Cookie & Browser Storage Policy

Effective date: July 29, 2026

Orbiton Inc. ("Orbiton", "we", "us") provides an AI-powered investor relations chat that public companies embed on their own websites, plus chat and research surfaces on our own domain. This page explains, in plain language, everything the chat can store in your browser, what each item is for, how long it lasts, and what consent is required before it appears. It supplements our Privacy Policy.

First, what we do not do

  • We set no HTTP cookies. The chat uses browser storage (localStorage and sessionStorage) only. EU ePrivacy rules treat browser storage the same as cookies, so we apply the same consent standards to it.
  • No advertising or cross-site tracking. There are no third-party ad cookies, no data sale, and no tracking of you across unrelated websites. Identifiers below are scoped to the specific company site and chat you use.

Consent tiers

Storage is gated by a three-tier consent model. The chat itself works at every tier — consent controls what is stored, not whether you can use the chat.

  • Tier 0 — Minimal: no consent given. Nothing is stored; any state lives in page memory and disappears when you leave.
  • Tier 1 — Session: you engage with the chat. Session-scoped items only (cleared when the browser tab session ends); your conversation works, but no persistent identifier and no analytics.
  • Tier 2 — Full: you explicitly consent (pre-chat card, the site's cookie banner, or its consent management platform). A persistent identifier enables cross-visit chat history and first-party analytics for the company whose site you are visiting.

Storage on the company's website (the embedded widget)

These keys can be set by the chat widget on the investor-relations site you are visiting:

Key Type Purpose Duration Appears at
profileIdentifier localStorage Random anonymous visitor identifier. Links your page visits and chat history for the company whose site you are on; contains no personal details itself. Until consent is withdrawn or you erase your data Tier 2
orbiton_consent_<company> localStorage Your consent decision itself: tier, policy version, timestamp, and how it was given. Written only when you make an explicit choice. Until changed or withdrawn Any explicit decision
orbiton_tc_consent_<company> localStorage Legacy terms-banner decision from older embeds; migrated into orbiton_consent_* on first read. Until migrated or withdrawn Explicit banner decision (legacy)
orbiton_prechat_<company> sessionStorage Receipt that you accepted the pre-chat consent card, so the card is not shown again during the same browsing session. Browser session Card accept
orb_session_id, orb_last_activity_ms sessionStorage Groups your page views into one visit for the company's analytics (a new session starts after 30 minutes of inactivity). Browser session Tier 1+
hasExistingChats localStorage / sessionStorage A yes/no flag ("true") so the widget can offer to continue an earlier conversation. Stored persistently only at tier 2; session-only at tier 1; page memory below that. Follows its tier (persistent / session / none) Tier-routed
orbiton_chat_dismissed localStorage / sessionStorage Remembers that you closed the chat, so it does not automatically reopen. Tier-routed like the flag above. Follows its tier Tier-routed
__orbiton_storage_test__ localStorage Technical availability probe: written and immediately removed to detect blocked storage. Never holds data. Milliseconds Always (stores nothing)

Storage inside the chat window (chat.orbiton.app)

The chat itself runs in a frame on our domain. Browsers keep its storage separate from the host site's:

Key Type Purpose Duration Appears at
profileIdentifier localStorage The chat's copy of your anonymous visitor identifier, so your conversation history can be retrieved on later visits. On consent-gated sites it is only used at tier 2. Until withdrawn or erased Tier 2 (gated sites)
chatId_<company> localStorage The id of your current conversation, so a page reload resumes the same thread instead of starting over. Until you start a new chat or erase data Using the chat
analyticsConsent_<company> localStorage Your answer to the in-chat analytics consent prompt ("granted"/"denied"), so you are not asked twice. Until changed or erased Explicit prompt answer
userEmail localStorage Stored only if you type your email into the chat (e.g. to retrieve past conversations or receive a transcript). Never collected automatically. Until you erase your data Explicit submission

Third-party scheduler embeds (Calendly / cal.com)

Some companies let you book a meeting with their team directly inside the chat. When that option is enabled and you click "Load scheduler", the chat loads a scheduling widget from Calendly or cal.com in its own frame. That widget is operated by the third party and may set its own cookies under its own policy — see the Calendly cookie notice and the cal.com privacy policy. Before you click, no request is made to either provider: the scheduler is never loaded automatically, so simply opening or using the chat sends nothing to Calendly or cal.com.

Withdrawing consent and erasing data

  • Through the site's cookie tool: if the company's website runs a consent banner or CMP, rejecting or withdrawing analytics consent there tears down our storage automatically — the persistent identifier and every Orbiton key above are erased from the site, and tracking stops immediately. The chat stays available.
  • Through the chat: the chat's data controls let you withdraw consent and request deletion of your stored conversations, analytics, and contact details from our servers. Deletion requests are honored without needing an account.
  • Manually: clearing your browser's site data for the company's website and for chat.orbiton.app removes every key listed here.

Each consent grant and withdrawal is also recorded server-side (decision, policy version, timestamp) as an audit trail, as described in our Privacy Policy — which also covers retention periods for server-side data such as conversations and analytics.

Changes to this page

When we add, rename, or re-scope a storage key, we update this page and its effective date. Material changes to what consent covers are versioned — your stored decision records the policy version it was given under.

Contact

Questions about this policy: privacy@orbitonfinancial.com.