Cookies & Local Storage Policy
Information about cookies, browser storage and similar technologies used by IOBend.
1.Purpose & Scope
This Cookies & Local Storage Policy explains how IOBend Technologies Private Limited ("IOBend", "we", "us", or "our") uses browser cookies, local storage, session storage, and related client-side technologies across the IOBend platform website (iobend.com) and web console application.
IOBend uses client-side storage technologies for specific, functional purposes:
- Authenticating developers and maintaining active user sessions;
- Preserving multi-tenant organization and workspace context;
- Protecting the application against session hijacking and automated abuse;
- Caching developer interface preferences and local consent choices; and
- Optimizing page loading performance without unnecessary network roundtrips.
This policy should be read alongside our Privacy Policy and Terms of Service.
5.Security Attributes & Protections
To protect against token theft, cross-site scripting (XSS), and unauthorized tampering, IOBend enforces strict security attributes on its authentication cookies:
Restricts client-side JavaScript from accessing the session cookie, neutralizing token extraction via XSS vulnerabilities.
Ensures cookies are only transmitted over encrypted TLS/HTTPS connections in production environments.
Prevents browsers from sending cookies on cross-site requests, mitigating Cross-Site Request Forgery (CSRF).
6.CSRF & Session Security
IOBend maintains multi-layered session validation:
- Cryptographic Verification: Session cookies contain digitally signed tokens verified against server-side keys;
- State Invalidation: Active sessions are cross-checked against Redis cache records and database token versions (
tokenVersion), allowing instantaneous revocation upon password change, logout, or security incident; - Logout Purge: When you log out (
logOutAction), session cookies are explicitly deleted from your browser and destroyed in the server-side cache.
7.Browser Local Storage
IOBend uses browser localStorage exclusively for client-side interface state and developer preferences:
| Storage Key | Type | Purpose & Description |
|---|---|---|
| iobend_local_consent | Boolean | Caches the user's consent preference for running interactive workstation diagnostics (InteractiveDoctor) on the dashboard without network latency. |
Data in localStorage remains in your browser until explicitly removed by the application, cleared via your browser settings, or when you clear site data.
8.Session Storage & Asset Caching
In addition to cookies and local storage, standard browser caching mechanisms are used to optimize platform delivery:
- HTTP Cache: Static user interface assets (such as CSS stylesheets, compiled JavaScript bundles, fonts, and platform icons) are cached in your browser using standard HTTP caching headers (
Cache-Control) to accelerate load times; - Session Memory: Volatile client-side state (such as in-flight form inputs and active view tab selections) may be maintained in transient browser memory during an active browsing tab.
9.Third-Party Technologies & External Links
When you interact with external services integrated into IOBend:
- OAuth Providers (GitHub / Google): When authenticating via single sign-on (SSO), your browser communicates directly with the respective authentication provider, which may set its own cookies on its domain;
- Payment Processors (Razorpay / Stripe): When entering checkout or billing management flows, tokenized payment forms are served securely under PCI-DSS compliance frameworks by the respective processor;
- Infrastructure Subprocessors: Cloudflare edge nodes terminate TLS connections and may utilize standard HTTP security headers to protect against DDoS traffic.
For more details on authorized service providers, please visit our Trust Center.
10.User Control & Browser Configuration
You have full control over the cookies and storage technologies stored on your device:
- Browser Cookie Settings: You can configure your browser (Google Chrome, Mozilla Firefox, Apple Safari, Microsoft Edge) to accept, reject, or prompt before accepting cookies, or to block third-party cookies;
- Clearing Site Data: You can delete existing cookies and clear
localStorageat any time through your browser settings or developer tools (Application / Storage panel); - Incognito / Private Browsing: Using private browsing mode automatically discards cookies and local storage when you close all private windows.
Consequences of Disabling Essential Cookies
Because the iobend_session cookie is strictly essential for authentication, blocking or deleting essential cookies will terminate your login session and prevent access to authenticated dashboards, project workspaces, and API management consoles.
11.Browser Storage Deletion vs. Account Deletion
Important Distinction: Browser Storage vs. Server Data
Clearing cookies, local storage, or browser cache on your local device removes client-side state from that specific browser. Clearing browser storage does NOT delete your server-side account, project repositories, secrets, or organization records stored on IOBend cloud infrastructure.
To request permanent deletion of your account and personal data, please follow the account deletion procedures outlined in our Privacy Policy or contact privacy@iobend.com.
12.Cookie Consent & Compliance
IOBend designs its web applications to respect user privacy and adhere to applicable data protection requirements under Indian law (including the Digital Personal Data Protection Act, 2023) and international standards.
Because IOBend currently utilizes only strictly necessary and functional first-party storage technologies essential for providing the requested developer services, invasive consent banners for cross-site behavioral tracking are not applicable. If optional tracking or analytics cookies are introduced in the future, IOBend will provide appropriate consent controls and update this policy accordingly.
13.Distinguishing Cookies from Telemetry
It is important to distinguish browser storage technologies from other technical logging categories:
- Browser Cookies & Local Storage: Client-side storage mechanisms managed within your browser sandbox;
- IOBend CLI Telemetry: Minimal diagnostic and execution metrics generated by workstation CLI binaries (governed in Section 6 of our Privacy Policy);
- Server-Side Infrastructure Logs: Security, routing, and access audit records maintained in cloud infrastructure for platform defense and compliance.
14.Changes to this Policy
IOBend may update this Cookies & Local Storage Policy from time to time to reflect changes in our technical architecture, client storage practices, or legal requirements.
When updates occur, we will post the revised version with an updated "Last Updated" and "Effective Date" at the top of this page. We encourage you to review this document periodically.
15.Contact Us
If you have questions, inquiries, or feedback regarding our use of cookies and local storage technologies, please reach out to our privacy and legal teams:
Governing Entity: IOBend Technologies Private Limited, India.
