/ LEGAL
Cookie Policy
LAST UPDATED · 22 JUNE 2026
This Cookie Policy explains how Hello by Flow uses cookies and similar tracking technologies.
What we use
Strictly necessary (always on)
- access_token — your authentication cookie (HttpOnly + Secure + SameSite=Lax). Set by our backend; not accessible to JavaScript. Required to keep you signed in.
- refresh_token — HttpOnly cookie used to rotate the access token every 15 minutes; 90-day lifetime.
- csrf_token — JS-readable cookie used by our frontend to mirror as
X-CSRF-Tokenon state-changing requests. - hbf_support_session_v1 — anonymous session ID for the Hello by Flow support chatbot. Stored in localStorage.
Functional
- UI preferences (dialer position, sidebar collapsed state).
Analytics
We use first-party, IP-anonymised analytics to count page views and identify performance issues. We do not use Google Analytics or any third-party advertising tracker.
Your choices
You can clear cookies in your browser settings at any time. Clearing strictly necessary cookies will log you out.
Do Not Track
We honour browser-level Do Not Track signals for the analytics bucket.
Contact
Questions: privacy@hellobyflow.com
← Back to home© 2026 HELLO BY FLOW
