remembers whether sidebars are collapsed and whether the onboarding card was dismissed; keys beginning neox.chat. / neox.console. / neox.onboarding. | First-party localStorage | Until you clear browser data |
| Functional — account profile cache | Caches your own display name and plan so a page refresh renders correctly without waiting for the API, under the key neox.auth.user | First-party localStorage | Until you sign out or clear browser data |
| Functional — conversation drafts | Keeps web chat conversations on your own machine so a refresh does not lose them, under the key neox.chat.conversations.v1. This does not upload them to our servers | First-party localStorage | Until you clear browser data |
| Analytics — visitor identifier | A randomly generated first-party ID (key neox.vid) sent with page views, used only to count repeat visits from the same browser as one visitor (UV). It is not linked to your account, not used for advertising, never sent to a third party, and cannot identify you across sites | First-party localStorage + server-side record | Browser side until you clear data; server-side records deleted after 90 days |
| Security and anti-abuse — rate limiting | Detects abnormal request volume over short intervals and enforces limits to protect availability | Server-side record (by IP) | Up to 24 hours |
| Security and anti-abuse — device fingerprint | Derives an identifier from browser and device characteristics (keys neox.device.machineId / neox.device.fpHash) to detect bulk signup, quota evasion, and credential stuffing | First-party localStorage / sessionStorage + server-side record | Up to 12 months |
Separately, after you register we write one neox.welcome.credits entry to sessionStorage purely so the welcome page can show it once; it disappears when you close the tab.
Strictly necessary cookies are a precondition for the site working and do not require consent. The security and anti-abuse categories rest on our legitimate interest in protecting the Service and its users (GDPR Article 6(1)(f)). The functional language preference is written only when you actively switch languages.
4What We Do Not Use
We do not serve advertising cookies, use cross-site tracking technology, integrate ad networks or data brokers, or sell or share your information for targeted advertising.
Concretely, the site contains none of the following:
- advertising conversion pixels or remarketing tags;
- social media tracking pixels;
- third-party cookies that link your identity across sites;
- behavioural analytics scripts that send your data to a third party;
- session-replay or heatmap tools that record where you click and move.
We do need to understand basic site usage, and we do it with our own server-side analytics — no Google Analytics or similar third-party service is integrated. To tell "one visitor came ten times" apart from "ten visitors came once", we store a random ID (neox.vid) in your browser and send it along with page views to our own server. We are not going to pretend otherwise: that is an identifier stored in your browser. Its boundaries are narrow, though — only we can read it, it is used only to count people, it is not linked to your account, it is never sent to a third party, and it cannot follow you to any other site. Clearing site data resets it.
5Third-Party Cookies During Checkout
When you subscribe to a paid plan, payment is handled by a third-party payment provider. During that flow the provider may set cookies under its own domain in order to:
- maintain the checkout session and order state;
- run bank-side authentication such as 3-D Secure;
- perform fraud detection and risk scoring, which card schemes and regulators generally require.
These cookies are controlled by the payment provider, not by us, and are governed by its own privacy and cookie policies. We never receive your full card number and cannot read the contents of those cookies. The payment provider is identified in the Subprocessors list.
Our documentation or help pages may embed third-party hosted video or code samples. Where such an embed is present, that third party may set cookies; we prefer embed modes that do not write cookies.
6How to Control Cookies
You can inspect, delete, or block cookies through your browser settings:
- Chrome: Settings → Privacy and security → Third-party cookies / Site data;
- Safari: Settings → Privacy → Manage Website Data;
- Firefox: Settings → Privacy & Security → Cookies and Site Data;
- Edge: Settings → Cookies and site permissions.
The language preference lives in localStorage and is removed by clearing site data. Once removed, the site returns to its default language.
Note: if you block strictly necessary cookies, core functionality will not work — you will not be able to sign in, or you will be signed out repeatedly, and form submissions may be rejected because CSRF validation fails. This is not something we can work around; it is what those cookies do.
Most browsers also offer Do Not Track (DNT) or Global Privacy Control (GPC) signals. Because we do not do cross-site tracking and do not share data for advertising, these signals do not change our behaviour — our default already matches what they ask for.
7Changes to This Policy
Whenever we add, change, or remove a storage technology, we update this page and the "Last updated" date at the top.
If you have questions about this policy or about a specific cookie we use, contact support@neox-dev.com.

