Cookie Policy
Service / product: AIGov
Website: https://govbase.dev
Operator / controller: AIMLGov, s.r.o., company ID: 29742188, registered office at Příčná 1892/4, Nové Město, 110 00 Praha 1, Czech Republic
Legal and privacy contact: hello@govbase.dev
Version: 2026-07-24
Effective date: 2026-07-24
Last updated: 2026-08-17
1. About this policy
This Cookie Policy explains how AIMLGov, s.r.o. (“AIMLGov”, “we”, “us”) uses cookies and similar technologies when you use the AIGov service on govbase.dev (the “Service”).
It reflects the technologies present in the current AIGov dashboard implementation. It is not a consent banner and does not describe a preference centre: AIGov does not currently collect cookie consent through the Service, because the cookies described below are limited to authenticated or functional Service operation, and the analytics tools described below are configured without cookies.
This policy should be read together with the Privacy Policy. Where the Privacy Policy and this Cookie Policy both apply, the Privacy Policy addresses broader personal-data processing; this Cookie Policy focuses on cookies, browser storage, and related measurement technologies.
2. What cookies and similar technologies are
Cookies are small text files stored by your browser when a website or application sets them. They may be first-party (set by govbase.dev) or third-party (set by another domain).
Similar technologies include browser storage mechanisms such as localStorage and sessionStorage, and scripts that send technical measurement data without writing a cookie (sometimes called cookieless measurement).
AIGov does not use advertising cookies, behavioural profiling cookies, marketing cookies, social-media pixels, browser fingerprinting for advertising, Google Analytics, Google Tag Manager, or similar marketing trackers in the current implementation.
3. Technologies used by AIGov
Under the current configuration, AIGov may use:
- First-party HttpOnly cookies for authentication and, where used, team or tenant context.
- Browser
sessionStorageandlocalStoragefor limited functional purposes after user action. - Vercel Web Analytics and Vercel Speed Insights for traffic and performance measurement. These are active on the Service and, in the current AIGov configuration, do not set cookies by default.
- A redirect to Stripe Checkout when a user starts a purchase or subscription. Stripe may use cookies on Stripe’s own domain; AIGov does not embed Stripe.js on ordinary AIGov pages.
Anonymous visits to public pages (including this Cookie Policy) do not set the first-party authentication or team/tenant cookies described below.
4. Strictly necessary and functional cookies
The following first-party cookies are defined in the AIGov dashboard application. Team and tenant cookies may not be created unless the corresponding authenticated functionality is actually used.
Cookie table
| Name | Provider | Purpose | Category | Party | Duration | Path | Domain | Secure (production) | HttpOnly | SameSite | Cookie consent |
|---|---|---|---|---|---|---|---|---|---|---|---|
govai_dashboard_access_token | AIGov / AIMLGov, s.r.o. | Maintains an authenticated dashboard session and associates requests with the signed-in user. | Strictly necessary / authentication | First party | 7 days | / | Host-only for the AIGov service | Yes | Yes | Lax | Not based on cookie consent; necessary to provide the authenticated service requested by the user. |
govai_selected_team_id | AIGov / AIMLGov, s.r.o. | Stores the selected team context for the authenticated multi-team service where that functionality is used. | Functional and necessary for requested team-context functionality | First party | Browser session | / | Host-only | Yes | Yes | Lax | No separate cookie consent currently requested; used to provide the requested authenticated service functionality. |
govai_selected_tenant_id | AIGov / AIMLGov, s.r.o. | Stores the selected tenant context for the authenticated multi-tenant service where that functionality is used. | Functional and necessary for requested tenant-context functionality | First party | Browser session | / | Host-only | Yes | Yes | Lax | No separate cookie consent currently requested; used to provide the requested authenticated service functionality. |
Notes
- These cookies are not accessible to application-side JavaScript (
HttpOnly). - They are set with
SameSite=Laxand, in production, theSecureflag. - The authentication cookie is set after successful sign-in or sign-up and is cleared or expired on logout as implemented by the Service.
- Team and tenant cookies are optional relative to a first anonymous visit: they are only relevant when authenticated team/tenant context features are used.
AIGov has not enabled Vercel’s optional cookie-based analytics mode and does not treat vc-session-id (or any Vercel analytics session cookie) as an active cookie of the Service. Vercel technically supports optional cookie-based analytics functionality; that mode is not enabled for AIGov.
5. Browser storage
The following items are not cookies. They are browser storage keys used by the AIGov dashboard after relevant user actions.
sessionStorage — govai_dashboard_api_key
- Purpose: Temporarily stores a user-provided hosted API credential during the relevant dashboard workflow (for example billing or getting-started flows).
- Duration: Until the browser tab or session is closed, subject to browser behaviour.
- Access: Accessible to application-side JavaScript in that browser context.
- Caution: Do not enter sensitive credentials on shared or untrusted devices. Closing the tab or clearing session storage removes the value from that browser context.
localStorage — aiDiscovery:lastResult
- Purpose: Restores the most recent AI Discovery scan result for authenticated user convenience.
- Duration: Until overwritten by a later scan, removed by the application, or deleted by the user through browser storage controls.
- Access: Accessible to application-side JavaScript.
- Control: You can delete this entry using your browser’s site storage / local storage controls for govbase.dev.
6. Analytics and performance measurement
AIGov currently loads:
- Vercel Web Analytics — aggregate traffic and navigation measurement for the Service.
- Vercel Speed Insights — real-user performance / Web Vitals monitoring.
Under the current AIGov configuration:
- both technologies are active on the Service;
- they are used for traffic measurement and technical performance monitoring;
- AIGov has not enabled Vercel’s optional cookie-based analytics mode;
- they do not set cookies by default in the current configuration;
- they remain relevant to transparency and privacy disclosures even though they are cookieless in this configuration.
Vercel may receive technical data associated with page views or performance samples. Depending on the product and request, that may include information such as the requested URL or route, referrer, browser or device category, approximate country or similar coarse location derived from the request, timing and Web Vitals metrics, request metadata, and SDK identification information.
This Cookie Policy does not claim that all such processing is anonymous, nor that cookieless measurement necessarily falls outside all data-protection requirements. Further information about personal-data processing, legal bases, and retention will be provided in the Privacy Policy (including when counsel finalises that document).
AIGov does not call va('enableCookie') and must not enable Vercel cookie mode without a fresh compliance assessment.
7. Stripe Checkout
When you choose to start a purchase or subscription, AIGov may redirect you to Stripe Checkout, which is operated by Stripe on Stripe’s own domain.
- Stripe may use its own cookies and similar technologies in the checkout environment.
- Those technologies are governed by Stripe’s notices when you visit Stripe.
- Based on the current implementation, AIGov does not embed Stripe.js or Stripe tracking scripts on ordinary AIGov pages; checkout is initiated by redirect after you start the billing flow.
This policy does not list exact Stripe cookie names, because those cookies are set on Stripe’s domain and were not inventoried as first-party AIGov cookies.
8. Managing cookies and browser storage
You can:
- delete or block cookies through your browser settings for govbase.dev;
- clear
localStorageandsessionStorageusing browser developer or privacy controls; - log out of the Service to terminate or clear the application session as implemented;
- contact hello@govbase.dev with privacy or cookie questions.
AIGov does not currently provide an in-product cookie preference centre, and does not collect or store cookie consent choices inside the Service.
Browser controls vary by vendor. Refer to your browser’s help documentation for precise steps.
9. Consequences of blocking necessary cookies
- Blocking or deleting
govai_dashboard_access_tokenprevents or disrupts login and authenticated use of the dashboard. - Blocking
govai_selected_team_idorgovai_selected_tenant_idmay prevent selected organisational context from being retained between requests. - Clearing browser storage may remove a saved hosted API credential from the current tab or remove the most recent AI Discovery result.
10. Changes to this policy
We may update this Cookie Policy when our technologies or legal requirements change. The version, effective date, and last-updated date appear at the top of this document. Material changes will be reflected on this page. Where required, we may provide additional notice through the Service or by other reasonable means.
11. Contact
Questions about this Cookie Policy or related privacy topics: hello@govbase.dev.
Postal correspondence may be directed to AIMLGov, s.r.o. at the registered office stated above.
12. Relationship to the Privacy Policy
The Privacy Policy describes how AIMLGov processes personal data in connection with AIGov more broadly. This Cookie Policy describes cookies, browser storage, and related measurement technologies.
Until counsel supplies the final Privacy Policy text, the public Privacy Policy page may remain a versioned placeholder. This Cookie Policy is intended to be accurate for the current technical inventory and should be reviewed together with the final Privacy Policy when that document is published.
Tenant-scoped acceptance is recorded only at /legal/acceptance after authentication — not on this page.