Legal documents

Cookie policy

Last updated · 13 August 2026 · version 1.0

We use few cookies and we declare all of them. Technical cookies keep you logged in; everything else runs only if you accept it, and you can change your mind at any time from the banner.

1. What they are

Small files the site saves in your browser to remember something between one page and the next: the sign-in session, the chosen language, the consent you gave.

2. The four categories

Necessary: they make the site work and need no consent. Preferences: they remember how you like to see the site. Statistics: they measure visits in aggregate. Marketing: they measure advertising campaigns. Everything except the necessary ones runs only if you turn it on, and stays off until you do.

3. Giving and withdrawing consent

On your first visit a bar appears with three equivalent options: reject all, customise, accept all. Closing the bar with the X counts as rejecting. The choice lasts 180 days and you can change it at any time from the “Cookie preferences” link at the bottom of every page. If we update this policy, consent is asked again.

4. Consent record

To be able to demonstrate consent, as article 7.1 GDPR requires, we record the choice made: a random identifier, the categories enabled, the policy version, the date, your IP address without its last part, and the browser. Nothing that identifies you. The record is deleted after two years.

5. Third parties

Google Analytics through Google Tag Manager, for statistics. Stripe, which sets its own cookies on payment pages to prevent fraud. Both may process data outside the European Union on the basis of standard contractual clauses.

6. From your browser

Regardless of this banner, every browser lets you block or delete cookies from its settings. Deleting them also erases the memory of the choice made here, and the bar comes back.

7. Cookie list

This table is generated from the site configuration: it lists the cookies that are actually installed.

Name Purpose Duration Controller
ci_session Keeps the browsing session and the customer area sign-in open. 2 ore heythor.ai
csrf_cookie_name Protects forms from being submitted by third-party sites. Sessione heythor.ai
thor_device Recognises a device marked as trusted and reopens the customer area without signing in again. 30 giorni heythor.ai
thor_consent Remembers the choice made on this banner, so it is not asked at every visit. 180 giorni heythor.ai
_ga, _ga_* Google Analytics: measures visits in aggregate. Runs only with consent to the Statistics category. 13 mesi Google
__stripe_mid, __stripe_sid Fraud prevention on payment pages. Set by Stripe when a purchase starts. 1 anno / 30 min Stripe

For any question about your data, write to privacy@heythor.ai.

Draft to be validated with legal counsel before publication · fields in square brackets must be filled in