Cookie Policy
Last Updated: October 3, 2026
FillaSurvey uses the following browser storage to operate its researcher dashboard and Telegram mini app.
Dashboard Authentication
The backend sets the __Host-fs_sid session cookie in production. It is host-only, HttpOnly, Secure and SameSite=Lax. Local development uses fs_sid over HTTP. The cookie contains a random session token; the database stores its hash. It is not shared across every FillaSurvey subdomain.
Dashboard sessions expire after 30 days. Signing out or revoking a session makes that session unusable. Blocking the session cookie prevents authenticated dashboard features from working.
Mini App Authentication
The Telegram mini app authenticates using Telegram's signed launch data and a short-lived bearer token rather than the dashboard session cookie. The bearer token expires after 15 minutes; the mini app can authenticate again using valid Telegram launch data.
Local Storage
The dashboard remembers your last selected workspace in browser local storage. This is a navigation preference rather than an authentication credential. Clearing it makes you choose a workspace again.
Browser push uses a local device identifier to manage your own subscription. Disabling the current device or signing out clears this identifier and unsubscribes that browser. Permission is requested only when you choose to enable push. A service worker receives notifications without storing session credentials or caching authenticated content.
Google Forms import stores a preview operation identifier in session storage, scoped to your account and workspace, so a reload or uncertain response can recover the same import. It does not store Google credentials or form answers in browser storage.
Payment Pages
Fincra's hosted checkout is a separate third-party page. It may use its own cookies and browser storage; its policies apply on that page.
Managing Browser Storage
Your browser's site settings let you inspect, block or delete cookies and local storage. Clearing authentication storage signs you out. Email and Telegram notification preferences are managed in account settings and are separate from browser storage.
Changes and Contact
We update this document when the browser storage used by the product changes. For questions, contact [email protected].