Cookie Policy
Every cookie SAIMA sets, what it does, how long it lasts, and what happens if you block it. The list below is complete — there is nothing set that is not named here.
Effective date: 9 August 2026 · Last updated: 9 August 2026
1. Our approach
SAIMA sets only cookies the platform needs to work. We do not set advertising cookies, we do not sell cookie data, and we do not embed third-party trackers that follow you across other websites.
Because every cookie we set is strictly necessary to deliver a service you have asked for — signing in, staying signed in, connecting an account securely — none of them requires consent to place. We publish the full list anyway, because you are entitled to know what is stored on your device.
2. Sign-in and session
- saima_session — Keeps you signed in. Contains a signed reference to your session record, never your password. Lasts 30 days, or until you sign out or end the session from your security settings. HttpOnly, so it cannot be read by scripts in the browser.
- saima_pkce_ms — Holds a one-time cryptographic verifier while you sign in with a provider such as Microsoft. It exists so that an intercepted authorisation code cannot be exchanged by anyone but us. Lasts 10 minutes and is deleted the moment sign-in completes.
3. Connected accounts
These are set when you connect an advertising or social account, and only for the platforms you actually connect.
- amh_oauth_state_* — A one-time random value that ties the authorisation you started to the response that comes back, which is what prevents a forged connection request from succeeding. Lasts 10 minutes and is deleted as soon as the connection completes.
- amh_ads_connections — The list of accounts you have connected and their status, so the integrations page can show them. Lasts 90 days.
- amh_ads_token_* — The access token for a connected platform, one cookie per platform. HttpOnly and, in production, sent only over HTTPS. Lasts 90 days, and is deleted immediately when you disconnect that platform.
4. Referral attribution
- saima_ref — Records the affiliate partner who referred you, so that a commission can be attributed correctly if you subscribe. It identifies the partner, not you, and is used for nothing else.
5. What we do not set
We do not set advertising or retargeting cookies. We do not embed social media tracking pixels on the platform. We do not use cookies to build a profile of you for marketing, and we do not share cookie data with data brokers.
If we ever introduce analytics or marketing cookies, we will update this policy and ask for your consent before setting them.
6. Your controls
You can delete cookies or block them in your browser settings at any time.
Be aware of the consequence: blocking our cookies will sign you out and prevent you from signing back in, and clearing them will disconnect your linked advertising and social accounts, which you would then need to reconnect. This is not a restriction we impose — these cookies are the mechanism by which the session and the connections exist.
7. Questions
For any question about cookies, contact privacy@saimahub.ai.
Related documents
