Cookie Policy
Last reviewed 11 September 2026
A complete inventory rather than a reassurance. One cookie, a handful of browser storage entries, all of it necessary to sign you in and remember your settings, and one item we flag as a genuine weakness rather than describe as secure.
The short version
VoxSign sets one cookie, to keep you signed in, plus a small number of entries in your browser's own storage to remember your settings and avoid asking the server for the same thing repeatedly. That is the whole list, and it is below in full.
There is no advertising cookie, no cross site tracking, no third party analytics script, no social media pixel and no fingerprinting. This is why you are not being shown a consent banner: there is nothing here to consent to beyond what the service needs in order to function, and a banner that asks permission for strictly necessary storage is theatre.
Browser storage, and an honest note about one item
These are stored by your browser for this site, not sent automatically with every request the way a cookie is. They stay on the device until you sign out or clear your browser data.
- voxsign_token
- A short lived access token that lets the app talk to the VoxSign API on your behalf. It is derived from your session and refreshed automatically when it expires.
- voxsign_user
- A copy of your own account details, your name, email address and profile picture, so the app can show them immediately instead of blanking the header while it asks the server.
- voxsign_captions and voxsign_caption_size
- Whether captions are on, and how large you set them, so the player opens the way you left it.
- voxsign_simulation_settings
- Playback options you have chosen for the signing avatar.
The disclosure about voxsign_token
The session cookie above cannot be read by scripts. The access token in voxsign_token is stored in ordinary browser storage, so it can be. If a malicious script ever ran on this site, through a flaw of ours or a compromised dependency, it could read that token and use it to call the API as you until the token expires. It cannot read the session cookie, and so cannot mint new tokens once that one expires.
We are telling you this rather than describing our storage as secure and leaving it there. The token is deliberately short lived, which bounds the damage, and it is the trade made so that the app interface and the processing API can live on separate hosts. We consider it a weakness worth closing and it is recorded as such on the security page.
Third parties
Two third parties can set something in your browser, and only in these circumstances:
- Google, if and only if you choose to sign in with Google. Google's own cookies are involved in that sign in, governed by Google's privacy policy, not ours. If you use an email address and password instead, Google is never involved.
- Our hosting providers may set a cookie needed to route or protect traffic. These are operational and are not used to build a profile of you.
We do not embed third party fonts served from another domain, tracking scripts, ad networks or social widgets, so none of those can set anything here.
Your choices
You can clear or block all of this from your browser settings at any time. Because everything listed is necessary rather than optional, the consequences are practical rather than a loss of personalisation:
- Clearing it signs you out and resets your caption and playback choices. Your accessibility settings are safe, because those are stored on your account, not in your browser.
- Blocking cookies for this site means you cannot sign in at all.
- Signing out clears the access token and the cached copy of your account details.
This page is the complete inventory. If you find something stored by this site that is not listed here, that is a fault and we want to hear about it at info@voxsign.co.ug.