Legal TermsContentsXVAPI

Cookie Policy

This page explains the cookies and browser storage currently used by the live XVAPI service, why those items exist, how they are categorized, and what users should expect when storage is cleared or limited.

Effective
June 1, 2026
Storage posture
Necessary + functional only
Support
ops@xvapi.com

Related Documents

Necessary
7 active
Authentication, OAuth state checks, two-factor verification, and remembered storage-preference choices.
Functional
3 active
Sidebar preferences, dismissed notices, and browser-local continuity for selected user workspaces.
Not active
Analytics / Ads / Replay
The live public storage inventory does not currently declare those categories as enabled.

Storage inventory

Cookies and browser storage in use

The following table reflects the live storage inventory used by the public site and customer-facing account flows.

10 active items

Strictly necessary

Required to keep sign-in, OAuth checks, session continuity, and directly requested account features functioning correctly.

northstar_session

Cookie

Category

Strictly necessary

Purpose

Keeps the signed-in session active across the customer console and account flows.

Retention

Up to 7 days

northstar_oauth_state

Cookie

Category

Strictly necessary

Purpose

Protects OAuth login and account-binding flows against invalid or mismatched state.

Retention

Up to 10 minutes

northstar_2fa_pending

Cookie

Category

Strictly necessary

Purpose

Temporarily carries state while a user completes two-factor verification.

Retention

Up to 5 minutes

northstar_cookie_preferences

localStorage

Category

Strictly necessary

Purpose

Remembers the user's storage-preference choice so the site can keep respecting necessary-only or functional-enabled mode.

Retention

Until cleared or overwritten

xvapi.image-studio.gallery.<account>

localStorage

Category

Strictly necessary

Purpose

Stores the current browser-only image studio gallery for the signed-in account so generated images can survive refresh in the requested workspace.

Retention

Until cleared or overwritten

xvapi.image-studio.api-key.<account>

localStorage

Category

Strictly necessary

Purpose

Stores the user-supplied image-studio API key in this browser so the requested workspace can reconnect after refresh.

Retention

Until cleared or overwritten

xvapi.image-studio.key-name.<account>

localStorage

Category

Strictly necessary

Purpose

Stores the browser-local display name for the currently connected image-studio key so the requested workspace can reconnect after refresh.

Retention

Until cleared or overwritten

Functional

Used for interface preferences, notice state, and local continuity features that improve product usability.

northstar.console.sidebar

localStorage

Category

Functional

Purpose

Remembers the customer console sidebar preference.

Retention

Until cleared or overwritten

northstar_notice_read_signature

localStorage

Category

Functional

Purpose

Remembers that the current public notice has already been dismissed or read.

Retention

Until cleared or a newer notice replaces it

xvapi.image-studio.pending-batch.<account>

localStorage

Category

Functional

Purpose

Temporarily stores an interrupted multi-image generation so the browser can offer recovery after refresh.

Retention

Until recovery completes, is cleared, or functional storage is turned off

01

How storage is classified on this site

XVAPI separates storage into strictly necessary items and functional items. Strictly necessary items are required to keep authentication, account protection, and directly requested product workflows running correctly.

Functional items are used for convenience features such as remembering interface state, dismissed notices, and browser-local continuity for user-requested workspaces.

02

What is not currently enabled

The current site does not describe active analytics pixels, behavioral replay tools, advertising storage, or marketing-only browser identifiers as part of the live public storage inventory.

If that storage posture materially changes, this page and the related consent behavior should be updated before those categories are treated as active public functionality.

03

User controls and operational consequences

Users can clear cookies and local storage through browser settings at any time. Clearing necessary items may sign the user out or interrupt verification and account-recovery flows.

Clearing functional storage may reset sidebar preferences, notice state, and browser-local workspace continuity, including local image-studio recovery data where that feature is enabled.