02Why we use cookies
Tengu uses cookies to:
- keep you signed in across pages and reloads;
- refresh your session safely without re-prompting for your password;
- protect requests from cross-site forgery and other common attacks;
- remember your interface preferences (light / dark / Tengu theme, sidebar state, dismissed notices);
- measure how the product is used in aggregate so we can fix what is broken and prioritise what matters.
03Categories of cookies we use
Strictly necessary. These cookies are required for the Service to work and cannot be turned off in the product. Disabling them in your browser will break sign-in. They include:
- Access token — a short-lived, HTTP-only cookie that proves you are signed in for each request.
- Refresh token — a longer-lived, HTTP-only cookie that lets the access token be renewed without sending you back to the login screen. Each refresh token carries a unique identifier so we can revoke a single session without signing you out everywhere.
- CSRF token — used to confirm that state-changing requests came from a Tengu page, not from a malicious site.
Functional / preference. These remember choices you have made so the interface feels consistent on your next visit. They cover items such as theme, locale, last-viewed dashboard tab, and dismissed in-product notices. Disabling them will not break the Service, but you will see the default state on every visit.
Analytics. Where enabled, these help us understand product usage in aggregate — which pages users open, where errors occur, which features are unused. We configure analytics providers to operate under data-minimisation defaults (no precise location, IP masked or hashed where the provider supports it).
Third-party cookies. When you embed or open content from a third party inside Tengu (for example a market-data widget, an AI-provider login screen, or a payment processor’s checkout iframe), that third party may set its own cookies under its own policy. Tengu does not control those cookies.
04How to manage cookies
Every modern browser lets you view, block, or delete cookies. The steps differ by browser but the controls are usually in “Settings” → “Privacy and security.” You can also use private / incognito mode to start each session with a clean cookie store.
If you block strictly-necessary cookies, you will not be able to stay signed in to Tengu. If you block functional cookies, your preferences will reset on each visit. If you block analytics or third-party cookies, the Service will still work but we will have less visibility into errors and usage patterns.
Where a regional regime (EEA, UK, certain U.S. states) requires it, we present a cookie banner that lets you accept or decline non-essential cookies before they are set. Your choice is recorded and respected on future visits.
05Do Not Track and Global Privacy Control
Browsers can send a Do Not Track header or a Global Privacy Control (GPC) signal. There is no single industry-wide standard for how a site should react to Do Not Track. Where the GPC signal is legally recognised (for example, under California law), Tengu treats it as a request to opt out of any “sale” or “share” of personal information for cross-context behavioural advertising.
06Updates to this policy
We may update this Cookie Policy as the Service evolves — for example, when we add or remove an analytics provider. The current version is always reachable from the footer of every page, and the “Last updated” date at the top will reflect the most recent change.
07Contact
Questions about this Cookie Policy: support@tengu.co.