Our AI agent can ring you back now.Get a call back
Cookie Policy

What we keep in your browser, and why

This page lists every cookie and every other item we store in your browser, in four places: this website (mirakash.com), the Mirakash Guide assistant on it, the Mirakash console at app.mirakash.com, and the chat widget our customers put on their own websites. Each row gives its name, what it is for, how long it lasts, and whether it is set before you have made a choice.

Last updated 19 September 2026

In short
  • On mirakash.com the only cookies are Google Analytics' two, and they are written only if you press Accept. Rejecting is one click, the same as accepting.

  • Rejecting also deletes any Google Analytics cookies already on your device. You can change your mind at any time with the Cookie preferences button in section 06.

  • Google's analytics tag is not loaded at all until you press Accept, so before that nothing about your visit goes to Google Analytics. Your answer lasts 6 months, then we ask again.

  • If your browser sends Global Privacy Control or Do Not Track, we take it as a no: no banner, no analytics. You can still accept on purpose from Cookie preferences.

  • The site and the Guide assistant keep a few small items in your browser's storage. The Guide stores nothing until you use it, and what it stores lasts only as long as the tab.

  • The console uses three cookies: one keeps you signed in, one covers the two-factor step, and one remembers your language. It also remembers three layout choices. The console has no analytics and no advertising.

  • There are no advertising cookies, no cross-site tracking and no social plugins anywhere. We do not sell or share personal information through cookies.

Change your cookie choice

01

What this covers, and who we are

A cookie is a small file a website asks your browser to keep and send back on later visits. Browsers have other places a site can keep information too. Local storage stays until it is cleared. Session storage lasts only as long as the browser tab. IndexedDB is a larger local database. The law treats all of them the same way, and so does this page. It also covers similar techniques, such as tracking pixels and requests that report on your visit without storing anything.

This page covers four places:

  • mirakash.com, this website (section 03);
  • the Mirakash Guide, the AI assistant in the corner of every page here (section 04);
  • the console at app.mirakash.com, where our customers sign in (section 09);
  • the chat widget on our customers' websites (section 10).

Mirakash is a brand and product of Naridon, Inc., a corporation incorporated in Delaware, USA. Naridon, Inc. decides what is stored on mirakash.com and in the console. On a customer's website, the customer decides whether to use our widget, and section 10 explains how responsibility is split.

This page is about what is kept in your browser. What we do with personal data more generally, including the conversations you have with the Guide, is in our Privacy Policy.

02

The rules, and how we sort each item

In the EU, Article 5(3) of the ePrivacy Directive, and the national laws that implement it (for example section 25 of Germany's TDDDG), say a site may store or read information on your device only with your consent. There are two exceptions: when the storage is only for carrying a communication, and when it is strictly necessary to provide a service you have explicitly asked for. The UK has the same rule in regulation 6 of PECR. Consent under these rules has the GDPR meaning. It must be freely given, specific, informed and unambiguous, and withdrawing it must be as easy as giving it. Where an item holds personal data, the GDPR or UK GDPR also applies.

We put everything we store into one of three categories:

  • Strictly necessary. Needed for something you asked for: staying signed in, a conversation you started, or remembering your answer to the cookie banner. We do not ask for consent for these. The law does not require it, and turning them off would break what you asked for.
  • Functional. Remembers how you like something to look or behave, such as a language or a panel size. Most are written only when you make that choice or use the feature, and we treat them as part of it. One is written without any action from you: mk_locale in the console. Its row says so.
  • Analytics. Measures how the site is used. Consent only. Nothing in this category is written until you press Accept.

There is no advertising category, because there is no advertising. We do not use advertising, retargeting or social-media cookies, or any cookie that follows you to other websites.

03

On mirakash.com

This website sets no cookies of its own. Our servers send no cookie with any page. Our code writes two items to your browser's local storage. Google's analytics tag is loaded only if you accept, and then it writes two cookies.

Cookies and storage on mirakash.com
NameSet byWhat it is forCategoryHow long it lastsWhen it is set
mirakash.consent.v2Local storageMirakash (first party). Never sent to any server.Your answer to the cookie banner (granted or denied) and the time you gave it. It stops us asking on every page, and it lets a Yes load Google's tag on your next visit without asking again.Strictly necessary6 months, then it is deleted and you are asked again. Sooner if you press Cookie preferences or clear this site's data.Only when you press Accept or Reject. An older key from the first version of the banner, mirakash.consent.v1, is deleted when you next visit.
_gaCookieGoogle Analytics. Written on the mirakash.com domain by Google's tag. What it measures goes to Google.A random ID and the time of your first visit, so Google can tell one browser from another and count returning visitors.Analytics2 years from your last visit. That is Google's default, and our tag does not change it. Your browser may shorten it (see below).Only after you press Accept, because Google's tag is not loaded before that. Deleted when you press Reject or Cookie preferences.
_ga_1P6WX2Q1NBCookieGoogle Analytics, as above. The suffix is our property's measurement ID.The state of your current visit: which visit this is and when it started. Google describes it as keeping session state.Analytics2 years from your last visit, as above.Only after you press Accept. Deleted when you press Reject or Cookie preferences.
mk_scriptLocal storageMirakash (first party). Never sent to any server.The language you picked for the sample conversation at the top of the home page (English, Hindi, Malayalam, Arabic or German), so it opens in that language next time.FunctionalNo expiry date. It stays until you clear this site's data.Only when you click a language in that sample. Until then the sample follows your browser's language, which is read on the page and not stored.

About the two Google Analytics cookies.Our tag uses Google's default cookie settings. It does not set a custom lifetime or domain. With those defaults, Google writes the cookies on the whole mirakash.com domain, so your browser also sends them with requests to app.mirakash.com and to our voice service. Nothing on those servers reads them. Google renews the expiry date each time you visit, so “2 years” means 2 years after your last visit. Some browsers shorten this. Chrome and Edge cap every cookie at 400 days. Safari limits cookies written by a page's scripts, which these are, to 7 days. Safari may also delete a site's script-written storage, including your answer to the banner, if you have not used the site for 7 days of browsing. If that happens, we ask you again.

This site uses no pixels, no social-media buttons, no chat or support tools other than our own Guide, no session recording or heatmaps, and no fingerprinting. Its fonts are served from mirakash.com itself, not loaded from a font service.

04

The Mirakash Guide on this site

The Guide is our own assistant, running through the same widget we give our customers. It sets no cookies and uses no local storage and no IndexedDB. Everything it keeps is in session storage. That storage belongs to this tab only, is not sent with requests on its own, and is cleared when you close the tab. A browser that restores closed tabs may restore it with the tab.

Session storage used by the Mirakash Guide on mirakash.com
NameSet byWhat it is forCategoryHow long it lastsWhen it is set
mirakash.widget.visitedSession storageMirakash (first party).The paths of up to 12 pages you have viewed on this site in this tab (no query strings), so that when you ask the Guide something it knows what you have already read.FunctionalThis tab only. Deleted when you close the tab.Only once you have opened the Guide in this tab. Before that, the pages you view are held in the open page's memory and nothing is written. The list is sent to us when you open the Guide, and again with each message.
mirakash.widget.sidSession storageMirakash (first party).A random conversation ID (w_ followed by a random string). It keeps every message from this tab in one conversation. It identifies a conversation, not you.Strictly necessaryThis tab only.When you open the Guide.
mirakash.widget.logSession storageMirakash (first party).The last 30 messages on screen, and whether the panel was open. This keeps the conversation in front of you when you move to another page.Strictly necessaryThis tab only. If it is more than 30 minutes old, it is ignored and deleted on the next page load.After you open the Guide, once its first message is on screen.
mirakash.widget.layoutSession storageMirakash (first party).The panel size, which side of the screen it sits on, and the launcher's shape.FunctionalThis tab only.Only when you change one of them.
mirakash.widget.callSession storageMirakash (first party).During a voice conversation, when the page changes, this holds the page you were on, the page you were going to, and the last thing the Guide said (up to 240 characters). The call then carries on from there instead of starting again.Strictly necessaryRead and deleted on the next page load, and ignored if it is more than 90 seconds old. Otherwise it goes when you close the tab.Only when a page changes while you are in a voice conversation.
mirakash.widget.arrivalSession storageMirakash (first party).When the Guide opens another page for you, this holds what it will say once you get there, any suggested replies, your question and the page you came from.Strictly necessaryRead and deleted on the next page load, and ignored if it is more than 45 seconds old. Otherwise it goes when you close the tab.Only when the Guide takes you to another page.

Nothing is stored before you use the Guide.Until you open it in this tab, the Guide keeps the pages you view only in the open page's memory and writes nothing to your browser's storage. That memory is gone when the page is reloaded or closed. This site moves between its own pages without reloading, so the Guide usually still knows the pages you have read when you open it. When you open the Guide, that list is sent to us, and again with each message, so it can answer with what you have already seen. From then on, the list is kept in mirakash.widget.visited for the rest of the tab.

Voice.If you start a voice conversation, your browser asks for the microphone. Your browser, not us, remembers whether you allowed it, and you can change that in your browser's site settings. The voice connection stores nothing on your device.

Videos and pages inside the panel.The Guide can show a video or a web page inside its panel. YouTube videos load from youtube-nocookie.com, Google's reduced-cookie player, and Vimeo videos load with Vimeo's do-not-track setting. Both play in a sandboxed frame whose scripts cannot read or write cookies or local storage. The video service's own servers can still set cookies, subject to your browser's third-party cookie settings and that service's policy. A web page shown in the panel is loaded from its own site and may set its own cookies under that site's policy.

What happens to what you say to the Guide is covered in the Privacy Policy.

05

Google Analytics and Consent Mode

We use Google Analytics 4 (property G-1P6WX2Q1NB) to see which pages are read, in what order, and whether visitors reach the demo page. It runs under Google's Consent Mode v2, set up the way Google calls basic: Google's tag is not loaded at all until you accept. That means:

  • Before you choose, and if you reject, nothing goes to Google Analytics. Your browser does not download Google's tag, so it sends Google Analytics no request, no cookie and no “cookieless ping” about your visit. The page only sets up a small placeholder of its own, with every consent signal set to denied.
  • When you press Accept, the page stores your answer, switches analytics storage on, and only then fetches the tag from googletagmanager.com. From that moment the tag writes the two cookies in section 03 and sends Google what it measures, along with your IP address, as any web request does. Measurement starts from your click, not from the page you arrived on.
  • Accept turns on analytics storage and nothing else. The three advertising signals (ad_storage, ad_user_data, ad_personalization) stay denied even after you accept. That is why no Google advertising cookie is ever written here.
  • On later visits, if you accepted less than 6 months ago, the tag loads as the page opens and we do not ask again. After 6 months your answer expires, the tag stops loading, and the banner asks you again.
  • If you reject after accepting, analytics storage is switched to denied at once, the _gacookies are deleted (section 06), and Google's own off switch for our property (ga-disable-G-1P6WX2Q1NB) is set, so the tag that was already running in the open page stops sending anything. It is not loaded again on your next visit.

Google receives what the tag collects in order to provide Google Analytics to us, and may process it outside the EU, including in the United States. How long Google keeps analytics data is set on our Analytics property. The Privacy Policy covers both points under analytics.

06

Accept, reject, or change your mind

The banner.The first time you visit, a banner offers Accept and Reject. The two buttons are the same size and the same style, and each is one click. If you ignore the banner, analytics stays off and Google's tag is not loaded. If your browser sends Global Privacy Control or Do Not Track, the banner does not appear at all, and we treat the signal as a no (section 08).

Rejecting deletes what is already there. Switching analytics off stops Google writing new cookies, but it does not remove old ones. So when you press Reject, or the Cookie preferences button below, the page finds every cookie whose name starts with _gaand deletes it, both as a cookie of the exact address you are on and as a cookie of the whole mirakash.com domain. It can reach only this site's cookies, which is where Google put them.

Changing your mind. The button below clears your stored answer, switches analytics back off, deletes any Google Analytics cookies on this device, and shows the banner again. Nothing is switched back on until you choose. It works even if your browser sends a privacy signal, so you can accept on purpose if you want to. Withdrawing consent does not make earlier measurement unlawful. It stops it from that moment on.

Checking your current choice…

How long your answer lasts. Your answer is stored with the date you gave it, and it lasts 6 months. After that we ask again, and Google's tag is not loaded until you answer. When your answer expires, any _ga cookies already on your device are deleted on your next visit. The first version of this banner kept its answer under a different name, mirakash.consent.v1, with no date. If your browser still has it, it is deleted on your next visit and you are asked once more.

Your answer is kept only in your browser, and we keep no copy on our servers. It applies to this browser on this device. A different browser, a private window or another device will be asked again. If your browser blocks local storage, we cannot remember the answer, so the banner comes back on each page and analytics stays off.

What deleting cookies does not do. Deleting the cookies does not delete data Google already received while analytics was on. That data is tied to the random ID in your _ga cookie, not to your name, so we can find it only if you tell us that ID. To ask, copy the value of your _ga cookie before you reject, then send it to us through the contact formwith the topic “Delete the data you hold on me”.

07

Controls in your browser

You do not need our button to control any of this. Every major browser lets you:

  • see and delete cookies and site data for one site. Look in the privacy or site settings, usually under “Cookies and site data”. This clears cookies, local storage and session storage together;
  • block cookies and storage for one site, or for all sites;
  • use a private window, which throws everything away when you close it;
  • block trackers with a built-in setting or an extension. Many of these stop Google's tag from loading even after you accept;
  • turn on Global Privacy Control or Do Not Track, which this site treats as a no (section 08).

Google also offers its own browser add-on that stops Google Analytics on every site, at tools.google.com/dlpage/gaoptout.

What breaks if you block things. If you block storage on mirakash.com, the site still works. The banner comes back on every page, and the Guide cannot carry a conversation across a page reload. If you block cookies on app.mirakash.com, you cannot sign in to the console, because __session is what keeps you signed in.

08

Global Privacy Control and Do Not Track

Some browsers and extensions send a Global Privacy Control (GPC) or Do Not Track (DNT) signal. This website reads both, in your browser, and treats either one as a no.

  • If your browser sends GPC, or sends DNT, and you have not given us an answer yourself, the cookie banner is not shown, analytics stays off, and Google's tag is never loaded. Nothing about your visit goes to Google Analytics.
  • A choice you make on purpose outranks the browser's default. You can still open the chooser with the Cookie preferences button in section 06 and press Accept. If you accepted before you turned the signal on, that answer stands until it expires after 6 months or you change it. The status line under the button tells you which applies.
  • We read the signal from your browser on the page. We do not read the Sec-GPC header that comes with each request, because mirakash.com is served as static files and no code on our servers makes decisions about visitors.
  • Under the US state laws that give GPC legal force, it is a request to opt out of the sale or sharing of personal information. We do neither (see section 11), and on this site the signal also keeps analytics off.
  • The signals do not change the Guide, which stores nothing until you use it (section 04).

09

In the console (app.mirakash.com)

The console is where our customers sign in and work. It sets the three cookies below and remembers three layout choices in local storage. It runs no analytics, no advertising and no third-party tracking script. It has no separate anti-forgery (CSRF) cookie. Sign-in is handled by our own server. No identity provider's script stores anything in your browser, and nothing is kept in IndexedDB.

Cookies and storage on app.mirakash.com
NameSet byWhat it is forCategoryHow long it lastsWhen it is set
__sessionCookieMirakash (first party). HttpOnly, Secure, SameSite=Lax. Page scripts cannot read it.Keeps you signed in. It is a signed token carrying your account ID, email address, role, current workspace and session ID. The server checks it on every request.Strictly necessaryThe cookie expires 7 days after it is issued. The session behind it ends sooner after 8 hours without use, when you sign out, or when it is revoked. It never lasts more than 7 days after you signed in.When you sign in. Deleted when you sign out.
__mfa_challengeCookieMirakash (first party). HttpOnly, Secure, SameSite=Strict, and sent only to the two-factor sign-in endpoint.Proof that your password was right, held while you enter your two-factor code, so the password is not sent twice.Strictly necessary5 minutes. Deleted as soon as you are signed in.Only if your account uses two-factor sign-in, after you enter your password.
mk_localeCookieMirakash (first party). Secure, SameSite=Lax.The console's language (en, de or ar), so the server and your browser show the same one.Functional1 year.On your first visit to any console page, including the sign-in page, without asking. It is filled from your browser's language setting and replaced when you choose a language.
mirakash.sidebar.collapsedLocal storageMirakash (first party). Never sent to any server.Whether you collapsed the side navigation.FunctionalNo expiry. It stays until you clear the console's site data.Only when you collapse or expand it.
mirakash.copilot.widthLocal storageMirakash (first party). Never sent to any server.The width you dragged the Copilot panel to.FunctionalNo expiry. It stays until you clear the console's site data.Only when you resize the panel.
mirakash.kb.viewLocal storageMirakash (first party). Never sent to any server.Whether the Knowledge page shows a grid or a list.FunctionalNo expiry. It stays until you clear the console's site data.Only when you switch between grid and list.

mk_localeis also set on the console's public pages: the status page and the page a person opens when a call is transferred to them. It holds a language code and nothing else.

Payments.When you pay or manage billing, you are sent to Stripe's own checkout and billing pages. Any cookies there belong to Stripe and follow Stripe's policy. We do not load Stripe's script into the console.

If you have accepted analytics on mirakash.com, your browser also sends the two Google Analytics cookies to app.mirakash.com (see section 03). The console does not read them.

10

The widget on our customers' websites

Our customers can add the same chat and voice widget to their own websites. On those sites, the customer decides whether the widget is there, what its agent does, and how visitors are asked for consent. The customer is responsible for its own cookie notice and consent tool. For the conversations themselves, we act for the customer as its processor under our Data Processing Addendum.

What the widget stores in a visitor's browser on a customer's site:

  • No cookies, no local storage and no IndexedDB. It loads no analytics, advertising or tracking script.
  • The same six session-storage items as on our own site (see the table in section 04). They are stored under the customer's own domain and belong to that tab only. None of them is written before the visitor opens or uses the widget.Until then, the pages the visitor views are held in the open page's memory only. On a site that reloads between pages, that means the widget opens knowing only the current page. One exception is in the customer's own hands: if the customer's page script reads MirakashWidget.sessionId, that creates the conversation ID at once.
  • Requests to us.On every page load, the widget loads its script, its settings and its font files from app.mirakash.com. Like any web request, these reach us with the visitor's IP address and browser details. No cookie goes with them. The page list goes to app.mirakash.com when the visitor opens the widget. Messages go there, and voice to our voice service, only when the visitor types or speaks.

A customer's consent tool may need to decide whether the widget runs at all. The widget has no consent switch of its own, so the way to do that is to add the widget's script tag only after the visitor agrees. Once it has loaded, the page's own script can start a fresh conversation by calling MirakashWidget.reset(), which clears the conversation ID and the saved messages.

Optional features that involve other companies.If a customer turns on a video avatar, the widget loads a video-call library (Daily's daily-js or livekit-client) from the public code host unpkg.com when an avatar session starts, and connects to the avatar provider's media servers. Each library is fixed to one version and carries an integrity fingerprint, so the browser refuses a file that has been changed. Like any web request, fetching it gives unpkg.com the visitor's IP address. Those libraries and providers may use storage of their own, and we have not catalogued it. Videos and web pages shown inside the panel work as described in section 04. Avatars are switched off on mirakash.com.

A customer can adapt this text for its own cookie notice:

Chat assistant (provided by Mirakash, a product of Naridon, Inc.).The chat assistant on this site sets no cookies and stores nothing until you open or use it. It then keeps the following in your browser's session storage, for this tab only, and they are deleted when you close the tab:

  • mirakash.widget.visited: the addresses (without query strings) of up to 12 pages you have viewed on this site in this tab. It is written only after you open the assistant; before that, pages are held in memory and nothing is stored.
  • mirakash.widget.sid: a random conversation ID, created when you open the assistant.
  • mirakash.widget.log: your recent messages, so the conversation continues when you change page (ignored after 30 minutes).
  • mirakash.widget.layout: the panel size and position, if you change them.
  • mirakash.widget.call and mirakash.widget.arrival: short-lived notes that carry a voice call, or the assistant's next sentence, across a page change (ignored after 90 and 45 seconds).

If you use the assistant, your messages (and your voice, if you speak to it) are processed by Mirakash on our behalf.

A customer that enables a video avatar, videos or page previews in the widget should add those providers to its notice.

11

No selling, no sharing, no advertising

We do not sell personal information. We do not share it for cross-context behavioural advertising, as California and other US state laws define those terms. We do not use cookies or any other storage for advertising, retargeting or building a profile of you across websites. Google's advertising consent signals stay denied even when you accept analytics, and no advertising or social-media company has a tag on our pages.

12

Things that are not cookies, but you should know about

Some things happen on this site that store nothing on your device. A cookie banner cannot switch them off, so we list them here:

  • The server's access log. The content delivery network that serves mirakash.com logs every request: IP address, user-agent, URL, time, response status and edge location. It is a record kept on our side, not a cookie. The logs are deleted automatically after 400 days, and the Privacy Policy covers them in its section on the access log.
  • The Guide loading.Each time a page loads, the Guide's script, settings and font files are fetched from app.mirakash.com. That is an ordinary web request carrying your IP address and browser details, with no cookie attached.
  • Settings your browser already shares with every page.The pricing page reads your time zone to show prices for your region. The demo-call form reads your time zone and browser language to pre-select your country code. The home page reads your browser language to pick the sample conversation's language. The cookie banner reads your browser's privacy signals (section 08). All of this is used in the page and is not stored or sent to us, apart from mk_script if you pick a language yourself. The country code you finally choose goes with the phone number you submit.

The load balancer in front of app.mirakash.com and our voice service does not use “sticky” cookies. Our web firewall there does not use challenge or CAPTCHA cookies. We checked both settings on 19 September 2026.

13

Changes to this policy

When we add, remove or change anything we store on your device, we update this page, and the date at the top changes with it. If we ever want to add storage that is not strictly necessary, it will be off until you agree to it, like analytics is today. If a change is material, this page will say what changed.

14

Questions and requests

Questions about this page, and requests about data connected to anything listed here, go to the form at /contact. It has topics for seeing, deleting and correcting your data, and for objecting to a use of it. Customers who are signed in can also reach us from the console. We answer within the shortest period the law that applies to you requires.

You can also complain to the data protection authority where you live or work.

Related documents: the Privacy Policy, the Terms of Service, the Data Processing Addendum, the list of sub-processors and the data deletion instructions.