Cookies and storage
Effective September 22, 2026. Privacy Notice.
Your choice
Optional analytics stays off until you accept. Accept and reject are equally available. Change your website choice using Privacy preferences in the footer. The console has a separate account-wide switch in My account, off by default. Declining leaves sign-in, policies and execution available.
Storage inventory
- Sign-in and CSRF cookies: the console uses these to authenticate your session and protect requests. Sessions expire after 15 idle minutes and at most eight hours. Short-lived login, invitation and OAuth challenges support your requested sign-in. Directory hints remember the identity provider to offer.
- Appearance cookie (eb_appearance): your requested console theme, retained for one year.
- Local browser preferences: eb.sidebar, table density and execbound.agent-host.* remember navigation, display and an agent's selected host until changed or browser storage is cleared. They are not analytics identifiers.
- Session storage: a reload guard prevents repeated reloads after a stale application bundle. It ends with the browser tab session.
- Website consent (eb.analytics.v1 in local storage): an accept/reject choice and expiry, retained for 180 days. No visitor ID. Invalid or unavailable storage means no optional collection.
- Account preference: the optional console analytics choice is saved against your account across devices. Security audit and notifications are independent of it.
Optional event fields
Website requests contain only an allowlisted page category, event (page visit, signup click or sales click) and affirmative consent. Console requests contain only account opened, agent connection verified, request verified or approval completed. The server adds a UTC day and combines counts within the relevant workspace. Counts store no visitor identifier, email, raw URL, query string, referrer, IP address, prompt, credential, policy text, resource name or action arguments.
These are approximate event totals, not unique visitors. Console events are limited to once per tab lifetime. Hosting systems still process ordinary technical connection information; operational logs are separate. We use no advertising cookies, third-party analytics SDKs, fingerprinting, autocapture or session replay.
Retention and withdrawal
Reports cover 90 days. Older count rows are removed when the workspace next records an event; inactive workspaces may retain older aggregates until maintenance. Withdrawal stops new optional collection. Previously combined totals cannot be separated for an individual. Clearing browser storage resets the website choice to off but does not change the account preference.
Request other account data or closure in My account or contact us. Audit, support and backup retention are handled separately.