1. Introduction
This Cookie Policy explains how Foreman ("we," "our," "us") uses cookies and similar tracking technologies on our website and platform. You can manage your preferences using our cookie consent controls.
2. What Are Cookies?
Cookies are small text files placed on your device when you visit a website. They are widely used to make websites work efficiently, remember preferences, and provide analytics.
3. How We Use Cookies
3.1 Strictly Necessary Cookies
These cookies are essential for the Service to function. They enable core functionality such as security, network management, and account access. You cannot opt out of these cookies.
Examples: The session authentication cookie (foreman_app_session) that keeps you signed in, and the short-lived sign-in cookie (oauth_state) used only during login. Cross-site request forgery is prevented using SameSite and same-origin request protections rather than a separate named token cookie.
3.2 Performance/Analytics Cookies
These cookies would help us understand how visitors interact with the Service by collecting aggregated, de-identified information.
We do not currently set any performance or analytics cookies. Non-essential cookie categories default to off, and no analytics or marketing cookie or storage item is written before you affirmatively opt in. If we later add an analytics vendor, we will name it in this policy and in the itemized list in Section 8, and it will remain disabled until you consent.
3.3 Functionality Cookies
These cookies allow the Service to remember choices you make and provide enhanced, personalized features.
Examples: Theme preference (light/dark mode) and view/density settings. This first-party preference storage is used only to run the app and remember how you like it configured; it stays on your device, is not shared with third parties, and does not involve profiling.
3.4 Advertising/Targeting Cookies
We do not use advertising cookies on our core platform. Any marketing site may use limited targeting for relevant content, but not for third-party advertising.
4. Third-Party Cookies
Some cookies are placed by third-party service providers who perform services on our behalf. These include:
- Payment Providers: Stripe (payment processing)
- Authentication Providers: Descope (identity verification) and Foreman session cookies
These third parties have their own privacy policies and cookie practices.
5. Cookie Consent Management
5.1 Consent Mechanism
We provide a fully accessible cookie consent banner that allows you to:
- Accept all cookies
- Reject non-essential cookies
- Customize cookie categories with toggle switches
- Withdraw consent at any time via "Cookie Settings" link in footer
- Access detailed explanations for each cookie category
5.2 Default Settings
By default, strictly necessary cookies are always enabled. Other categories require your explicit consent.
5.3 Managing Cookies
You can manage cookie preferences through:
- Our cookie consent banner with accessible modal interface
- "Cookie Settings" link in website footer to reopen preferences
- Browser settings (instructions below)
- Third-party opt-out tools
Consent preferences are stored in your browser's localStorage with a 1-year expiry. You can clear these at any time by clearing site data in your browser settings.
6. Browser Controls
Most browsers allow you to control cookies through their settings:
- Chrome: Settings > Privacy and security > Cookies and other site data
- Safari: Preferences > Privacy > Cookies and website data
- Firefox: Options > Privacy & Security > Cookies and Site Data
- Edge: Settings > Cookies and site permissions > Cookies and data stored
Note: Disabling cookies may affect the functionality of the Service.
7. Browser Privacy Signals
Foreman honors Global Privacy Control (GPC) signals by treating them as an opt-out of sale, sharing, and targeted advertising. When GPC is detected, analytics sharing and marketing/targeting cookies are disabled and the cookie preference interface displays that the opt-out was honored. Our Service does not currently respond to legacy Do Not Track signals separately from GPC.
8. Cookies and Local Storage We Use
The Service uses the first-party cookies and browser-storage items described below. All of them are either strictly necessary or functional (preference) storage; none are analytics or advertising. We do not load any third-party analytics or advertising cookies. Two third-party providers may set their own strictly-necessary cookies only at the moment you use their embedded flows: Descope during sign-in, and Stripe during checkout and payment (used by Stripe for payment processing and fraud prevention). Those cookies are governed by the providers' own privacy and cookie policies.
Strictly necessary (required to run the Service):
foreman_app_session (cookie) — Session authentication (keeps you signed in). Expires after 12 hours on the web; up to 30 days in the installed desktop app.fmn_active_ws (cookie) — Remembers which workspace is active so your requests are routed to it; re-validated against your workspace memberships on every request. Expires after 30 days.oauth_state (cookie) — Sign-in request protection, set only during login. Expires within minutes (10-minute maximum).foreman_cookie_consent and foreman_gpc_status (localStorage) — Record your cookie preferences and whether a Global Privacy Control opt-out was honored.foreman.composeDraft and foreman.replyDraft.* (localStorage) — Auto-save message drafts so you don't lose work in progress.foreman.remoteDevice.v1 (sessionStorage) — Maintains your remote-device session routing.foreman.queryCache.v1 (localStorage, desktop app only) — A short-lived snapshot of recently viewed workspace data so the desktop app opens instantly; refreshed continuously and replaced on each session.foreman_registration_dob and foreman_registration_us_residency (sessionStorage) — Hold your age and U.S.-residency confirmation during signup; cleared when registration completes.studio-thread-<projectId> and studio-mode-<projectId> (localStorage) — Your Studio chat thread drafts and mode, saved per project.foreman.activeWorkspaceSlug (localStorage) — Remembers which workspace you were last working in.
Functionality / preferences (remember how you like the app):
theme-mode (localStorage) — Your light/dark/auto theme preference.foreman.inboxDensity and foreman.inboxFamilyCollapsed (localStorage) — Your inbox layout density and collapsed channel groups.foreman.providerAlertsSeen (localStorage) — Which provider alerts you've already dismissed.foreman.remoteDevice.optout (sessionStorage) — Your choice to opt out of the remote-device view.crm.phoneMirror.<userId> (localStorage) — Your CRM phone-mirror preference.crm.outreachDefault.<userId>.<kind> (localStorage) — Your default outreach channel choices.foreman.reacceptEmailFired.<version> and foreman.reacceptBannerDismissed.<version> (sessionStorage) — Track whether you've been notified about or dismissed a terms re-acceptance notice.team-org-chart-zoom (sessionStorage) — Your zoom level on the team org chart.
These are first-party items stored on your device to run the Service and remember your preferences; they are not shared with third parties and are not used for profiling or advertising. You can clear them at any time by clearing site data in your browser settings. We review and update this list as our storage practices change.
9. Changes to This Policy
We may update this Cookie Policy periodically. We will notify you of material changes via email or in-app notice. Material changes to cookie practices will be reflected in our consent controls, which you can review and update at any time.