Cookie Policy

How we use cookies and similar technologies on our website

2025/06/23

Last updated: June 23, 2025

Introduction

This Cookie Policy explains how FlowChart AI, a service operated by Chaowen Tan ("we," "our," or "us") uses cookies and similar technologies on our website and services. We are committed to being transparent about our cookie practices and complying with applicable privacy laws, including the EU ePrivacy Directive, GDPR, CCPA, and other international regulations.

By continuing to use our website, you consent to our use of cookies as described in this policy, except where your consent is specifically required for non-essential cookies.

What Are Cookies

Cookies are small text files that are stored on your device (computer, tablet, or mobile) when you visit a website. They are widely used to make websites work more efficiently and provide a better user experience. Cookies can be set by the website you are visiting ("first-party cookies") or by third-party services used by that website ("third-party cookies").

Types of Cookies by Duration

  • Session Cookies: Temporary cookies that are deleted when you close your browser
  • Persistent Cookies: Cookies that remain on your device for a specified period or until manually deleted

Types of Cookies by Purpose

  • Strictly Necessary: Essential for the website to function properly
  • Functional: Enhance functionality and personalization
  • Performance/Analytics: Help us understand how visitors use our website
  • Marketing/Advertising: Used to deliver relevant advertisements

Strictly Necessary Cookies

These cookies are essential for our website to function properly and cannot be switched off. They are usually set in response to actions you take, such as logging in or filling out forms.

Cookie NamePurposeDurationSet By
better-auth.session_tokenMaintains your login sessionSessionOur Website
better-auth.csrf_tokenProtects against cross-site request forgery attacksSessionOur Website
__Secure-authjs.session-tokenAlternative session managementSessionOur Website
__Host-authjs.csrf-tokenCSRF protection for authenticationSessionOur Website
next-i18n-cookieRemembers your language preference1 yearOur Website
cookie-consentRemembers your cookie preferences1 yearOur Website

Third-Party Authentication Cookies

These cookies are set by third-party authentication providers when you choose to log in using their services.

Google Login

Cookie NamePurposeDurationSet By
__Secure-1PSIDGoogle authentication and security2 yearsGoogle
__Secure-3PSIDGoogle authentication across domains2 yearsGoogle
HSIDGoogle security and authentication2 yearsGoogle
SSIDGoogle security identifier2 yearsGoogle
APISIDGoogle API authentication2 yearsGoogle
SAPISIDSecure Google API authentication2 yearsGoogle

Google's Privacy Policy: https://policies.google.com/privacy Data Location: United States and other Google data centers globally Legal Basis: Necessary for contract performance (login service)

GitHub Login

Cookie NamePurposeDurationSet By
_gh_sessGitHub session managementSessionGitHub
logged_inGitHub login status1 yearGitHub
dotcom_userGitHub user identification1 yearGitHub
_device_idGitHub device identification1 yearGitHub

GitHub's Privacy Policy: https://docs.github.com/en/site-policy/privacy-policies/github-privacy-statement Data Location: United States Legal Basis: Necessary for contract performance (login service)

Payment Processing Cookies (Creem)

These cookies are used to securely process payments and manage billing through our Merchant of Record.

Cookie NamePurposeDurationSet By
creem_sessionSecure payment session management30 minutesCreem
creem_customer_idCustomer identification for billing1 yearCreem
creem_checkout_stateMaintains checkout process stateSessionCreem
creem_csrfPayment security protectionSessionCreem

Creem's Privacy Policy: https://creem.io/privacy Data Location: Singapore, Estonia Legal Basis: Necessary for contract performance (payment processing)

These cookies enable enhanced functionality and personalization but are not strictly necessary.

Cookie NamePurposeDurationSet By
theme_preferenceRemembers your dark/light mode choice1 yearOur Website
canvas_settingsSaves your canvas and drawing preferences1 yearOur Website
user_preferencesStores various user preference settings1 yearOur Website
feature_flagsManages feature availability for your accountSessionOur Website
ai_chat_historyMaintains AI conversation contextSessionOur Website

These cookies help us understand how visitors interact with our website by collecting and reporting information anonymously.

Cookie NamePurposeDurationSet By
plausible_ignoreExcludes your visits from analytics (if opted out)PermanentPlausible
_pa_sessionTracks page views and user interactions24 hoursOur Analytics
_pa_userAnonymous user identification for analytics1 yearOur Analytics

Analytics Provider: Self-hosted Plausible Analytics Data Location: Our controlled infrastructure Privacy Features: No personal data collection, no cross-site tracking Legal Basis: Legitimate interest (with opt-out option)

These cookies are used when you interact with our AI-powered flowchart generation features.

Cookie NamePurposeDurationSet By
ai_session_stateMaintains AI conversation contextSessionOur Website
ai_usage_trackingTracks AI feature usage for billing30 daysOur Website
openrouter_sessionAPI session management for AI servicesSessionOpenRouter
flowchart_autosaveAutomatically saves your work in progressSessionOur Website

Third-Party AI Service:

Data Location: United States Legal Basis: Consent (for AI feature usage)

Hosting and Infrastructure Cookies

These cookies are set by our hosting provider for performance and security.

Cookie NamePurposeDurationSet By
__vercel_liveVercel deployment and performance trackingSessionVercel
_vercel_jwtVercel security and authenticationSessionVercel

Hosting Provider: Vercel Privacy Policy: https://vercel.com/legal/privacy-policy Data Location: Global edge network Legal Basis: Necessary for service provision

Email Service Cookies (Optional)

These cookies are used if you opt-in to email communications.

Cookie NamePurposeDurationSet By
resend_trackingEmail delivery and open tracking30 daysResend
email_preferencesYour email communication preferences1 yearOur Website

Email Provider: Resend Privacy Policy: https://resend.com/privacy Data Location: United States Legal Basis: Consent (for email communications)

Strictly Necessary Cookies: No consent required, but we inform you about their use.

Non-Essential Cookies: We obtain your consent through:

  1. Cookie Banner: Displayed on your first visit with clear options
  2. Granular Control: You can accept/reject different cookie categories
  3. Informed Choice: Clear information about each cookie type before consent

You have several options to manage cookies:

2. Browser Settings

Chrome: Settings > Privacy and Security > Cookies and other site data Firefox: Settings > Privacy & Security > Cookies and Site Data Safari: Preferences > Privacy > Manage Website Data Edge: Settings > Cookies and site permissions > Cookies and site data

3. Third-Party Opt-Outs

  • Google: https://adssettings.google.com/
  • GitHub: Account Settings > Privacy
  • Creem: Contact Creem support for opt-out options
  • OpenRouter: Manage through your OpenRouter account settings

You can withdraw your consent at any time by:

  1. Updating Preferences: Use our Cookie Settings page
  2. Clearing Cookies: Delete cookies through your browser
  3. Contacting Us: Email support@flowchartai.org
  4. Re-visiting Banner: Clear your consent cookie to see the banner again

Important: Withdrawing consent may affect website functionality and your user experience, particularly for AI features and canvas functionality.

International Compliance

European Union (GDPR + ePrivacy Directive)

  • We obtain explicit consent for non-essential cookies
  • You can withdraw consent at any time
  • We provide detailed information about each cookie
  • We respect your right to object to cookie processing

United Kingdom (UK GDPR + PECR)

  • Similar to EU requirements with additional UK-specific considerations
  • You can complain to the ICO about cookie practices
  • We follow ICO guidance on cookie consent

California (CCPA/CPRA)

  • Some cookies may be considered "personal information"
  • You have the right to opt-out of the "sale" of personal information
  • We do not discriminate based on your privacy choices
  • Note: We do not sell personal information to third parties

Other Jurisdictions

We comply with applicable cookie and privacy laws in all jurisdictions where we operate, including Canada (PIPEDA), Brazil (LGPD), and Australia (Privacy Act).

We implement appropriate security measures for cookies:

Technical Safeguards

  • Secure Flag: Sensitive cookies are only transmitted over HTTPS
  • HttpOnly Flag: Prevents client-side script access to sensitive cookies
  • SameSite Attribute: Protects against cross-site request forgery
  • Encryption: Sensitive cookie data is encrypted

Data Protection

  • Minimal Data: We only store necessary information in cookies
  • Regular Cleanup: Expired cookies are automatically removed
  • Access Controls: Strict controls on who can access cookie data
  • Monitoring: Regular security audits of cookie practices

We may update our Cookie Policy from time to time. We will notify you of any changes by posting the new Cookie Policy on this page and updating the "Last updated" date.

Contact Us

If you have any questions about this Cookie Policy, please contact us:

For specific questions about third-party cookies, please refer to the respective privacy policies of our service providers.