Privacy & cookies

Coaptive ships a Privacy page at /legal/privacy. Visitors reach it from the Legal page. The cookie banner’s default policy link is the same path.

You cannot edit, duplicate, or delete it, and the slug stays privacy so that address keeps working. Legal is locked the same way; Hide on that row only controls the footer link.

Cookies the software sets

The session cookie is an id. Names, email, and records stay on the server.

CookieWhenWhat it contains
{app}-sessionEvery visit that starts a sessionEncrypted session id. On Coaptive Core the name is coaptive-core-session (this host only, 24 hours idle). On Coaptive GME it is coaptive-session (shared with .coaptive.dev).
XSRF-TOKENWith the sessionEncrypted form-protection token. It does not identify the visitor.
remember_web_59ba36addc2b2f9401580f014c7f58ea4e30989dRemember me on loginEncrypted user id, remember token, and a hash of the password hash. Lasts 400 days.
coaptive_localeCMS language switcher onlyA language code. Not set on GME. Lasts 1 year.
coaptive_consentAfter the visitor answers the cookie bannerWhether analytics and marketing were allowed. Lasts 1 year. Written only when the banner is enabled.

Banner and analytics

Tools → Privacy & Consent turns the banner on, sets the policy URL, and enables Google Consent Mode v2 when Google Analytics or Tag Manager is on. Settings live in storage/app/private/privacy-settings.json.

System → Analytics can add Google Analytics 4, Tag Manager, Hotjar, Microsoft Clarity, Meta Pixel, PostHog, Matomo, Umami, Plausible, or Fathom. Those tools are off until you enable them. With the banner on, non-Google tags stay blocked until the visitor accepts analytics or marketing.

Not cookies

Appearance (coaptive.color_mode) and the accessibility widget (coaptive.a11y) use this browser’s local storage.