Flolah

Cookie Policy

Version 2026-08-09

Flolah currently uses strictly necessary and functional preference storage only. We do not load advertising or product-analytics pixels on the main app or marketing homepage as of this version. No consent banner is required for optional marketing cookies because none are deployed. If that changes, we will update this policy and add consent where required.

1. What we mean by cookies

This page covers HTTP cookies and similar browser storage (localStorage / sessionStorage) used by Flolah, plus related third-party storage for optional features (CRM, OAuth providers).

2. How Flolah keeps you signed in

Primary app authentication uses a session token in localStorage (agent-os-auth-token), not a first-party login cookie. The server validates that token on API requests. Sessions typically last up to about 14 days unless you sign out earlier.

3. First-party HTTP cookies

NamePathPurposeDurationCategory
agent_os_os_console /opensearch Admin-only launch cookie for the OpenSearch console proxy (HttpOnly, SameSite=Lax; Secure on HTTPS). Bound to a valid Flolah admin session. ~30 minutes Strictly necessary (admin)
agent_os_oc_console /openconnector Admin-only launch cookie for the OpenConnector console proxy. ~8 hours Strictly necessary (admin)

These cookies are cleared when you log out of Flolah (and related console logout paths).

4. localStorage (first-party app)

KeyPurposeCategory
agent-os-auth-tokenBearer session tokenStrictly necessary
agent-os-impersonator-tokenAdmin impersonation restore tokenStrictly necessary (admin)
agent-os-themeLight/dark preferenceFunctional
agent-os-nav-collapsedSidebar layout preferenceFunctional
agent-os-nav-section:*Nav section open/closedFunctional
agent-os-dismissed-feed-idsDismissed notification IDsFunctional
agent-os-wf-props-pane-widthWorkflow editor layout widthFunctional

5. sessionStorage (first-party, tab-scoped)

Key patternPurposeCategory
company-operate-resume-stepResume company-operate wizardFunctional
wf-agent-chat:{id}Workflow builder chat draftFunctional
ao-public-vr-chat:{slug}Public Virtual Room transcript cacheFunctional

6. Related storage (not Flolah login-host cookies)

7. Marketing homepage, blog, and forum

The static marketing site (flolah.cloud) does not set tracking cookies by default. The public blog is static. The forum uses GitHub Discussions on github.com — when you sign in or comment there, GitHub’s cookies and terms apply (not Flolah login cookies).

8. Managing storage

9. Changes

If we introduce analytics or advertising cookies, we will update this page and implement consent tools where required.