Legal
Cookies & Tracking
Last updated August 25, 2026
This page explains the cookies Foundry sets, the anonymous analytics we use, and the control you have. In short: we set only the cookies needed to run the product, one to remember your appearance, and one to credit the link that brought you here; our site analytics use no cookies at all; we set no advertising or third-party trackers; and you can opt out below.
The short version
- The cookies we set are strictly necessary (to keep you signed in and secure), a preference cookie that remembers your light/dark appearance, or a marketing-attribution cookie that remembers which link brought you here.
- Our anonymous site analytics use no cookies. It is a small first-party beacon, and it is currently off platform-wide.
- We set no advertising cookies and no third-party tracking cookies.
- You can opt out of anonymous analytics for your browser at any time, right on this page. If your browser sends a Global Privacy Control signal, we treat that as an opt-out without you doing anything.
Cookies we set
Foundry uses a small set of first-party cookies, and only for the reasons below:
- foundry_session (strictly necessary): keeps you signed in after you log in. It is httpOnly and Secure, so browser scripts can’t read it, and it lasts up to seven days.
- foundry_2fa (strictly necessary): a short-lived cookie used only during two-step sign-in, between the password step and the code step. It is httpOnly and Secure and expires in about five minutes.
- foundry_theme (preference): remembers whether you chose light, dark, or system appearance so the page renders correctly. It holds no personal data and lasts about a year.
- foundry-demo-session (only if you use our sales demo): a demo-only gate. It carries no identity, touches no database, and reaches only the self-contained demo.
- fdy_audience (preference, and only if you use the partners page): remembers which partner seat you chose (reseller, ISO, or software company) so the page shows you that version when you come back. It holds only that one word, and it lasts about thirty days.
- fdy_path (preference, and only if you pick a trade on our home page): remembers which kind of work you told us you do, so the page talks about your trade instead of about work in general when you come back. It holds only that one word out of a short list we publish on the page itself. It holds no identifier, we do not use it to build a profile or to follow you to other websites, and it lasts about thirty days.
- foundry_attr (marketing attribution): if you arrive from a campaign link, a referral link, or a partner’s link, this remembers which one so the person who referred you can be credited if you later sign up. It holds the campaign labels from that link (including an advertising click identifier, if the link you followed carried one), the page you landed on, and a random reference for the visit so we can match it to a later signup. It holds no name, no email, and nothing that identifies you personally; we do not use it to build a profile or to follow you to other websites. It is httpOnly and Secure. It lasts about thirty days by default. If you arrived through a partner link, it lasts as long as that partner’s referral window, which can be up to ninety days.
We do not set advertising cookies, and we do not set third-party tracking cookies. Every cookie above is first-party: strictly necessary, an appearance preference, or the attribution cookie that credits the link you arrived from. None of them is shared with anyone.
Other things stored in your browser
Some things are kept by your browser itself rather than as cookies. Here is all of it:
- foundry-journey-seen (session only): a short list of which sections of our story page you have already scrolled through, so we count each one once per visit instead of once per scroll. It holds no identifier and nothing about you, and your browser discards it when you close the tab.
- foundry-analytics-optout: set only if you use the opt-out control below. It records that you have opted out, which is the one thing we need to remember in order to honor it.
- foundry-analytics-session-id (session only): a random reference so we can tell that a set of page views in the same browser tab belonged to one visit. It holds no identifier that could be traced back to you, and your browser discards it when you close the tab.
- foundry-analytics-anon-id: a random reference so we can tell that page views across several visits came from the same browser, without knowing who is using it. This is what lets us count "visitors" rather than only "page views". It is not tied to your name, email, or account even after you sign in, and it stays only in this browser; we do not use it to follow you to other websites. Cleared if you clear your browser storage.
- foundry_chat_session (session only, and only if you open the chat): a random reference that lets your messages in one chat stitch together into a single conversation on our side. It is sent to Foundry with each message you send, it identifies the conversation rather than you, and your browser discards it when you close the tab.
Anonymous site analytics (no cookies)
To understand how the marketing site is used, we use a small first-party analytics beacon rather than cookies. It is designed to be anonymous by construction:
- What it can send: the page path (with any query string and fragment stripped off), the referring page (same stripping), a scroll-depth bucket, time on page, a signup-funnel step, a widget or chat interaction (counts and technical details only, never message content), and the two random identifiers described above (foundry-analytics-session-id and foundry-analytics-anon-id) so we can tell how many page views came from one visit versus one returning browser, without knowing who the visitor is.
- What it never stores: no name, email, or other personal data; no IP address; no browser user-agent. Those are read server-side only to filter obvious bots and rate-limit abuse, and are never saved. Every other field is checked against a fixed allowlist and dropped if it does not match.
- It sets no cookie, is first-party (it posts only to Foundry), and shares no data with third parties. When you arrive from a campaign or referral link, the request does carry the attribution cookie described above, so we can credit that link. It is read and never stored alongside the analytics event.
- It is currently off platform-wide, so today it records nothing at all; it will only begin recording once we explicitly enable it.
Because this beacon is cookieless, anonymous, and off by default, we disclose it here and give you a self-serve opt-out (below) rather than showing a cookie-consent banner.
When you join the waitlist or create an account
Two things you can do here are recorded on our own servers, and it is worth naming exactly which two rather than describing forms in general:
- Joining the waitlist records that a waitlist submission happened, the industry you picked if you picked one, and the campaign labels from the link that brought you here.
- Creating an account records that a signup completed, whether it came through a referral or partner link, and those same campaign labels.
Neither record holds your name, your email, your business name, or anything you typed. Sending us a message through the contact form is not recorded this way at all. Your message goes to us and nothing else is written down about the fact that you sent it.
These are a separate thing from the anonymous analytics described above, and the difference matters: they are not affected by the site-analytics switch, because they record something you deliberately did rather than measuring how you browsed. Both of them honor a Global Privacy Control signal from your browser. If you send one, the waitlist entry and the account are still created. The signal stops the measurement, never the thing you asked for.
Browser security reports (no cookies)
Your browser can send us anonymous security reports when a page tries to load something our Content Security Policy doesn’t allow. These reports help us tighten the site’s security. They are generated by your browser, set no cookie, carry no account or personal data, and we record only the technical details of the blocked resource.
Your choice: opt out anytime
Anonymous analytics are optional. Use the control below to turn them off for this browser; when it’s off, the beacon will not fire from your browser even after we enable analytics platform-wide.
Anonymous site analytics
On for this browser (the beacon is also off platform-wide today).
This choice is stored only in this browser: no cookie, no account, no identifier. Clearing your browser data resets it, and you’ll set it once per device and browser you use.
Global Privacy Control & Do Not Track
We honor Global Privacy Control. If your browser or an extension sends a GPC signal, we treat it as an opt-out of anonymous analytics for that browser. You do not have to use the control above as well, and you do not have to ask us for anything. We treat a Do Not Track header the same way.
Changes & contact
We may update this page; we’ll change the date above when we do. Questions? Email contact@myfoundry.io.