How the current service uses browser storage
HEXOUT uses first-party cookies for authentication and CSRF protection and may use first-party preference storage for the selected appearance theme. These technologies are used for security, session continuity and user-requested preferences, not behavioural advertising.
hexout_portal_session
Purpose: essential authenticated portal session. First party. The cookie is HttpOnly and SameSite=Lax, and is Secure in production. Current production absolute lifetime: up to 12 hours, with a server-side idle limit of 30 minutes.
hexout_portal_csrf
Purpose: essential cross-site request forgery protection for the portal. First party, SameSite=Lax and Secure in production. The authenticated lifetime follows the portal session, up to 12 hours. An anonymous CSRF token used before authentication has a maximum age of 10 minutes.
xo_platform_session
Purpose: essential authenticated HEXOUT application/customer/operator session. First party. HttpOnly, SameSite=Lax and Secure in production. Current production maximum age: 12 hours.
xo_platform_csrf
Purpose: essential cross-site request forgery protection for the HEXOUT application. First party, SameSite=Lax and Secure in production. Current production maximum age: 12 hours.
xo_theme preference
The Control interface can store a theme preference under the key xo_theme in localStorage and in a first-party cookie so the user's selected appearance can be remembered. The cookie can persist for up to one year. This preference is not used for advertising or cross-site tracking.
Wallet and third-party software
A connected wallet, payment provider or other separately chosen third-party software may use its own cookies or browser storage. Where HEXOUT introduces a third-party technology on its own pages, HEXOUT will assess the purpose, third party, duration and consent requirements before treating it as production-ready.
Consent and strictly necessary technologies
Technologies that are strictly necessary to provide a service expressly requested by the user, such as authentication and security controls, may be used without consent where the applicable PECR exemption applies. Non-essential technologies that require consent will not be activated until the required clear information and valid consent mechanism are in place.
No advertising or third-party analytics in the current release
The current public marketing templates do not configure advertising cookies, tracking pixels or third-party analytics cookies. If analytics, advertising technology, link tracking, fingerprinting or additional non-essential storage is introduced, this notice and the consent mechanism must be reviewed before that feature is treated as production-ready.
Managing storage
Browser controls can be used to inspect or delete cookies and local storage. Deleting essential authentication storage will sign the user out or prevent an authenticated request from completing until a new valid session is established.
Changes
HEXOUT will update this notice if the purposes, technologies, third parties or storage durations change materially.