We use a small number of first-party cookies, all named with a blankit- prefix. We do not use advertising cookies, analytics cookies, or cross-site tracking cookies. There is no Google Analytics, no advertising pixel, and no ad-network or data-broker tag anywhere on our site or in our product.
We do measure how our site and our product are used, without cookies and without sending anything to an analytics vendor. See Analytics below.
Strictly necessary.
These are required to sign in and use the platform. Blocking them will prevent you from logging in. All of them are HttpOnly, Secure, and SameSite=Lax, which means they are sent only to us, only over HTTPS, and cannot be read by JavaScript in your browser.
- Sign-in session — keeps an advisor signed in. Expires after 7 days.
- Plan-member portal session — the equivalent for the plan-member portal. Expires after 7 days.
- Two-factor, passkey, and re-authentication cookies — carry you through a two-factor prompt, a passkey ceremony, or a step-up check before a sensitive settings change. Each expires in 5 to 10 minutes.
- Trusted device — set only if you ask us to remember a browser, so you are not prompted for a second factor on every sign-in. Expires after 30 days, and is revoked whenever you change your password or alter your two-factor settings.
- Support impersonation — set only while a blankit administrator is working inside a firm's account at that firm's request, so we can return to our own account afterwards. Every such session is written to the audit log.
Functional.
- Chatbot visitor identifier — when a firm has enabled the plan-member chatbot, we set a randomly generated identifier so the firm's advisor can see how often the assistant is used. The value is an opaque random string: it holds no name, email, or IP address, it is not shared with anyone, and it is not used to build a profile or to follow you to any other site. It lasts only until you close your browser and is not retained across visits. The chatbot tells you about it on screen before it is set.
- Chat language preference — remembers the language you picked in the chatbot. Expires after 1 year. The same preference is also kept in your browser's local storage so it survives if the cookie is cleared.
Analytics.
We measure how our marketing site and our product are used. Both systems are ours, both run on our own servers in Montreal, and neither sets a cookie or sends anything to an analytics vendor.
- Site and product measurement — each page view records the page path (never the query string), the hostname of the external site that referred you if there was one, and a visitor identifier that is a one-way salted hash of your IP address and browser user-agent. The salt is rotated daily, so the identifier cannot be used to recognise you the following day or to follow you to any other site, and your IP address itself is never stored. Inside the signed-in product, page views are also attributed to the firm and user account, because a firm's administrator needs to see how their own team uses the platform.
- Marketing-site analytics — on our public marketing pages only, we run our own installation of Plausible Analytics on our own server in Montreal. It records the page, the referring site, any campaign parameters in the link you followed (for example utm_source), your country, and your browser, operating system and screen class. It sets no cookie, stores no IP address, and creates no identifier that persists beyond the day. Because it is self-hosted, no analytics company receives your data.
Neither system records your name, your email address, or anything you typed. Neither is used for advertising, and we do not sell or share what they collect. Because no cookies are involved, blocking cookies does not change what they record — if you have a question about either, contact our Privacy Officer below.
Third parties that set their own cookies.
Three vendors we embed set cookies from their own domains when their component loads or when you interact with it. We do not control those cookies and we do not receive them:
- Cloudflare Turnstile — bot and abuse protection on our public forms. Its cookies exist to tell a human from an automated script.
- Calendly — the meeting-booking embed on our marketing pages.
- Featurebase — the in-product feedback widget, where a firm has it enabled.
Each is listed in our sub-processor disclosure.
Your choices.
You can block or delete cookies in your browser settings. Blocking the strictly necessary cookies above will stop you from signing in; blocking the functional ones will not — the chatbot works normally without them, and it will simply count each visit as a new one. The chatbot visitor identifier clears itself when you close your browser, so there is nothing to opt out of across visits.