Essential cookies
- __Host-crowdalpha_session: secure, host-only, HttpOnly API session cookie used in production to keep you signed in.
- __Host-crowdalpha_oauth_state: short-lived, host-only OAuth state cookie used during Google sign-in.
- __Host-crowdalpha_magic_binding: short-lived, host-only cookie that binds a magic link to the browser that requested it.
- crowdalpha_csrf: API-host compatibility token for non-browser cookie clients. The CrowdAlpha web app uses exact first-party Origin validation for state-changing requests and cannot read API-host cookies.
Local storage
Dashboard filters, dismissed onboarding banners, and local dispatch drafts may be stored in your browser. JWTs are not stored in local storage.
Analytics
CrowdAlpha does not currently set non-essential analytics or advertising cookies.