Back to home

Cookie Policy

This page lists every cookie BoltAI actually sets on your browser. We try to keep the list short — only what is required for the service to work, plus one short-lived referral tracker we set when a partner sends you to the signup page.

Strictly necessary

admin_session — set when an operator signs into the BoltAI admin dashboard. Without it you cannot reach the admin pages at /admin. It is HttpOnly (not readable by JavaScript) and only exists on browsers that have actually logged in. If you never visit /admin, you will never see it.

Authentication

We use the better-auth library to handle sign-in. It sets its own session cookie when you are logged into a BoltAI account. The exact cookie name, flags, and lifetime are chosen by the library, not by us — they are standard “Strict" or “Lax" cookies scoped to this site. If you are signed out, the cookie is gone.

Referral tracking (optional)

referral_code — a short-lived cookie we write when you land on the signup page with a ?ref=… query parameter (for example, from a partner link). The cookie remembers who sent you, gets attached to your new account at signup, and is then deleted. We do not put anything else in it, and we do not share it with anyone outside BoltAI.

Analytics

Polsia analytics cookies are used only on deployments where the POLSIA_ANALYTICS_SLUG environment variable is set. If your deployment has it on, the analytics script reads anonymous page-view counts so we know which pages are useful. It does not identify you personally and we do not sell the data.

Questions about cookies?

If anything on this page is unclear, or you want to ask us to delete a tracker, email boltaiusa@polsia.app. We respond within 24 hours on business days.

We do not use cookies to advertise to you, ever.