Cookie Policy
Last updated: 2026-07-01. Policy version: 2026-08.1.
What this policy covers
This policy explains how GovSecure AI uses cookies, local storage entries, and third-party scripts. It lists every technology we use, what category it falls into, its purpose, and how long it persists. You can change your preferences at any time using the Cookie Preferences link in the footer.
Cookie categories
Strictly Necessary
Required for the site to function. You cannot opt out of these — without them, you cannot sign in or stay signed in.
Analytics
Help us understand how the site is used so we can improve it. Loaded only after you consent to analytics.
Preferences
Remember your UI choices (theme, locale). Optional — the site works without them.
Marketing
Third-party ad pixels and retargeting. Currently unused — no marketing cookies are loaded.
Full cookie inventory
Strictly Necessary
| Name | Type | Purpose | Duration | Domain |
|---|---|---|---|---|
| govsecure-consent | localStorage | Stores the user's cookie-consent decision (categories bitmask + policy version) so we can remember the choice across page loads. | 180 days | First-party |
| authjs.session-token | cookie | NextAuth v5 session cookie — required for authenticated requests. Without it the user cannot sign in or stay signed in. | Session | First-party |
| __Host-authjs.csrf-token | cookie | Auth.js CSRF-protection cookie — binds authentication form requests to this browser and prevents cross-site request forgery. | Session | First-party |
| __Secure-authjs.callback-url | cookie | Auth.js return-path cookie — remembers the safe first-party page to open after authentication completes. | Session | First-party |
Analytics
| Name | Type | Purpose | Duration | Domain |
|---|---|---|---|---|
| https://www.googletagmanager.com/gtm.js | script_load | Google Tag Manager container script. Loaded only after the user consents to analytics. | N/A | googletagmanager.com |
| _ga | cookie | Google Analytics 4 first-party cookie for client-id. Set only when the GA4 tag fires, which requires analytics consent. | 730 days | First-party |
| dataLayer | localStorage | GTM/dataLayer is a plain JS array attached to window. It is created regardless of consent (it must exist before Consent Mode pushes its default-denied state), but event emission through it is gated on analytics consent. | Session | First-party |
Preferences
| Name | Type | Purpose | Duration | Domain |
|---|---|---|---|---|
| theme | localStorage | next-themes persists the user's UI theme preference (light / dark / system) across sessions. | 365 days | First-party |
Marketing
No cookies in this category.
Managing your preferences
You can change your cookie preferences at any time by clicking Cookie Preferences in the footer. You can also clear cookies in your browser settings. See our Privacy Policy for more information about how we handle your data.
Policy version history
- 2026-07.1 (2026-07-01): Initial consent system. Categories: strictly_necessary, analytics, preferences, marketing. GPC honoured. Google Consent Mode v2 default-denied.
- 2026-08.1 (2026-08-15): Documented Auth.js CSRF and callback cookies and changed Google Tag Manager to load only after Analytics consent.