Agreement & reference

Draft

Cookie & tracking notice

What the Novexa Pilot app itself stores in your browser, and what the tracking snippet does on your customers’ sites.

Last reviewed
2026-08-26

1. Two different things this notice covers

First, the cookies novexapilot.com sets when you use this app yourself. Second, the behaviour of the np.js tracking snippet you install on your own website — which is a separate, much more limited, and off-by-default-on-storage system.

2. Cookies set by the Novexa Pilot app

A session/authentication cookie so you stay signed in, a CSRF-protection cookie, and a theme-preference cookie (light/dark/system). These are strictly necessary for the app to function and are not used for advertising or cross-site tracking.

3. What the tracking snippet does on your website

By default, the snippet sets no cookies and uses no device storage at all. A visitor is identified only by a hash that is salted and rotated every 24 hours, so it cannot be used to recognise the same visitor across days.

The snippet honours the domain’s configured consent mode: "off" sends nothing; "respect Do-Not-Track / Sec-GPC" (the default) checks the browser’s signal before sending anything; "strict consent" sends nothing until the site calls np('consent','granted'), which is intended for use with the site’s own cookie-consent banner.

4. Your choices

As a website visitor, you can set Do-Not-Track or Sec-GPC in your browser and any Novexa Pilot-instrumented site using the default consent mode will honour it. As the site owner, you control the consent mode from your domain settings, and can add a specific visitor or IP exclusion at any time, which stops future collection immediately.

You can clear or block the Novexa Pilot app’s own cookies through your browser settings; doing so will sign you out.

5. Changes

We will update this notice as tracking behaviour changes and note the date at the top.