Cookie Policy
Last updated 2026-07-19
This policy covers cookies and similar storage on hosted.devdocs.ai (the apex marketing site and account dashboard) and explains what workspace documentation hosts do differently.
Workspace subdomains (for example, acme.hosted.devdocs.ai) do not set non-essential HTTP cookies and do not show a DevDocs cookie banner. A visitor to a workspace's documentation site is there for that workspace's brand, not ours, and the workspace operator is the controller of that site under our data processing agreement with them. Putting a DevDocs cookie banner on their branded domain would misattribute who is asking for consent.
Workspace hosts may still use first-party browser storage that is strictly functional for the product: a theme preference and reader chat history (including a local visitor token for multi-session chat) in local storage on that host only. That data stays in the visitor's browser, is not a third-party ad cookie, and is not shared across workspaces. Server-side workspace analytics record aggregate page views without setting cookies and without storing raw IP addresses (see the Privacy Policy).
1. Essential storage on the apex (no consent required)
These are strictly necessary for the Service to function on hosted.devdocs.ai and are exempt from consent requirements:
- Session cookie: keeps you signed in to your account. Host-only to hosted.devdocs.ai (no Domain attribute that would share it with workspace subdomains), HttpOnly and Secure where the browser supports it.
- Consent preference cookie (hd_consent): remembers accept or decline so we do not ask again on every visit. Also host-only to hosted.devdocs.ai.
- Theme preference: light or dark appearance stored in local storage so the site matches your choice after reload. Functional only.
2. Non-essential storage on the apex (requires your consent)
The banner on hosted.devdocs.ai lets you accept or decline non-essential marketing analytics before that category is used:
- Aggregate marketing analytics: when enabled, helps us understand how the marketing site is used. Configured not to identify you individually where we can avoid it. If you decline, we do not load that category for your browser. If this category is not yet active in production, declining still records your preference for when it is.
We do not use advertising cookies or third-party ad trackers on hosted.devdocs.ai. Workspace documentation hosts never load DevDocs marketing analytics scripts.
3. Payment checkout (Stripe)
When you buy a plan or credit pack, we send you to Stripe-hosted Checkout to enter payment details. Stripe may set cookies on its own domains under Stripe's policies. Those are not DevDocs marketing cookies on hosted.devdocs.ai. After payment, Stripe notifies us so we can grant entitlements or credits. See the subprocessor list and Privacy Policy for how payment references are stored.
4. Error monitoring on the apex
The apex application may send error and performance events to our error-monitoring subprocessor (Sentry) so we can fix failures. That path is for reliability, not advertising. Workspace documentation hosts do not load that monitoring as a marketing tracker. See /legal/subprocessors.
5. Managing your choice
You can change your choice at any time using the Cookie preferences control in the site footer, or by clearing cookies for hosted.devdocs.ai in your browser and revisiting the site, which shows the banner again. Clearing site data for a workspace host removes local theme and chat history for that host only.
6. Contact
Questions about this policy can be sent to privacy@devdocs.ai.