ValueinValuein
Back to home

Cookie Notice

Effective 2026-10-01 · Version 2026-10-01

What changed in this version

  • First published Cookie Notice.
  • Lists every cookie and browser-storage item we use, with its purpose and duration.
  • Explains that we use no advertising cookies, pixels or third-party analytics cookies.
  • Explains what Global Privacy Control switches off.

1.In short

Valuein (as identified in the Terms) uses a small number of first-party cookies and browser storage. Most keep you signed in or remember choices you made. Three — vi_ft, vi_persona and vi_vid — help us measure our own marketing and page experiments; they hold a channel name, a page name or a random number, never your name or email, and they are never shared with an advertiser. We use no advertising cookies, no third-party analytics cookies, no pixels and no session replay. If your browser sends Global Privacy Control, we stop setting the three measurement cookies. This summary is not a substitute for the notice below.

2.Cookies

"First party" means set on a valuein.biz domain. "Set by" names the code or service that creates the cookie.

NameSet byPurposeDurationPartyCategoryEffect of GPC
__Secure-authjs.session-tokenSign-in (Auth.js)Keeps you signed in; a signed, encrypted session token holding your user ID and sign-in method30 days, renewed while you use the ServiceFirstStrictly necessaryNone
__Host-authjs.csrf-tokenSign-in (Auth.js)Protects sign-in forms against cross-site request forgeryBrowser sessionFirstStrictly necessaryNone
__Secure-authjs.callback-urlSign-in (Auth.js)Remembers the page to return to after sign-inBrowser sessionFirstStrictly necessaryNone
__Secure-authjs.state, __Secure-authjs.pkce.code_verifier, __Secure-authjs.nonceSign-in (Auth.js), during Google/LinkedIn sign-in onlySecure the OAuth hand-off with Google or LinkedInAbout 15 minutesFirstStrictly necessaryNone
vi_llm_keyWorkspace, when you connect your own AI keyCarries your model key, sealed with AES-GCM; httpOnly, Secure, SameSite=Strict24 hours, or until you disconnectFirstStrictly necessary (feature you requested)None
vi_llm_laneWorkspace, when you choose Valuein-managed AIRecords that this session uses the managed lane (value managed; no secret)24 hours, or until you switchFirstStrictly necessary (feature you requested)None
valuein_ws_uiWorkspaceRemembers your Workspace layout (classic or chat)1 yearFirstFunctionalNone
vi_ftScript on every public pageRecords the channel and referring site of your first visit (for example social|linkedin); stored on your Account at sign-up so we know which channels bring customers1 year; never overwrittenFirstAnalytics (first-party attribution)Not set or read
vi_personaScript on /solutions/* pagesRecords the last solutions page you read (a page name only)30 daysFirstAnalytics (first-party attribution)Not set or read
vi_vidOur server, on page requests in scope for experimentsA random 32-character identifier that keeps you in the same version of a page we are testing and links a later sign-up to that version1 year, renewed on each visitFirstAnalytics (first-party experiments)Not set or read; no experiment exposure recorded

3.Browser storage (local storage and session storage)

These items stay in your browser and are not sent to us automatically, except where noted.

Key (pattern)Set byPurposeDurationCategoryEffect of GPC
vi_chat_v1, vi_chat_sessions_v1, vi_chat_active_session_v1, vi_chat_tombstones_v1, valuein:chat-sync-cursorWorkspace chatYour conversations on this device and the state of Cross-Device Sync (copies on our servers are described in the Privacy Policy)Conversations: 30 days after last use unless pinned; up to 200Strictly necessary (feature you requested)None
vi_report_chat_link_v1, valuein:ws-shell-panel-open, valuein:ws-shell-panel-mode, valuein:ws-shell-doc-id, valuein:ws-shell-panel-pct, valuein:ws-rail-collapsed, valuein:report-review-dock, valuein:dashboard-sidebar-collapsed, report-draft keys, model-choice keysWorkspaceRemember panel layout, the open report, unsaved drafts and your chosen modelUntil you clear themFunctionalNone
valuein:ws-first-run-dismissed, valuein:setup-card-dismissed, valuein:welcome-dismissed, valuein:start:*, valuein:mcp-tested, valuein:data-budgetWorkspace and onboardingRemember onboarding steps and notices you have dismissedUntil you clear themFunctionalNone
valuein:active-secondsWorkspace (signed-in)Total active minutes on this device, so the product survey appears only after real useUntil you clear itFunctionalNone
valuein:pmf-dismissed, valuein:pmf-answeredWorkspace (signed-in)Remember that you dismissed or answered the product surveyUntil you clear themFunctionalNone
valuein:session-id (session storage)Workspace (signed-in)A random per-tab identifier sent with a once-a-minute activity heartbeat, so we can measure time spent in the WorkspaceUntil the tab closesAnalytics (first-party product usage, signed-in only)None — it applies only to signed-in use of the Service
Other session-storage flags (refresh-on-return, examples prompt, token reveal)WorkspaceAvoid repeating an action within one tabUntil the tab closesFunctionalNone

4.Third-party services that run on our pages without cookies

  • Cloudflare Web Analytics. A script from static.cloudflareinsights.com sends page URL, referrer, browser type and page-performance timings to Cloudflare, which gives us aggregate statistics. It sets no cookies and no local storage, and Cloudflare does not use it to track you across sites. It runs on every page.
  • Cloudflare Turnstile. On sign-in, sign-up, contact and data-issue forms, Turnstile (loaded from challenges.cloudflare.com in a frame) checks that a person, not a bot, is submitting. Cloudflare's Turnstile Privacy Addendum states that it processes the client IP address, TLS fingerprint, user-agent and site key, that these signals are strictly necessary for bot detection, and that Cloudflare also uses them, as a controller, to improve bot detection. It is strictly necessary for those forms.
  • Company logos are served from logos.valuein.biz, our own cache. The logo vendor never receives your browser's request.

We do not use Google Analytics, advertising pixels (Meta, LinkedIn Insight, Google Ads), session-replay tools, third-party chat widgets or error-tracking scripts that capture page content.

6.Global Privacy Control

When your browser sends Sec-GPC: 1, we treat it as an opt-out of sale, sharing and targeted advertising (none of which we do), we stop setting and reading vi_ft, vi_persona and vi_vid, and, if you are signed in, we record the preference on your Account. See Privacy Policy Section 13.

7.Your controls

  • Turn on Global Privacy Control in your browser or with an extension.
  • Block or delete cookies and site data in your browser settings. Blocking the sign-in cookies means you cannot sign in; blocking vi_llm_key means your own AI key cannot be used; blocking the measurement cookies has no effect on the Service.
  • Clearing site data for valuein.biz removes the browser copies of your chats; copies held for Cross-Device Sync remain on your Account until you delete them.

8.Changes

If we add a cookie or storage item that is not strictly necessary or functional, we will update this notice before it is used, and treat it as a material change to the Privacy Policy (30 days' notice). Questions: legal@valuein.biz.