This Cookie Policy explains how makojima.com uses browser cookies and related device storage. Read it with the Privacy Policy.
Overview
A cookie is a small value a website asks a browser to return with later requests. Local storage is a separate browser feature that stays on the device and is not automatically sent with every request. Makojima uses these technologies for signed-in sessions, security, presentation preferences, and bounded public metadata caches.
The current Production Service does not use advertising cookies or create a cross-site behavioral advertising profile. A prototype or protected test environment does not define what the public Production Service stores.
Essential Session Cookies
Makojima's authentication service uses secure cookies to establish and refresh a signed-in website session. They let server-rendered pages and protected routes determine whether the request is authenticated and enforce account, credential-management, security, and database boundaries.
Blocking or clearing these cookies signs you out or prevents sign-in, Settings, Developer Access, API Activity, recovery, and application approval from working. Cookie values are not displayed as account identity and must not be placed in public content, analytics, or shared caches.
The public Model API does not authenticate with a website cookie. Native and server clients send an API key or application access token in the Authorization header.
Cookieless Analytics And Performance
Makojima uses Vercel Analytics and Speed Insights to measure aggregate website traffic, delivery, and Web Vitals without setting analytics cookies. These services can still process ordinary request and device context needed to deliver a page and calculate a metric, such as network address, user agent, route, timing, and coarse location.
We use this information to understand reliability and performance, not to build advertising profiles. Cookieless means the measurement does not depend on a persistent analytics cookie; it does not mean no technical request data is processed.
Analytics event properties must not contain prompts, generated results, search text, destination URLs, raw account or request IDs, email addresses, credentials, cookies, or local-storage values. Makojima does not use session replay for the current Service.
Local Device Storage
Production may store these device-level values:
- Theme Preference: the light, dark, or system choice for this browser.
- Navigation State: whether a navigation rail or search area is expanded.
- Public Metadata Cache: a bounded versioned copy of already-public model or page metadata used to render and refresh public content.
These values must not contain your name, email address, password, website session, API key, access or refresh token, authorization code, private request, generated result, two-factor data, or recovery material. Sign In with Makojima applications use their operating system or platform credential store, not makojima.com browser local storage, to persist application credentials.
Monitoring And Security Signals
Optional error monitoring may process scrubbed diagnostics when the website fails. Makojima's configuration removes user identity, cookies, request bodies, query strings, and common credential fields and keeps session replay and default personal-data collection disabled.
Bot and abuse controls process request and browser signals needed to protect sign-in, credential management, application approval, and the Model API. Security events generally use keyed pseudonymous identifiers. For denied requests and important authentication or credential events, Makojima may retain bounded forensic details as described in the Privacy Policy.
What We Do Not Use
The current Production Service does not use advertising cookies, third-party social-media tracking pixels, or cookies to sell or share personal information for cross-context behavioral advertising. It does not place Model API request content or credentials in analytics or browser storage.
If Makojima later adds a technology that requires consent, the public interface must provide the required notice and control before or when it is activated.
Your Controls
You can inspect, block, or delete cookies and site data in browser settings. Clearing session cookies signs you out. Clearing local storage resets presentation and navigation preferences and removes public metadata caches; it does not delete the server-side account, API keys, connected applications, requests, credits, or security records.
Privacy modes, content blockers, and enterprise policies may limit cookies or storage. Public legal text should remain readable, but signed-in features may not work. A third-party application controls its own protected credential store and sign-out behavior.
Changes And Contact
We will update this policy when Production storage or measurement practices materially change. Privacy and legal questions may be sent to legal@makojima.com. Technical support may be sent to hello@makojima.com. Do not send cookie values, credentials, passwords, two-factor codes, or recovery material by email.