Cookies & local storage

Cookies and local storage

A short document, because there is very little to describe. No analytics, no advertising, no tracking — and a precise account of the few things that are stored.

Last updated 15 August 2026Revision Draft 1.0Effective [EFFECTIVE DATE]

In plain language

The public Tephlo sites — marketing, documentation and this legal site — set no tracking cookies of any kind. There is no analytics script, no advertising pixel and no third-party script at all: the sites’ security policy blocks them outright.

  • One optional first-party cookie exists, on the pricing page, and only if you choose a different currency.
  • The signed-in consoles set session cookies. Without them you cannot stay logged in, so they are strictly necessary.
  • The embeddable chat widget stores a random id in the browser’s local storage so a conversation survives a page reload. It is not a cookie and it identifies nobody.

1. The public sites

Visiting the marketing site, the documentation site or this legal site sets no cookies at all unless you take the action described in section 2. There is nothing to opt out of, because:

  • no analytics product is installed — not a self-hosted one either;
  • no advertising, remarketing or conversion pixels are present;
  • no third-party fonts, scripts, embeds or content delivery networks are loaded — everything is served from our own origin, and the pages send a content security policy that forbids third-party scripts, frames and connections;
  • no fingerprinting is attempted, and nothing about your visit is passed to another company by us.

Our hosting provider processes ordinary connection data — IP address, request time, user agent — in server logs to deliver the page and protect against abuse, as any web host does. That is described in the Privacy Policy, and the provider is on the sub-processor list.

2. The one preference cookie

The pricing page shows prices in a market currency. If you switch markets, that choice is stored so the page keeps showing your currency next time.

Set on the marketing site only
NameWhat it holdsSet whenLifetime
tephlo_marketA short market code such as a country or region identifier — nothing about you.Only when you pick a market on the pricing page. Simply visiting the page sets nothing.One year, first-party, SameSite=Lax.

An older cookie named xephlo_market, from before the product was renamed, is actively cleared when you set a market. Deleting either one simply returns the pricing page to its default currency. Your choice is never used to identify you, and the page never guesses your market from your IP address.

3. The consoles

The agent console and the operator console are private applications you sign into. They set strictly necessary cookies — without them there is no way to know you are signed in.

Set after you sign in
CookiePurposeLifetime
__Host-dash_access / __Host-op_accessHolds the short-lived access token that authorises each request.Minutes — it is refreshed automatically while you work.
__Host-dash_refresh / __Host-op_refreshLets the console get a new access token without asking you to sign in again. Rotated on every use; replaying an old one revokes the whole session family.Until it expires or you sign out.
__Host-dash_mfa_enrollment / __Host-op_mfa_enrollmentMarks that you are part-way through setting up multi-factor authentication, so the console knows where to send you. It contains no credential.The enrolment step only.

All of these are httpOnly — JavaScript cannot read them, which is what stops a script on the page from stealing a session. In production they carry the __Host- prefix, meaning the browser refuses to accept them from any other host or path, and are marked Secure and SameSite=Lax.

The console also remembers your light or dark theme choice in the browser’s local storage under theme. It never leaves your device.

4. The embeddable chat widget

If a business puts the Tephlo chat widget on its own website, the widget stores a value in that site’s local storage under xw_visitor: a random string the widget generates in your browser. It exists so that reloading the page does not start a new conversation from scratch.

  • It is not a cookie, is not sent automatically with requests, and is readable only by that one site.
  • It contains no name, email or account — it is random, and clearing site data replaces it with a new one.
  • The conversation session itself is held on our servers for one hour of inactivity and then expires.
  • Because it is storage on your device, the business embedding the widget is responsible for mentioning it in their own cookie or privacy notice.

5. WhatsApp and Telegram

Conversations on WhatsApp and Telegram happen inside those apps, and nothing in this document applies to them. What those apps store on your device is governed by their own policies.

6. Controlling what is stored

  • Browser settings. Every browser can block or delete cookies and site data for a specific site. Nothing here resists that.
  • The preference cookie. Delete it, or block cookies for the marketing site, and pricing simply shows its default currency.
  • The console cookies. Blocking them prevents signing in — there is no alternative mechanism, which is what “strictly necessary” means.
  • The widget id. Clearing site data for the site hosting the widget removes it.
Do Not Track and Global Privacy Control. We have nothing to switch off in response to these signals, because there is no tracking to begin with.

Consent is required for storage that is not strictly necessary for a service the visitor asked for. On these sites there is none: no analytics, no advertising, no profiling. The currency cookie is set only by your own explicit choice, and the console cookies are necessary for a service you signed into. A banner asking permission for nothing would be theatre, and would train people to click through the ones that matter.

If that changes, this page changes first. If we ever add analytics, a consent mechanism will ship with it and this page will say so before it is switched on.

Contact

General questions about this document go to support@tephlo.com. Questions about personal data, including requests from individuals, should go to the data protection contact at [DATA PROTECTION CONTACT]; until that address is published, the general address above reaches the same team.

Postal address: [REGISTERED COMPANY NAME], [REGISTERED ADDRESS].