Cookie Policy
Version 1.3 · Effective date: 12 September 2026 · Governing law: Scotland
Current position
AppGantry does not currently use browser analytics or advertising trackers. The marketing website uses only necessary cookies. Optional analytics will be consent-gated if introduced where required.
1 About cookies
Cookies are small text files stored by a browser. Similar browser storage may perform related functions. This Policy covers relevant AppGantry web properties, including www, the application, the admin UI, and the API only where a browser authenticates directly with the REST API or completes an applicable API-hosted authentication or SSO flow. These API cookies are not used by the normal server-side WebApp authentication path. This Policy also covers storage created conditionally by payment and abuse-prevention providers.
AppGantry uses necessary storage to remember privacy choices, maintain signed sessions, authenticate users and secure the Service. Necessary cookies do not require consent where they are strictly required to provide a requested service, but we still explain them here.
2 AppGantry cookies
| Name | Purpose | Provider | Duration | Category |
ag_consent |
Remembers cookie and privacy preferences. | AppGantry | About 180 days | Necessary/preference |
agwebapp_marketing_session |
Maintains security and continuity for a marketing-site session where needed. | AppGantry | Up to 14 days | Necessary |
agwebapp_app_session |
Maintains signed application session state where used. | AppGantry | Up to 14 days | Necessary |
agwebapp_admin_session |
Maintains signed administrative session state where used. | AppGantry | Up to 14 days | Necessary |
agwebapp_access |
Authenticates short-lived application requests. | AppGantry | About 30 minutes | Necessary |
agwebapp_refresh |
Securely refreshes application authentication. | AppGantry | About 30 days | Necessary |
agwebapp_logged_in |
Browser-readable, cross-subdomain signed-in marker used to coordinate the user experience; contains no account data. | AppGantry | About 30 minutes | Necessary |
ag_sso_state |
Short-lived SSO anti-CSRF and state protection for a browser-directed identity-provider flow. | AppGantry | About 10 minutes | Necessary/security |
dfdeveloper |
Authenticates a browser directly with the REST API during applicable API-hosted authentication or SSO flows. | AppGantry | About 10 minutes | Necessary |
dfdeveloper_refresh |
Refreshes direct browser authentication with the REST API during applicable API-hosted authentication or SSO flows; path-scoped to login and refresh endpoints. | AppGantry | Up to 30 days | Necessary |
In production, agwebapp_access and agwebapp_refresh are configured Secure, HttpOnly and SameSite=Lax. The agwebapp_logged_in marker is intentionally browser-readable, works across AppGantry subdomains, is necessary and contains no account data. ag_sso_state is Secure, HttpOnly and SameSite=None because an identity provider may return by cross-site POST. HttpOnly prevents browser scripts from reading protected cookies and Secure restricts transmission to HTTPS. In production, dfdeveloper and dfdeveloper_refresh are also Secure, HttpOnly and SameSite=Lax. The refresh cookie is path-scoped to the applicable login and refresh endpoints.
3 Conditional third-party storage
| Service | When and why used | Provider | Duration | Category |
| Paddle.js | Loaded on payment pages to provide checkout, payment security, fraud prevention, billing and tax functions. Paddle may set cookies or use browser storage under its own notices. | Paddle | Set by Paddle; varies by purpose | Necessary for checkout |
| hCaptcha | Loaded on sign-up or login only when abuse-prevention checks are enabled. It may use cookies or browser storage to distinguish legitimate use from automated abuse. | hCaptcha | Set by hCaptcha; varies by purpose | Necessary/security when enabled |
These providers may receive technical information such as IP address, user-agent, page context and interaction data needed for their function. Paddle may act as an independent controller for payment, fraud, tax and legal obligations. Their privacy notices provide further detail.
Where AppGantry pages load CDN assets from bunny.net, the asset request may transmit an IP address, user-agent and requested asset information. This delivery is not analytics and does not set AppGantry cookies.
4 Analytics and feature flags
We do not currently use browser analytics or advertising cookies. PostHog is used server-side for feature flags and does not capture browser analytics through cookies. If we later add optional browser analytics, we will update this table and obtain consent before activating it where law requires.
5 Managing choices
You can use our consent control, where shown, to review or change optional choices. You can also delete or block cookies through browser settings. Blocking necessary cookies may prevent sign-in, checkout, security checks or other requested features from working.
Some browsers transmit Global Privacy Control ("GPC") or similar preference signals. AppGantry honours GPC as rejection of optional cookies. We currently do not use browser analytics or advertising tracking, sell personal data, or share it for cross-context behavioural advertising, so there are presently no such optional activities to disable.
6 Changes and contact
We may update this Policy when cookies, providers or law change. The current version and effective date appear on the document. For questions, email contact@appgantry.com. Our Privacy Policy explains the wider handling of personal data.
Questions about this document? support@appgantry.com.