Scope
This Cookie Policy covers cookies used by the ElevateIQ web application (e.g., app.elevateiq.me) for authentication and security only. We do not set advertising cookies. Our public marketing pages do not set any cookies. They do run a one-time cleanup script that deletes a leftover eq_cookie_consent cookie from browsers that visited before September 2026, when we removed our cookie-consent banner.
What Are Cookies?
Cookies are small text files placed on your device by your browser at the request of a website. They are widely used to keep you signed in, enable site functionality, and protect your account.
How We Use Cookies (Login Only)
Note: We do not require CSRF tokens on the /auth/token, /auth/refresh, Passkey, SSO, and MFA verification endpoints. Those endpoints are unauthenticated or use a one-time flow. After you successfully authenticate, we set a CSRF cookie for state-changing requests inside the app.
Cookies We Set
| Cookie | Purpose | Type | Duration | Attributes |
|---|---|---|---|---|
| eq_access_token | Signed, opaque token that maps to your authenticated session. Keeps you signed in during an active session. Refreshed automatically when you're using the application. | Session (essential) | 15 minutes (rolling; refreshed automatically on activity) | Secure; HttpOnly; SameSite=Lax; Path=/; HTTPS only. |
| eq_refresh_token | Signed, longer-lived token used to automatically refresh your access token. Enables "Remember me" functionality across browser restarts. | Persistent (essential) | 7 days (30 days with "Remember me") | Secure; HttpOnly; SameSite=Lax; Path=/; HTTPS only. |
| eq_csrf_token | Cross-site request forgery protection token. Set after successful authentication. Used with a matching X-CSRF-Token request header on state-changing requests. |
Session (essential) | Matches refresh-token lifetime (7 or 30 days) | Secure; SameSite=Lax; readable by JavaScript (not HttpOnly); Path=/; HTTPS only. |
Session behavior
- Active use: the access token refreshes automatically while you're using the app.
- Inactivity: sessions expire after the refresh-token TTL (7 days, or 30 days for "Remember me").
- Logout: all three cookies are cleared server-side and immediately invalidated.
- Device tracking: basic device data (browser, platform, masked IP) is logged for security monitoring (separately from cookies).
Device Information Collection
For session security and audit logging, the application collects minimal device information at sign-in:
- Browser type (e.g., Chrome, Firefox, Edge)
- Platform (e.g., macOS, Windows)
- IP address, full address logged for security event correlation; a masked variant (network prefix only, e.g.
192.168.x.x) is stored alongside session data for privacy. - Timezone & language for user-experience.
We do not collect high-entropy fingerprinting identifiers like exact screen resolution, GPU info, or detailed browser-version strings. Device information is used solely for session security, suspicious-login detection, and improving the user experience.
Session Timeout
Your session will automatically expire after 7 days of inactivity, or 30 days if you selected "Remember me" during login. The access token is rotated automatically while you actively use the application; rotation pauses during periods of inactivity.
Data Retention
Session data is automatically deleted when:
- You explicitly log out.
- Your refresh token expires (7 days, or 30 days for "Remember me").
- You revoke the session from another device.
Audit and security event logs are separate from session data and are retained longer. They record the full client IP address, which is not truncated or anonymised. Ordinary entries are kept for 90 days by default; entries flagged as security events are kept for a minimum of 365 days. See the Privacy Policy for the full retention schedule.
Third-Party Cookies
We do not use analytics cookies, advertising cookies, or any other third-party tracking cookies, on our marketing pages or in the application. No analytics provider is loaded on any page.
Cookie Consent
We do not display a cookie-consent banner, because we set no cookies that require consent. The only cookies we set are the strictly necessary authentication cookies listed above, which are exempt from the consent requirement under the ePrivacy Directive because the Service cannot function without them.
If we ever introduce analytics or any other non-essential cookie, we will publish an updated policy and, in jurisdictions that require prior consent (including the EEA and UK under the ePrivacy Directive), we will ask for affirmative consent before any such cookie is set.
Your Choices
Because the authentication cookies above are strictly necessary, blocking them in your browser will prevent you from logging in to ElevateIQ. You may delete cookies at any time via your browser settings; you will be asked to sign in again.
Security
Authentication cookies are issued over HTTPS with Secure and HttpOnly flags and a SameSite=Lax policy. CSRF protection applies after authentication and uses a separate cookie paired with an X-CSRF-Token request header. The /auth/token, /auth/refresh, Passkey, SSO, and MFA verification endpoints do not require CSRF because they are unauthenticated or use a one-time, short-lived flow. Cookie values are signed and validated server-side, and session identifiers are rotated as appropriate (e.g., after MFA success).
Contact
Questions about this Cookie Policy? Contact support@elevateiq.me.
Effective Date: 2026-09-13