ZI² Discover

Cookie Policy

Last updated: 2026-06-07. Effective: 2026-06-07.

This Cookie Policy explains how Zenith Intelligence Technologies ("ZI²"), operator of ZI² Discover, uses cookies and similar technologies when you visit discover.zi2.app and the dashboard. Read this together with our Privacy Policy.

1. What cookies are

Cookies are small text files placed on your device when you visit a website. They let the site remember things — that you are signed in, your language preference, the theme you chose. We also use similar technologies that store information on your device, such as localStorage and sessionStorage; for this policy we refer to all of them as "cookies".

2. Why we use them

We use cookies to:

We do not use cookies for advertising, cross-site tracking, or profiling for marketing purposes. There are no ad-tech pixels on this site.

3. Categories we use

3.1 Strictly necessary

These cookies are required for the Service to function — for example, to log you in. They are set without consent because the Service cannot work without them.

3.2 Functional

These cookies remember choices you make, like your interface language or theme. They are set the first time you change a preference.

3.3 Analytics — only if you opt in

If we run analytics, it will be a privacy-respecting tool such as Plausible (cookieless by default) or a self-hosted PostHog instance configured without third-party transfer. EEA, UK, and Swiss visitors are not measured unless they opt in via the cookie banner. We do not enable Google Analytics on this site.

3.4 Advertising

None. We do not set advertising cookies, and we do not allow third parties to set them on our site.

4. The cookies we set

The table below lists the specific cookies the Service may set. We update this list when it changes; the current version is always here.

Name Purpose Duration Type
zi2_session Authenticates a signed-in user; holds a short-lived JWT reference. Session Strictly necessary
zi2_refresh Renews your session without forcing you to sign in again. 30 days Strictly necessary
zi2_csrf Cross-site request forgery token for state-changing API calls. Session Strictly necessary
zi2_locale Remembers your chosen language. 1 year Functional
zi2_theme Remembers your chosen color theme (light or dark). 1 year Functional
zi2_workspace Remembers your last active workspace so the dashboard opens there. 90 days Functional
zi2_consent Stores your cookie consent choice so we don't ask again. 12 months Strictly necessary
__cf_bm, cf_clearance Cloudflare bot management and security challenge state. 30 minutes — 30 days Strictly necessary (third party: Cloudflare)
__stripe_mid, __stripe_sid Set by Stripe on checkout pages for fraud prevention. Up to 1 year Strictly necessary (third party: Stripe)
plausible_* or ph_* Aggregate analytics (loaded only if you opt in). Up to 1 year Analytics

If you sign in to the dashboard from a Verified Site connection flow, the connected platform (for example, your CMS) may set its own cookies under its own policy.

5. Third-party cookies

We allow third-party cookies from only two parties, both for strictly necessary purposes:

No advertising or tracking third parties are loaded on the marketing site or the dashboard.

6. How to control cookies

You can:

If you block strictly necessary cookies, you will not be able to sign in or use the Service.

7. Do Not Track and Global Privacy Control

We honor a Global Privacy Control (GPC) signal as an opt-out for any analytics cookies. We do not respond to the legacy Do Not Track (DNT) header, because there is no consistent industry interpretation, but on the marketing site DNT users see the same minimal cookie set everyone else sees by default (necessary plus your explicit functional choices).

8. GDPR consent

For visitors in the EEA, UK, and Switzerland, we treat analytics cookies as requiring prior opt-in consent under ePrivacy and GDPR. The banner is configured to default all non-necessary categories to "off" until you choose. You can withdraw consent at any time via the "Cookie preferences" link.

9. CCPA / CPRA

For California residents, we do not sell or share personal information for cross-context behavioral advertising. Because there is no sale or sharing for advertising, no "Do Not Sell or Share" link is required, but you may exercise your rights as described in the Privacy Policy.

10. Changes to this policy

We will update this page when our cookie usage changes. The "Last updated" date at the top reflects the current version. Where a change is material we will surface it via the cookie banner the next time you visit.

11. Contact

Questions about cookies or this policy: [email protected].

See also: Terms · Privacy · Security · Acceptable Use · DMCA