Cookie Policy
How Yaha AI Platforms Private Limited uses browser storage and third-party services across our website, console, and related web apps. Effective date: September 1, 2026.
Overview
Yaha AI Platforms Private Limited ("Yaha") uses browser storage (including cookies, localStorage, and sessionStorage) to operate Yaha AI Gateway. This policy covers our marketing website (yahagateway.io), web console (app.yahagateway.io), documentation, and blog.
We do not set first-party HTTP cookies for tracking or advertising. Most of our storage is strictly necessary to authenticate you, process payments, and keep the service running.
What we don't use
We do not use marketing, advertising, or analytics cookies such as Google Analytics, Meta Pixel, or similar trackers. We do not sell data collected through browser storage.
Third-party services
Some features rely on trusted third parties that may set their own cookies or process data on their domains:
- Cloudflare Turnstile: bot protection during sign-up. See Cloudflare's privacy policy at cloudflare.com/privacypolicy.
- Razorpay: payment processing when you subscribe or refill your wallet. You are redirected to razorpay.com; their cookies and privacy policy apply on their site. See razorpay.com/privacy.
How to control storage
You can clear localStorage and sessionStorage through your browser settings. Clearing auth storage will sign you out of the console. Signing out also removes session tokens and workspace scope from your browser.
You can unregister service workers through your browser's developer tools or site settings. Razorpay and Turnstile cookies are managed on their respective domains.
Contact and updates
Questions about this policy? Contact Yaha AI Platforms Private Limited at [email protected].
We may update this policy from time to time. Material changes will be reflected in the effective date above. The Services are not directed at anyone under 18.
Storage we use
The table below lists browser storage and third-party services used across our web apps. For how we handle personal information more broadly, see our Privacy Policy.
| Name | Category | Mechanism | Duration | Purpose | App |
|---|---|---|---|---|---|
| yaha-ai-gateway-auth | Strictly necessary | localStorage | Until sign-out or cleared | Keeps you signed in to the console | Console |
| yaha:gateway-key:{projectId} | Strictly necessary | sessionStorage | Browser tab session | Temporarily holds a gateway key shown after creation | Console |
| oauth_pkce_verifier | Strictly necessary | sessionStorage | OAuth flow only | Secures OAuth authorization code exchange (PKCE) | Console |
| nova-impersonation-backup-token | Strictly necessary | sessionStorage | Impersonation session only | Fallback token for superadmin impersonation | Console |
| Cloudflare Turnstile | Strictly necessary | Third-party script | Sign-up session | Bot protection on account registration (when enabled) | Console |
| Razorpay hosted checkout | Strictly necessary | Third-party redirect | Payment session | Processes subscriptions and wallet refills | Console |
| theme | Functional | localStorage | Until cleared | Remembers light or dark mode preference | All web apps |
| yaha-sub-org | Functional | localStorage | Until sign-out or cleared | Remembers your selected workspace scope | Console |
| yaha_signup_plan | Functional | sessionStorage | Sign-up flow only | Carries plan selection from the marketing site | Console |
| yaha-sw-reload | Functional | sessionStorage | App update only | Prevents duplicate reloads after service-worker updates | All web apps |
| Service worker (/sw.js) | Functional | Browser cache | Until updated or unregistered | Delivers app updates in the background | All web apps |
© 2026 Yaha AI Platforms Private Limited. All rights reserved.