01
The whole list
There is one cookie. Below it are the only other things AGA CRM keeps in your browser, and that is the complete inventory — not a summary of one.
| Name | What it is | What it does | How long it lasts |
|---|---|---|---|
| crm_refresh | Cookie — strictly necessary | Keeps you signed in. It holds a random value, not your details: the server stores only a SHA-256 hash of it, so the cookie says nothing about you even if it is read. It is HttpOnly, so no script can touch it, Secure, so it only travels over HTTPS, SameSite=Lax, and scoped to /api/auth, so it is not sent with ordinary page requests at all. | 30 days. Rotates every time it is used, and is revoked the moment you sign out or use “sign out everywhere else”. |
| crm_idle_logout | Session storage | A single “1”, set when a session ends for inactivity, so the sign-in page can tell you why you were signed out instead of leaving you guessing. It is deleted the moment the page reads it. | Until the tab closes, and usually a second or two. |
| crm_break_… | Session storage | Remembers that you put yourself on a break, so reloading the page does not quietly put you back on duty. Keyed to your user id and holds nothing else. | Until the tab closes or the break ends. |
| Your access token | Memory only — never stored | The token that authorises each request is held in a JavaScript variable and deliberately not written to local storage, where any script on the page could read it. Reloading the tab discards it and the app asks for a new one using the cookie above. | 15 minutes. |
03
What we deliberately do not do
This is a list of absences, which is harder to prove than a list of features, so each one is stated plainly enough to be held against us.
- No analytics of any kind. No Google Analytics, no tag manager, no product-analytics SDK, no heatmaps or session recording. We do not know which pages you visited.
- No advertising or conversion pixels, and no social media trackers.
- No third-party cookies, because there are no third-party scripts to set them.
- Web fonts are downloaded at build time and served from this domain, so loading a page does not tell a font provider that you were here.
- Server access logs record the usual request lines — IP address, time, path, response — and are kept to operate and secure the service, not to profile anyone.
- Two libraries we use for calling and live updates will read a debug flag out of browser storage if a developer has set one by hand. Neither writes anything on its own, and neither sets a cookie.
04
Turning them off
Every browser lets you block or delete cookies for a site, and the controls sit under Privacy or Site settings. Clearing them here is harmless: you will be signed out, and signing in again will set the one cookie again.
Blocking crm_refresh outright does not break the app in any dangerous way, but it does make it impractical — your session will end every fifteen minutes and you will be asked to sign in each time. Nothing else on the list can be blocked usefully, because session storage is cleared when you close the tab anyway.
Signing out, or using “sign out everywhere else” in your security settings, revokes the cookie server-side as well as deleting it. A cookie copied off your machine is useless afterwards.
05
Questions and changes
If something here does not match what you observe in your browser, we would genuinely like to know: write to info@agadigitaltech.com and we will either fix the page or fix the product.
Material changes to this notice are announced to workspace administrators by email, and the date at the top of this page always reflects the current version.
