Hello by Flow
/ LEGAL

Cookie Policy

LAST UPDATED · 22 JUNE 2026

This Cookie Policy explains how Hello by Flow uses cookies and similar tracking technologies.

What we use

Strictly necessary (always on)

  • access_token — your authentication cookie (HttpOnly + Secure + SameSite=Lax). Set by our backend; not accessible to JavaScript. Required to keep you signed in.
  • refresh_token — HttpOnly cookie used to rotate the access token every 15 minutes; 90-day lifetime.
  • csrf_token — JS-readable cookie used by our frontend to mirror as X-CSRF-Token on state-changing requests.
  • hbf_support_session_v1 — anonymous session ID for the Hello by Flow support chatbot. Stored in localStorage.

Functional

  • UI preferences (dialer position, sidebar collapsed state).

Analytics

We use first-party, IP-anonymised analytics to count page views and identify performance issues. We do not use Google Analytics or any third-party advertising tracker.

Your choices

You can clear cookies in your browser settings at any time. Clearing strictly necessary cookies will log you out.

Do Not Track

We honour browser-level Do Not Track signals for the analytics bucket.

Contact

Questions: privacy@hellobyflow.com

← Back to home© 2026 HELLO BY FLOW