Cookie Policy
Effective October 3, 2026 · Centraflow Pvt Ltd
The few cookies and browser-storage items we use, and why none of them need a consent banner.
1. Summary
Centraflow AI uses only cookies and browser storage that are needed to sign you in, keep your session secure and remember your work and settings. We do not use advertising, tracking or analytics cookies. Because of this we do not show a cookie consent banner; if that changes we will ask for your consent first.
2. Cookies we set
- Session cookie (
authjs.session-token) — keeps you signed in. Strictly necessary. Expires when your session ends or after its maximum lifetime. - CSRF token (
authjs.csrf-token) — protects sign-in and sign-out requests from forgery. Strictly necessary. - Sign-in flow cookies (
authjs.callback-url,authjs.state,authjs.pkce.code_verifier) — short-lived cookies used while signing in with Google or GitHub. Strictly necessary.
On secure connections these cookie names carry a __Secure- or __Host- prefix.
3. Browser storage
- IndexedDB — a local copy of your latest draft (notes, outline, preview state and theme) so your work is restored if you reload the page or lose connection.
- Local storage (
mindmap:model-choices) — remembers the AI model you selected.
4. Checkout and Paddle
When you open the pricing or checkout experience, Paddle.js is loaded from Paddle so you can pay securely. Paddle, as our Merchant of Record, may use cookies or similar technologies for checkout functionality, fraud prevention and security. See the Paddle Privacy Notice for details.
5. Managing cookies and storage
You can block or delete cookies and site data in your browser settings. If you block the strictly necessary cookies you will not be able to sign in. Clearing site data also removes your local draft copy; projects saved to your account are not affected.
6. More information
See our Privacy Policy for how we handle personal data, or contact us at omar@centraflow.tech.