Cookie Policy
Agily uses only strictly-necessary and functional cookies — no ad trackers.
Last updated: 2026-09-12 · Effective: 2026-09-12
We are finalizing our legal documentation ahead of general availability. These pages describe our current practices; contact legal@agily.app with any questions.
This policy explains the cookies and similar browser storage that the Agily service at https://www.agily.app and the website at https://www.agily.app use. It supplements the Privacy Policy.
Summary
Agily uses only:
- Strictly necessary cookies and storage — required to sign you in, keep you signed in, and protect sign-in flows. These cannot be switched off without breaking the Service, and no consent is required for them.
- Functional cookies and storage — remember interface preferences such as your language, sidebar state, and view settings.
Agily does not use advertising cookies, cross-site tracking, or third-party analytics/marketing trackers in the application.
Cookies
| Name | Set by | Type | Purpose | Duration | Flags |
|---|---|---|---|---|---|
refresh_token | Agily API | Strictly necessary | Keeps you signed in by allowing the app to obtain a new short-lived access token without re-entering your password | ~30 days (rolling) | HttpOnly; SameSite=Lax; Secure (in production); Path / |
oauth_state | Agily API | Strictly necessary | Protects the “Sign in with Google/GitHub” flow against cross-site request forgery | A few minutes | HttpOnly; Secure (in production); Path /auth/oauth |
oauth_link | Agily API | Strictly necessary | Same protection for connecting a Google/GitHub account to an existing account from Settings | A few minutes | HttpOnly; Secure (in production); Path /auth/oauth |
sidebar_state | Agily web app | Functional | Remembers whether the navigation sidebar is expanded or collapsed | ~7 days | Path / |
NEXT_LOCALE | Agily web app | Functional | Remembers your language choice | ~1 year | Path / |
Browser local storage
The application also stores small values in your browser’s localStorage. This is not a cookie and is never sent to our servers automatically.
| Key | Type | Purpose |
|---|---|---|
auth-storage | Strictly necessary | Holds your current session state (including the short-lived access token and basic profile) so the app works across page reloads and tabs |
preferences-storage | Functional | Your interface preferences |
| Various per-view keys (board density, roadmap panel width, “what’s new” seen flags, saved filters, collapsed sections) | Functional | Remember how you last used a particular screen |
Third-party cookies
- When you enable an Integration (Slack, Microsoft Teams, Telegram, Discord, Google, GitHub), the third party’s own sign-in or authorization pages may set their own cookies under their control and privacy policies. Agily does not control those.
- The payment flow is hosted by our payment processor; its checkout page may set its own cookies. See our Sub-processors page.
Managing cookies
- You can delete or block cookies in your browser settings. Blocking strictly necessary cookies will prevent you from signing in.
- Clearing site data will sign you out and reset your interface preferences.
Contact
Questions? Email legal@agily.app. Privacy requests: privacy@agily.app. Report a security issue: security@agily.app.