Cookie Policy
What cookies and local storage Chordize AI uses, why we use them, and how you can control them.
1. What are cookies and similar technologies?
A "cookie" is a small text file that a website stores on your browser. "Local storage" and "session storage" are similar mechanisms used by modern web apps to keep small amounts of data on your device. In this policy we refer to all of these as "cookies" for simplicity.
Chordize AI uses cookies to sign you in, secure the Service, remember your settings, and prevent abuse. We do not use cookies to build advertising profiles.
2. Categories of cookies we use
| Category | Purpose | Legal basis (EEA/UK) |
|---|---|---|
| Strictly necessary | Signing you in, keeping your session, protecting against cross-site request forgery, remembering that you accepted our Terms during a signup or checkout flow. | Necessary for the service you requested — no consent required. |
| Security & anti-abuse | Cloudflare Turnstile challenge tokens to distinguish humans from automated abuse; abuse-detection identifiers used to rate-limit or block harmful behaviour. | Legitimate interests — protecting the Service. |
| Preferences | Remembering your selected AI model, minimum-input-words setting, saved custom prompt, and whether you use AI-detection. | Necessary for the service you requested where you are signed in; otherwise consent. |
| Performance & diagnostics (optional) | Anonymous or pseudonymous metrics to help us understand which features are used, page load times, and error rates. This category is off by default in the EEA/UK and only runs after you accept. | Consent. |
3. Specific cookies and storage entries
The list below is a representative summary. Actual names and values may change as we ship updates.
| Name / key | Type | Purpose | Duration |
|---|---|---|---|
| Authentication session cookie (name may vary) | Secure HttpOnly cookie | Maintains your authenticated session. JavaScript on the website cannot read this cookie. | Until sign-out or expiry. |
| Session-security cookie or control (name may vary) | Cookie and/or request security metadata | Helps protect authenticated sessions against cross-site request forgery and related abuse, where enabled. | Session or short-lived. |
| Account preferences | Server-side account storage | Stores your selected AI model, minimum input words, custom prompt, and AI-detection preference. | Until changed, reset, or the account is deleted, subject to our retention practices. |
| Optional account location | Encrypted server-side account storage—not a cookie or browser-storage entry | When you separately enable “Use my location,” stores a rounded, encrypted location payload. The website receives only status and expiry information when displaying the setting. | Up to 30 days from capture, unless refreshed; deleted when you turn the setting off. |
cz_cookie_consent | localStorage | Records your cookie-banner choice and the version of the policy in force at the time. | 12 months. |
| Cloudflare Turnstile tokens | Cookie / storage set by Turnstile | Anti-abuse challenge as part of sign-in and sign-up. See Cloudflare's privacy policy. | Short-lived (usually minutes). |
| Stripe cookies (during checkout only) | Third-party cookies on checkout.stripe.com | Set by Stripe when you are on the payment page for fraud detection and payment processing. See Stripe's privacy policy. | Set on Stripe's domain, not ours. |
4. How to manage cookies
You can control cookies in the following ways:
- Cookie banner: in the EEA, UK, and other regions where consent is required, we display a cookie banner on your first visit. You can accept all optional cookies, accept only the essential ones, or customize your choice. You can change your choice later at any time by clicking "Cookie settings" in the website footer.
- Browser settings: most browsers let you delete existing cookies, block new cookies, or block all cookies. If you block strictly necessary cookies, sign-in, checkout, and other core features may stop working.
- Signing out: signing out clears your authentication cookie.
5. "Do Not Track" and Global Privacy Control signals
Because we do not use cookies for cross-context behavioural advertising and do not sell personal information, browser "Do Not Track" and "Global Privacy Control" (GPC) signals do not change our behaviour today. If we ever add cookies that would trigger those signals, we will honour them where required by law.
6. Third-party services
Some cookies may be set by third-party services we use to run the Service, including Cloudflare (anti-abuse) and Stripe (payments). These services set their own cookies subject to their own privacy notices, linked above.
7. Changes
We may update this Cookie Policy from time to time. The updated version will be posted on the website with a new effective date. If material cookies change, we may re-prompt the cookie banner or notify you inside the Service.
8. Contact
Questions about this policy: support@chordize.com
Mailing address: #1219, 39 Niagara Street, Toronto ON M5V 0T6, Canada.