SorenLegal & Privacy

Cookie & Tracking Notice

Company draft for attorney review. Version: launch-draft-1. Effective date: September 11, 2026. Operator: [LEGAL OPERATOR NAME], operating under the Pineform Labs brand. Questions: [email protected].

Necessary browser mechanisms

Soren uses browser mechanisms necessary for sign-in, account security, and requested app functionality. The hosted service sets a secure, HttpOnly session cookie named __Host-soren_session. It authenticates your session; the normal server-issued session lasts eight hours unless otherwise configured within the server's permitted bounds. Signing out expires the cookie and revokes that session. Browser expiry is not deletion of historical server-side session records.

The __Host-soren_login and __Host-soren_workspace cookies bind their respective Google authorization flows to your browser. Each has a five-minute maximum age and is cleared when its flow completes or is handled as failed. They are separate from granting Workspace access. Secure and HttpOnly protections apply to hosted cookies, with SameSite settings appropriate to each flow.

Authenticated changes require a session-bound CSRF proof held by the page in memory and sent in a request header; it is not an advertising identifier. Explicit loopback development uses equivalent development-prefixed cookies. The separate local UI uses soren_ui_csrf for request protection and local storage keys sorenSessionId and sorenVoiceMuted for the selected conversation and voice preference. Those local-storage values persist until changed or cleared. The hosted command center does not currently use those local preference keys.

Tracking inventory

Current Soren application source does not include third-party advertising cookies, third-party analytics scripts, or cross-site behavioral tracking. Hosting and identity providers process technical information needed for their services under their own practices. We do not describe those services as incapable of logging requests. Google sign-in and Workspace consent occur on Google's service, where Google's own notices apply.

Your choices

You can clear or block cookies and local storage in your browser. Blocking essential cookies can prevent sign-in and connection flows; clearing browser storage does not necessarily revoke a server session or delete stored account data. Use Sign out to revoke your current Soren session and Disconnect to remove the live Workspace credentials.

We have not added a decorative consent banner for essential storage alone. Before adding nonessential analytics, advertising, or tracking, we will revisit the inventory, this notice, and jurisdiction-appropriate consent controls. Contact [email protected] with questions or requests.