Transparent Storage Practices
Flozo is designed with privacy-first principles. We do not use third-party advertising cookies, behavioral tracker scripts, or cross-site data broker pixels. We use only strictly necessary session tokens, essential preference storage, and encrypted local databases needed to run the messaging service.What Are Cookies & Local Storage?
Cookies are small text files placed on your device by websites or web applications that you visit. Alongside traditional HTTP cookies, modern web and mobile applications use client-side storage technologies such as LocalStorage, SessionStorage, IndexedDB, and on mobile, encrypted Hive / Keystore databases.
In this policy, the term “Cookies” collectively refers to HTTP cookies, JWT authentication headers, and all localized caching technologies used to make Flozo function smoothly.
Why Flozo Uses Cookies
Flozo relies on localized storage mechanisms for the following primary purposes:
Keeping your session active so you do not have to verify via OTP on every page transition or message send.
Protecting your session against unauthorized cross-site requests, clickjacking, and token hijacking.
Caching recent channel messages and contact rosters in local storage so you can review conversations even with weak connectivity.
Remembering your selected workspace, sidebar toggle state, and notification preference flags.
Categories of Cookies We Use
These are required for Flozo to operate. Without these cookies, you cannot log into your account, send encrypted messages, or establish secure WebSocket connections to the messaging gateways.
These remember your workspace preferences, such as selected organization tabs, active channel views, audio mute toggles, and UI language.
Aggregated, anonymous telemetry (via Firebase Crashlytics) to measure app load latency, crash frequency, and network reconnect rates. None of this telemetry contains message content or personally identifying data.
Detailed Cookie & Storage Inventory
The table below provides a full inventory of the tokens and local storage keys used across Flozo web and mobile applications:
| Key / Cookie Name | Type & Storage | Purpose | Duration |
|---|---|---|---|
| flozo_session_jwt | Essential (Secure Enclave / HttpOnly Cookie) | Stores verified authentication token for encrypted API requests | Session / 30 Days (Cleared on Logout) |
| flozo_csrf_token | Essential (Secure Cookie) | Protects against Cross-Site Request Forgery attacks | Session duration |
| flozo_device_id | Essential (Hardware Storage) | Validates legitimate device login and handles push routing | Persists until app uninstall |
| flozo_ui_prefs | Preference (LocalStorage) | Stores user interface state: collapsed sidebar, sound alert toggles | 1 Year |
| hive_chat_cache | Functional (Encrypted Local Database) | Caches chat messages locally for instant render and offline reading | Cleared on manual cache wipe or logout |
Third-Party Cookies & Ad Tracking
How You Can Manage & Block Cookies
Most web browsers allow you to control cookie settings through their preferences. You can configure your browser to reject all cookies or notify you when a cookie is placed:
Consequences of Disabling Cookies
Policy Updates & Contact Us
We may update this Cookie Policy from time to time to accommodate new features or regulatory requirements. Any adjustments will take effect upon posting with an updated revision date.
Have inquiries regarding our use of storage tokens?
