Cookie Policy
Last updated: February 21, 2026
1. What Are Cookies
Cookies are small text files that are placed on your device (computer, tablet, or mobile phone) when you visit a website. They are widely used to make websites work more efficiently, provide a better user experience, and give website operators information about how their site is being used.
Cookies can be "session" cookies, which are deleted when you close your browser, or "persistent" cookies, which remain on your device for a set period of time or until you delete them manually.
2. Cookies We Use
2.1 Essential Cookies
These cookies are strictly necessary for IndexPilot to function. Without them, you would not be able to log in or use the service securely. Essential cookies cannot be disabled.
| Cookie Name | Purpose | Duration |
|---|---|---|
next-auth.session-token | Stores your encrypted session identifier to keep you signed in across page visits. This cookie is essential for authentication. | Session / 30 days |
next-auth.callback-url | Stores the URL to redirect you to after completing OAuth authentication with Google. This ensures you return to the correct page after signing in. | Session |
next-auth.csrf-token | A security token used to protect against cross-site request forgery (CSRF) attacks. This ensures that form submissions and authentication requests originate from our website. | Session |
2.2 Functional Cookies
Functional cookies allow IndexPilot to remember your preferences and provide enhanced, personalized features. These cookies are not strictly necessary but help improve your experience.
- User preferences — These cookies store your preferred settings such as sidebar collapse state, dashboard layout preferences, and notification settings. They ensure that your customizations persist across sessions.
2.3 Third-Party Cookies
Some cookies are set by third-party services that we integrate with. These cookies are governed by the privacy policies of their respective providers.
- Stripe — When you access the billing or payment pages, Stripe may set cookies to process payments securely, detect fraud, and maintain your payment session. These cookies are essential for payment processing.
- Google — If you choose to sign in with Google OAuth, Google may set cookies to facilitate the authentication flow and maintain your Google session. These cookies are only set when you actively use Google sign-in.
3. Managing Cookies
You can manage cookies through your browser settings. Most browsers allow you to:
- View the cookies stored on your device.
- Delete individual cookies or all cookies at once.
- Block cookies from specific websites or all websites.
- Set your browser to notify you when a cookie is being placed on your device.
Here are links to cookie management instructions for common browsers:
Important: If you disable or delete essential cookies (particularly the next-auth.session-token and next-auth.csrf-token cookies), you will not be able to log in to IndexPilot or use any authenticated features. The Service requires these cookies to function.
4. Changes to This Cookie Policy
We may update this Cookie Policy from time to time to reflect changes in the cookies we use or for other operational, legal, or regulatory reasons. If we make material changes, we will notify you by posting a prominent notice on our website or by sending you an email notification.
We encourage you to review this Cookie Policy periodically. The "Last updated" date at the top of this page indicates when this policy was last revised.
5. Contact Us
If you have any questions about this Cookie Policy or our use of cookies, please contact us at:
- Email: privacy@indexpilot.com
For information about how we handle your personal data more broadly, please see our Privacy Policy.