Last updated: July 1, 2026

Cookie Policy

Overview

This policy explains how Duct uses cookies and similar technologies on our marketing site (https://ductai.vercel.app), the dashboard, and embedded shell experiences. We do not use cookies for advertising or cross-site tracking.

What we use

Dashboard session (duct_session) — httpOnly cookie so company accounts stay signed in for up to 7 days. Cleared when you log out (the JWT is also revoked server-side) or when the session expires.

Admin session (duct_admin_session) — httpOnly cookie for authorized operators on /admin, also up to 7 days, cleared on sign-out.

Attribution (duct_attr) — first-party cookie on the marketing site so we know how visitors found us (UTM/referrer). Not used for advertising profiles.

Preference storage — the marketing site may store your audience toggle (founder vs developer view) in localStorage so your choice persists across visits.

Shell session storage — embedded shells may store a session identifier in localStorage or sessionStorage so a conversation can resume in the same browser.

Theme preference — light, dark, or system theme may be stored locally so the UI renders consistently on return visits.

What we do not use

We do not set third-party advertising cookies on the marketing site.

We do not sell cookie data or use it to build advertising profiles.

We do not embed third-party analytics trackers that follow you across unrelated sites.

Third-party cookies

When you configure bring-your-own-key LLM credentials, requests from the shell runtime go directly to your chosen provider under that provider's policies. Duct does not set cookies on behalf of LLM vendors.

Your choices

You can clear cookies and site data from your browser settings at any time. Clearing session cookies will sign you out of the dashboard or /admin.

Disabling essential cookies will prevent the dashboard from maintaining a signed-in session.

Embedded shells may not resume prior conversations if you block localStorage.

Changes

We may update this policy when our storage practices change. Material updates will be reflected in the "Last updated" date above.

Contact

Questions about cookies or browser storage? Use the support page.

See also: Privacy Policy · Terms of Service