Cookie Policy
Effective Date: April 5, 2026 Last Updated: July 29, 2026 Version: 2.2
1. What Are Cookies
Cookies are small text files stored on your device when you visit a website. They help websites remember your preferences, maintain sessions, and provide a better user experience. We also use similar technologies such as browser localStorage and session storage.
hiroi is operated by TrentApps LLC (d/b/a hiroi). This policy covers hiroi.ai and its subdomains. Where a hiroi chat widget is embedded on someone else's website, see Section 4.
2. How We Use Cookies
We use cookies and similar technologies to operate the Service, maintain security, and improve your experience. We do not use cookies for cross-site behavioral advertising, and we do not sell or share data collected through cookies.
3. What We Actually Set
3.1 Essential Cookies (Always Active)
These are necessary for the Service to function. They cannot be disabled.
| Cookie | Purpose | Duration | Provider |
|---|---|---|---|
hiroi_session |
Signed server-side session: authentication, and the CSRF token used to protect state-changing requests | Browser session, subject to an enforced maximum lifetime | hiroi |
pa_visitor_session |
Session for visitors chatting with someone's public assistant at /with/<name> — set only on those pages |
Up to 12 hours | hiroi |
We do not set a separate CSRF cookie; the CSRF token is carried inside the
signed session cookie above. We do not set a cookie_consent cookie — your
consent choice is stored in localStorage (Section 3.3).
3.2 Optional Cookies
We currently set no optional cookies. The consent banner offers an Analytics category so that your choice is recorded and honoured in advance, but no third-party analytics or advertising cookies are set today. If we introduce any, we will update this policy and only set them where you have opted in.
3.3 Local Storage
The following are stored in your browser's localStorage rather than as cookies. They stay on your device, are not transmitted with every request, and can be cleared through your browser settings.
| Key | Purpose |
|---|---|
cookie_consent_choices |
Your cookie consent preferences — clearing it re-shows the banner |
cookie_visitor_id |
A random identifier generated in your browser so a consent choice can be recorded against it |
theme |
Dark/light mode preference |
hiroi.sidebarCollapsed |
Dashboard sidebar collapse state |
hiroi_onboarding_dismissed |
Whether the onboarding banner has been dismissed |
Your consent choice is also sent to our server (/api/consent/cookie) together
with the cookie_visitor_id, so that we hold a record of the choice you made.
4. The Chat Widget on Other Websites
When a hiroi AI agent chat widget (va-wave-widget.js) is embedded on a
third-party website:
- The widget sets no cookies
- It stores widget state in that site's localStorage under keys prefixed
va-widget-(for example, whether the widget is minimized and where it sits on screen) - It does not set tracking identifiers that follow you across different websites, and does not use third-party cookies
- The website operating the widget is responsible for disclosing it in their own cookie and privacy notices, and for obtaining any consent required in their jurisdiction
5. Third-Party Cookies
5.1 OAuth Providers
When you sign in with Google, Apple, or Microsoft, the respective provider may set cookies on their own domain as part of the authentication process. These cookies are governed by the provider's own privacy policy (Google, Apple, Microsoft).
5.2 Stripe
When you access payment features, Stripe may set cookies for fraud prevention and payment processing. These cookies are governed by Stripe's Privacy Policy.
5.3 Cloudflare
Our site is served through Cloudflare, which may set cookies necessary for security and bot mitigation. See Cloudflare's Privacy Policy.
6. Managing Cookies
6.1 Cookie Consent Banner
On your first visit we display a consent banner where you can:
- Accept All: Allow essential cookies plus any optional category you enable
- Essential Only: Allow only what is strictly necessary
- Manage Preferences: Set the Analytics category individually
The banner is not shown to signed-in users, because the cookies needed to keep you signed in are essential and cannot be declined while you are using an account.
To change your choice, clear your browser's site data for hiroi.ai — the banner will reappear.
6.2 Browser Settings
You can control cookies through your browser settings:
- Chrome: Settings > Privacy and security > Cookies and other site data
- Firefox: Settings > Privacy & Security > Cookies and Site Data
- Safari: Preferences > Privacy > Manage Website Data
- Edge: Settings > Cookies and site permissions
Note: Blocking essential cookies will prevent the Service from functioning properly — you will not be able to stay signed in.
7. Do Not Track and Global Privacy Control
There is no consistent industry standard for how sites should respond to "Do Not Track" (DNT) signals, and we do not currently alter our behaviour in response to DNT. We also do not currently detect the Global Privacy Control (GPC) signal.
Neither changes what we do with your data: we do not track you across websites, we do not serve behavioural advertising, and we do not sell or share personal information for cross-context behavioural advertising — so there is no opt-out-of-sale for these signals to exercise. If that ever changes, we will implement and honour GPC and update this policy first.
8. Changes to This Policy
We will update this Cookie Policy if we introduce new cookie categories or change how we use cookies. Material changes will be communicated through the Service.
9. Contact
For questions about our use of cookies:
TrentApps LLC (d/b/a hiroi) 117 S Lexington St, Ste 100 Harrisonville, MO 64701, United States Email: privacy@hiroi.ai