Product: Heyz (heyz.ai) Controller: JAWK AS, Norway · org.nr 936 250 319 Language: English Version: 1.2 · Effective 18 September 2026
Contact: legal@heyz.ai (verify this mailbox is monitored)
This Cookie Policy explains how Heyz uses cookies and similar local storage. It is not personalized legal advice.
This Cookie Policy explains how Heyz uses cookies and similar local storage. It should be read with the Privacy Policy and Terms.
1. What we use today
Heyz is a first-party product. We do not use third-party advertising cookies or trackers. With your consent, first-party Explore read counting uses a random browser identifier to count at most one document read per browser per 24 hours. Popular now uses a rolling seven-day count. We do not load external analytics scripts.
Explore read counting starts only after you choose Accept in the cookie banner. Essential only (reject non-essential) keeps the product working without optional read counting.
Your choice is stored in:
localStoragekeyheyz_cookie_consent- a first-party cookie of the same name (so the preference can be read on later visits)
That record is treated as essential — it remembers this choice so we do not ask on every page load.
2. Categories
Essential (always on)
Required to operate Heyz securely. These are not used for advertising.
| Name / type | Purpose | Duration (typical) |
|---|---|---|
| Convex Auth / session cookies | Keep you signed in; protect authenticated routes | Session / provider default |
| Security / CSRF-related cookies set by auth | Prevent session abuse | Session / provider default |
heyz_cookie_consent (cookie + localStorage) | Store Accept vs Essential only | Up to 12 months, or until you change it |
heyz_explore_reporter (sessionStorage) | Deduplicate reports you submit; created only when you report a document | Browser tab session |
Exact cookie names for Convex Auth are set by the auth library and may change. They are first-party to the Heyz host.
The global app uses the same sign-in session when accessing EU and US artifacts. Direct regional API requests use bearer authorization and omit cookies. Account cookies and tokens are not sent to the artifact renderer. These authentication mechanisms do not store artifact content in session cookies.
Non-essential (off until you Accept)
| Type | Status |
|---|---|
| Explore reader identifier | localStorage key heyz_explore_reader, a random identifier created after Accept. Sent only when an Explore document is opened, then hashed in its owning backend. Read-event hashes expire after seven days; the local identifier remains until site data is cleared. It is not linked to your account or shared with the category-review providers. |
| Advertising / retargeting | Not used. |
| Social plugins that set third-party cookies | Not used. |
Optional Google sign-in, when an operator enables it, is an authentication flow (essential to that feature), not an analytics cookie we set on the landing page.
3. Sandbox artifacts
Interactive HTML you view in the separate sandbox origin is blocked from using the Heyz app’s cookies, localStorage, and account session. Artifact pages are not a place we plant ad cookies.
4. How to choose
On first visit a banner offers:
- Accept — essential cookies plus optional Explore read counts;
- Essential only — reject non-essential. The service still works (sign-in, artifacts, sharing).
Use Cookie settings in the footer to change your mind. You can also clear site data in your browser.
Norwegian / EEA rules treat non-essential cookies as requiring consent. Essential cookies do not.
5. Changes
We will update /cookies if these technologies change. We will not load them retroactively under an old “Essential only” choice.
6. Contact
JAWK AS, Norway · org.nr 936 250 319 legal@heyz.ai