Cookie Policy
Last updated:
In plain language
Business AI Assistant uses a single strictly necessary cookie to keep you signed in, plus a theme preference in your browser. The chat widget on customers’ websites uses no cookies at all, only an anonymous visitor identifier and the current conversation kept in browser storage. There are no advertising or analytics cookies. Cloudflare, which protects our servers, may set its own security cookies.
This summary is for convenience only; the full text below is what applies.
On this page
1.What cookies and browser storage are
A cookie is a small text file that a website stores in your browser and that the browser sends back with later requests to the same site. Cookies are how a site recognises that you are signed in.
Local storage and session storage are similar browser features that let a page keep small pieces of data on your device. Unlike cookies, they are never sent to a server automatically; the page has to read them. Session storage is cleared when the tab is closed; local storage stays until it is deleted.
This policy explains which of these Nexoply uses in Business AI Assistant, why, and how you can control them. It is part of our Privacy Policy.
2.What we use
Customer app (nexoply.com)
| Name | Purpose | Type | Duration |
|---|---|---|---|
__Host-bai_session | Keeps you signed in to your account. Contains only a random session identifier; it is httpOnly (not readable by scripts), Secure (HTTPS only) and SameSite=Lax. | Strictly necessary cookie | 30 days from your last visit, or until you sign out or reset your password |
bai-theme | Remembers whether you chose the light or dark theme. Absent if you leave the theme on “system”. | Functional (localStorage) | Until you change the setting or clear site data |
Admin app (admin.nexoply.com)
The admin app is used only by our staff.
| Name | Purpose | Type | Duration |
|---|---|---|---|
__Host-bai_admin_session | Keeps a staff member signed in to the admin app. Same protections as the customer session cookie; a customer session never works in the admin app and vice versa. | Strictly necessary cookie | 12 hours from the last request, or until sign-out |
bai-theme | Theme preference, as in the customer app. | Functional (localStorage) | Until changed or cleared |
Chat widget (on our customers’ websites and our demo page)
The widget that businesses embed on their websites sets no cookies. It keeps two items in the browser storage of the website it is installed on:
| Name | Purpose | Type | Duration |
|---|---|---|---|
bai_visitor | A random, anonymous identifier (32 hexadecimal characters) that lets a returning visitor continue a recent conversation and lets us limit abuse. It is not linked to any name, email or account and is not shared between websites. | Functional (localStorage) | Until the visitor clears the website’s site data |
bai_chat_<chatbot key> | The identifier of the current conversation and whether the chat window is open, so the chat survives page navigation within the same tab. | Functional (sessionStorage) | Until the browser tab is closed |
Because the widget runs on the business’s website, that business is responsible for including it in its own cookie or privacy notice where the law requires one.
3.No advertising or analytics cookies
We do not use advertising cookies, analytics cookies, tracking pixels, social-media plug-ins or cross-site identifiers on nexoply.com, on the admin app or in the widget. We do not track visitors across websites, and we do not build profiles of website visitors.
Usage figures shown in a customer’s dashboard (such as the number of conversations) are counted on our servers from the conversations themselves, not from cookies.
4.Third-party cookies
Our websites sit behind Cloudflare, which protects them from attacks. Cloudflare may set its own cookies on nexoply.com and its subdomains for security purposes, for example:
| Name | Purpose | Duration |
|---|---|---|
__cf_bm | Distinguishes automated traffic (bots) from real visitors as part of Cloudflare’s bot management. | Up to 30 minutes |
cf_clearance | Records that you passed a security challenge, so you are not asked again. | Set by Cloudflare, typically up to a few hours or days |
These cookies are controlled by Cloudflare and described in its own cookie policy. They are not used for advertising. The widget’s requests also pass through Cloudflare, but Cloudflare cookies set on nexoply.com are not visible to the website the widget is installed on.
When you subscribe to a paid plan, checkout and billing management happen on pages hosted by Stripe, which sets its own cookies under Stripe’s privacy and cookie policies.
5.How to control cookies and storage
- Signing out removes the session cookie immediately. Resetting your password signs you out everywhere.
- Browser settings let you view, block or delete cookies and site data for any website, including local and session storage. Look for “cookies and site data” or “privacy” in your browser’s settings.
- Private or incognito windows discard cookies and storage when you close them.
- Visitors can remove the widget’s identifier by clearing the site data of the website they chatted on; the next chat then starts with a fresh anonymous identifier.
The session cookie is required for the Service to work: if you block it, you will not be able to sign in. Blocking browser storage on a website that uses the widget still lets you chat, but the conversation will not be remembered when you navigate to another page.
We do not currently respond to browser “Do Not Track” or Global Privacy Control signals, because we do not track or sell data in the first place.
6.Changes to this policy
If we add a cookie or storage item, or change how one is used, we will update the tables above and the “Last updated” date. Material changes will also be announced in the dashboard or by email.
7.Contact
Questions about cookies or browser storage in Business AI Assistant are welcome:
- General questions and privacy requests: [email protected]
- Legal notices: [email protected]