Cookies and localStorage
Legal force. Only the Russian version of this document has legal effect. This translation is provided for convenience; if the two differ in any way, the Russian original governs — read the original. The service is operated under the law of the Russian Federation, and the Russian text is the one a court, a regulator and the parties rely on.
While you are reading the pages of this site, nothing is written to your device: not a single cookie is set before you sign in to the account area. Everything the service may store in your browser is listed below, together with the condition under which it happens. There is not one entry serving advertising, profiling or cross-site tracking.
1. What is stored and why
1.1. The site uses one cookie:
session_token— the sign-in cookie. It is set at the moment of a successful sign-in to the account area and only then: a visitor who has not signed in is never given it. It confirms that you are signed in and nothing more — it holds neither your actions on the site nor your browsing history. Its lifetime is 90 days and is extended on every request to the account area, so with regular use you do not have to sign in again. It carries the flagsHttpOnly(not accessible to page scripts),Secure(sent only over a secure connection) andSameSite=Lax. It is deleted when you sign out — both in the browser and on the server. Without it, signing in is impossible.
1.2. Besides that cookie, two entries may appear in your browser’s local storage. Both are created only by an action of your own, both are kept until you or your browser clears the site’s data, and both stay on your device — they are not sent to the server:
kristina_theme— appears if you have pressed the light/dark theme switch. It holds a single word: the theme you chose. Until the switch is pressed there is no entry, and the site opens in the light theme regardless of your device’s settings.kristina_pwa_dismissed— appears in the account area if you dismissed the offer to install the app. It exists solely so that the offer does not appear again.
1.3. In the chat widget on client companies’ websites, an entry of the form kristina:“company identifier” is stored in the browser’s local storage — on the domain of the site hosting the widget, not on the service’s domain. It contains a random visitor identifier and a conversation key: without them an answer could not be returned to the person who asked, and a conversation already started would break off on every page reload. The entry is created when the widget loads. It is kept until the visitor or their browser clears that site’s storage. The widget is not embedded on kristina-ai.ru itself.
1.4. Technical data about requests to the service, including the IP address. This is not an entry in the browser, but it is disclosed here for completeness: it is processed to protect against spam, password guessing and other abuse, and is not used for anything else.
1.5. There is no separate banner with an “Accept cookies” button on this site, and that is a deliberate decision rather than an omission. There would be nothing to put in it: before you sign in to the account area nothing is written to your device, and the sign-in cookie is necessary for the sign-in service itself — you cannot refuse it and go on using the account area, so the button would offer a choice that does not exist. Consent to the processing of personal data is taken where it is genuinely required — by a separate tick box at registration.
2. Analytics and advertising
2.1. No analytics, advertising or other third-party tracking technologies are installed on the public pages of the service or in the chat widget.
2.2. If such technologies are introduced, the Operator will update this document and the personal data processing policy before they are used, and will ensure that consent is obtained where the law requires it. The reverse order — connect first, describe afterwards — is not used.
3. How to refuse
3.1. Cookies and the contents of local storage can be deleted and blocked using your browser; its help pages explain how.
3.2. The sign-in cookie (clause 1.1) and the chat widget entry (clause 1.3) cannot be refused while keeping those functions working: they are needed to provide the service itself, not to watch the user. Deleting or blocking them means you will have to sign in to the account area again, and the chat will start a new conversation unconnected with the previous one.
3.3. The entries in clause 1.2 are optional: do not press the theme switch and do not dismiss the installation offer, and they will not appear. Deleting them has no effect other than that the site will open in the light theme again and the installation offer will be shown once more.
4. Relationship to the processing of personal data
4.1. Where the entries and technical data listed here make it possible to identify a person directly or indirectly, they are processed as personal data — on the grounds and for the periods established by the personal data processing policy.
4.2. On the websites of client companies where the chat widget is embedded, the company itself is the operator of its visitors’ data. Informing those visitors about the technologies used on its site is that company’s duty.