Legal

Cookie Policy

Effective date: September 22, 2026

This policy explains which cookies and similar browser storage myaitoken.io uses, what each one does, how long it lasts and how you can change your choice. It supplements our Privacy Policy, which covers everything else we do with personal data.

1. What cookies and similar storage are

Cookies are small text files a website asks your browser to keep and send back with later requests to that site. “Similar storage” means the other places a site can keep data in your browser: localStorage (kept until it is deleted) and sessionStorage (cleared when the tab closes). Neither is sent to our servers automatically. This policy covers all of them, grouped by purpose: strictly necessary (always on), analytics (only with your consent) and third-party (set by a service we use to run the site).

2. Strictly necessary cookies and storage

These are required for the site to work as you expect: keeping you signed in, protecting the sign-in flow, and remembering your theme and your cookie choice. None of them identifies you across other websites. They cannot be switched off in the banner, but you can delete them in your browser at any time (see section 5).

Always on. The session cookie exists only after you sign in; the CSRF and callback cookies are set on your first page view.
NameType · set byPurposeDuration
__Secure-authjs.session-tokenCookie · our serverKeeps you signed in after you authenticate through Infinihash SSO (auth.infinihash.com). Holds an encrypted session token; set only once you sign in. HttpOnly, Secure, SameSite=Lax.Up to 30 days of inactivity, extended while you keep using the site; removed when you sign out.
__Host-authjs.csrf-tokenCookie · our serverProtects sign-in and sign-out requests against cross-site request forgery. Set on your first page view by the signed-in-status check the site runs on every page, whether or not you sign in. HttpOnly, Secure, SameSite=Lax.Browser session (deleted when you close the browser).
__Secure-authjs.callback-urlCookie · our serverRemembers which page to return you to after signing in. Set together with the CSRF cookie; until you start a sign-in it simply holds the site address. HttpOnly, Secure, SameSite=Lax.Browser session.
cookie-consentlocalStorage · this siteRecords your banner choice (“accepted” or “declined”) so we do not ask again on every page, and tells Google Analytics whether it may run.Until you clear it or use the Reset button in section 5.
myai-themelocalStorage · this siteRemembers your light or dark theme choice once you use the theme toggle.Until you clear it.

On the live https site the sign-in cookies carry the browser-enforced __Secure- / __Host- prefixes; in local development they are named authjs.session-token, authjs.csrf-token and authjs.callback-url.

A few features keep first-party data in localStorage only once you use them. They are not used for advertising or cross-site tracking and are never set just by browsing:

Functional storage — set only when you use the feature.
NameType · set byPurposeDuration
myai_walletlocalStorage · this siteSet when you connect a browser wallet in the dApp. Stores the connected address and wallet type so the dApp can reconnect on your next visit.Until you click Disconnect or clear it.
myai_anonlocalStorage · this siteA random anonymous device id created only when you start a browser compute node on /earn or /live, so that node’s earnings stay attributed to the same device across reloads.Until you clear it.
myai_referral_sourcelocalStorage · this siteSet only when you arrive on /for-agents through a link carrying a ?ref= code; keeps that code so the referrer can be credited when you register.Until you clear it.
myai_demo_wallet, myai_demo_earnings, myai_demo_anchorlocalStorage / sessionStorage · this siteUsed only by the interactive walkthrough on /demo to keep its simulated wallet address and earnings counter between steps.Until you clear them; the sessionStorage entry goes when the tab closes.

3. Analytics cookies (Google Analytics 4) — only with your consent

We use Google Analytics 4, provided by Google LLC, under property ID G-YEB23ZXXBQ to understand how visitors use the site: page views and a small set of product interactions such as connecting a wallet, installing the agent or clicking Buy.

The Google tag is loaded with Consent Mode v2, and its default state for every signal (analytics_storage, ad_storage, ad_user_data, ad_personalization) is denied. Until you click Accept in the cookie banner, Google Analytics sets no cookies and reads none; Google states that in this state the tag sends only cookieless pings. Clicking Accept grants analytics_storage only. The advertising signals stay denied whatever you choose — we do not use Google advertising features or advertising trackers. Clicking Decline leaves everything denied. Your choice is remembered in the cookie-consent entry described in section 2.

Set by Google only after you click Accept.
NameType · set byPurposeDuration
_gaCookie · Google AnalyticsDistinguishes one browser from another with a random client ID, used to count unique visitors and sessions.2 years (lifetime set by Google; renewed on each visit).
_ga_YEB23ZXXBQ (pattern _ga_*)Cookie · Google AnalyticsKeeps the session state (session ID and count) for our Google Analytics property G-YEB23ZXXBQ.2 years (lifetime set by Google; renewed on each visit).

Retention is set by Google — see Google’s cookie usage page. The data is processed by Google under the Google Privacy Policy; Google states that Google Analytics 4 does not log or store IP addresses. You can also block Google Analytics on every website with the Google Analytics opt-out browser add-on.

4. Third-party cookies and storage

A few services we rely on to run the site can set their own cookies or storage. We list everything we know about below; none of it is used for advertising, and we embed no advertising or social-media tracking pixels.

  • Cloudflare (Cloudflare, Inc. — CDN, WAF and DDoS protection). myaitoken.io is served through Cloudflare. To tell people from bots, Cloudflare may set security cookies on some requests, such as __cf_bm (bot management; expires after 30 minutes of inactivity) and cf_clearance (set after you pass a challenge; lifetime set by Cloudflare’s challenge settings). They are strictly necessary for security, are not used to track you across sites and cannot be disabled in the banner. Our content-security policy also permits Cloudflare’s Web Analytics beacon (static.cloudflareinsights.com); where it is enabled it is cookieless and does not fingerprint visitors. See Cloudflare’s cookie documentation and privacy policy.
  • Support chat widget (Oryah, served from omni.infinihash.com and operated by Infinihash LLC, the company behind MyAi). Every page loads this widget. It sets no cookies. If you never open the chat, it stores nothing. Once you start a conversation it stores a chat session ID in your browser’s localStorage under oryah_session_<site key> so the conversation survives page reloads; it stays until you clear site data. Your messages are kept on Infinihash servers to run the conversation and are not stored in your browser.
  • Sign-in (auth.infinihash.com, Infinihash SSO). Signing in takes you to auth.infinihash.com, which sets its own cookies on its own domain to run the login. When you return, our server sets only the Auth.js cookies listed in section 2.

5. Managing your choice

Your banner choice is stored in your browser, not on our servers, so you can change it whenever you like:

  • Click Reset cookie preferences below. It clears the saved choice (the cookie-consent entry), deletes any Google Analytics cookies (_ga, _ga_*) your browser lets us delete, and reloads the page so the banner appears again. Until you accept again, Google Analytics stays in the denied state.
  • Or use your browser’s settings to view, block or delete cookies and site data for myaitoken.io (look for “Cookies and site data” in Chrome, Firefox, Safari or Edge). Blocking the strictly necessary cookies will sign you out and may stop parts of the site from working.
  • To block Google Analytics on every website, install the Google Analytics opt-out browser add-on.

6. Changes

We may update this policy when the cookies or services we use change. The effective date at the top always shows the current version, and material changes will be announced on the site. If we add a category of cookies that needs your consent, we will ask for it before setting anything.

7. Contact

Questions about cookies or this policy: [email protected] (MyAi Network, Infinihash LLC). For anything else about your personal data and your rights, see our Privacy Policy.