Cookie & Tracking Notice.
Last updated: 2026-07-13
LifeSage LLC, a Washington limited liability company operating under the "Dharta" brand ("Dharta," "we," "us"), provides a business platform on which customers ("Customers") deploy, host, meter, and serve their own agents as durable kartas. This Cookie & Tracking Notice (this "Notice") explains how Dharta uses cookies, local storage, pixels, and similar technologies (collectively, "cookies") on Dharta's marketing websites, documentation, customer dashboard, billing pages, and related first-party web surfaces (the "Dharta Sites"). Capitalized terms not defined here have the meanings given in the Dharta Privacy Policy and the Dharta Terms of Service.
This Notice addresses only Dharta's own use of cookies on the Dharta Sites. It does not govern cookies, local storage, or other tracking technologies deployed by Customers on their own websites, applications, or agent experiences, including where a Customer embeds a Dharta agent surface (see Section 5).
1. Current Posture
Dharta currently uses cookies and similar technologies on the Dharta Sites only for strictly necessary purposes, such as authentication, session security, CSRF protection, abuse prevention, fraud prevention, rate limiting, and payment checkout support.
Dharta does not currently use advertising cookies, retargeting pixels, cross-site or cross-context tracking cookies, social-media tracking widgets, or third-party marketing trackers on the Dharta Sites, and Dharta does not sell or share personal information for cross-context behavioral advertising or use personal information for targeted advertising. Because the Dharta platform is offered for business and developer use only and the Dharta Sites are not directed to consumers, families, or children, Dharta does not knowingly use the Dharta Sites to collect information from any individual under 18.
2. Strictly Necessary Cookies
Strictly necessary cookies keep users signed in, protect sessions, prevent CSRF, secure checkout, and help detect abuse. These cookies are exempt from consent requirements under applicable law because they are essential to deliver a service the user has requested, and they cannot be disabled through Dharta controls because the Dharta Sites cannot function securely without them. You may block or delete cookies through your browser, but doing so may prevent sign-in, dashboard use, or checkout. Allocation of liability for use of the Dharta Sites is governed by the Dharta Terms of Service.
The strictly necessary cookies and similar technologies used on the Dharta Sites fall into the following categories:
| Cookie / family | Purpose | Party | Type / approximate retention |
|---|---|---|---|
| Dharta session cookie | Keeps the user signed in; maintains session state | First-party (Dharta) | Session or short-lived persistent (typically up to ~30 days) |
| CSRF / session-integrity tokens | Prevents cross-site request forgery; protects session integrity | First-party (Dharta) | Session |
| OAuth state / nonce | Secures the sign-in flow | First-party (Dharta) | Transient (cleared after sign-in) |
| Stripe checkout / fraud-prevention cookies | Enables and secures checkout; prevents payment fraud on billing pages | Third-party (Stripe) | Per Stripe; session and persistent (see Stripe's cookie/privacy notice) |
Cookies set by Dharta's payment processor, Stripe, on billing pages in the checkout context are third-party cookies governed by Stripe's own cookie and privacy notices. Cookie names and exact storage lifetimes may change as Dharta updates the Dharta Sites; the categories, purposes, and approximate retention described in this Notice continue to apply.
3. Security and Abuse Signals
Dharta may use device, browser, IP, origin, rate-limit, and request signals to protect accounts, Credits, Agents, embeds, and platform integrity. Dharta uses these signals for security and abuse prevention, not for advertising, profiling, or cross-site tracking. Where consent is not required because these signals are strictly necessary to provide a service the user has requested, Dharta processes them on the basis of its legitimate interests (and, where applicable, its legal obligations) in securing the Dharta Sites and preventing fraud and abuse.
4. Analytics
Dharta does not use analytics cookies on the Dharta Sites. Dharta uses OpenPanel, a cookieless, privacy-preserving analytics tool that Dharta self-hosts on its own infrastructure, to understand aggregate usage of its public documentation and marketing site; it sets no browser cookies, does not track users across sites, and analytics data is not shared with any third-party analytics provider. Dharta's public documentation site is delivered through Cloudflare's content-delivery and TLS edge, which processes site-visitor connection data such as IP address in order to deliver and secure the site. This website-infrastructure provider is identified in the Sub-processor List and the Privacy Policy. Dharta does not use advertising or cross-site tracking technologies. If Dharta later adopts analytics or other technologies that set non-essential cookies or require consent or an opt-out under applicable law, Dharta will provide any notice and controls required by applicable law before enabling them (see Section 7).
5. Customer Agents and Embeds
As between Dharta and the Customer, the Customer is responsible for all cookies, local storage, analytics, pixels, tracking technologies, and consent or preference mechanisms present on the Customer's own websites, applications, products, and agent experiences, including any surface on which the Customer embeds or links to a Dharta agent. As between the parties, and without limiting Dharta's own obligations as a processor or service provider under the Data Processing Agreement and applicable law, the Customer is responsible for providing all legally required cookie and tracking notices to, and obtaining all legally required consents and opt-outs from, its own end users on its own surfaces, and for honoring those end users' choices. The Customer represents and warrants that it has, and will maintain, all rights, notices, consents, and authorizations necessary for any cookies, tracking, or processing on its surfaces, and Dharta may rely on the Customer's compliance with these obligations. Dharta does not control, and is not responsible for, the Customer's surfaces or any third-party cookies or trackers the Customer or its end users place or encounter there.
Dharta's embeddable widget and hosted agent surfaces may use first-party cookies or local storage strictly necessary to establish and maintain the agent session, security, and integrity of the interaction; they do not deploy Dharta advertising or cross-site tracking cookies. The Customer's deployment, configuration, and disclosure obligations are governed by the Customer's agreement with Dharta (including the Data Processing Agreement, under which the Customer is the controller and Dharta is the processor for End-User Data). The Customer's indemnification and compliance obligations under that agreement apply to its handling of cookie and tracking disclosures and consents.
6. Your Choices
You can control cookies through your browser settings, including by blocking or deleting cookies. Blocking strictly necessary cookies may prevent sign-in, dashboard use, or checkout. Because the cookies on the Dharta Sites are strictly necessary, Dharta does not provide, and is not obligated to provide, a consent manager, cookie banner, or other granular in-product cookie controls on the Dharta Sites beyond the browser-level controls described here.
Because Dharta does not sell or share personal information, does not use personal information for cross-context behavioral advertising or targeted advertising, and does not use advertising cookies on the Dharta Sites, no opt-out (including via Global Privacy Control or any other opt-out-preference signal) is required to be exercised on the Dharta Sites. If that ever changes, Dharta will honor opt-out-preference signals to the extent required by applicable law.
Do Not Track. Web browsers may offer a "Do Not Track" ("DNT") setting. Because there is no common industry standard for how to interpret DNT signals, the Dharta Sites do not currently respond to DNT signals.
7. Changes
Dharta may update this Notice from time to time to reflect changes in its technologies, practices, or legal requirements. Dharta will post the updated Notice with a revised "Last updated" date. Changes that introduce non-essential cookies or tracking technologies requiring consent or an opt-out under applicable law will not take effect until Dharta has provided any notice and obtained any consent required by applicable law; other changes take effect when posted. Dharta may make changes that take effect immediately where necessary to address a security, fraud-prevention, or legal-compliance requirement. This Notice is informational and does not by itself create contractual obligations; nothing in it substitutes for the cookie consent that applicable law requires before any non-essential cookie is set.
8. More Information; International Transfers
This Notice supplements, and should be read together with, the Dharta Privacy Policy (which describes how Dharta handles account, billing, dashboard, support, and other platform-administration data as a controller) and the Data Processing Agreement (which governs End-User Data processed through a Customer Agent, for which the Customer is the controller and Dharta is the processor). Those documents describe applicable data-retention periods, data-subject rights (including the right to lodge a complaint with a competent supervisory authority), Dharta's subprocessors, and the safeguards Dharta uses for international data transfers, including the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, and the Swiss adaptations to the Standard Contractual Clauses. The Dharta Sites are served from Dharta's control-plane infrastructure, which is hosted in the United States. Because LifeSage LLC and its hosting are located in the United States, data collected through cookies on the Dharta Sites is processed in the United States. The Dharta Privacy Policy is the canonical source for the identity of Dharta's controller entity and any appointed EU/UK representative.
9. Order of Precedence; General
This Notice is informational and is intended to be read together with the Dharta Terms of Service, the Dharta Privacy Policy, and the Data Processing Agreement. In the event of any conflict between this Notice and those agreements, the Terms of Service (including its limitation-of-liability provisions) and the Data Processing Agreement govern with respect to the subject matter they address. Section headings are for convenience only and do not affect interpretation. If any provision of this Notice is held unenforceable, the remaining provisions remain in full force and effect.
Contact
Questions about this Notice: privacy@dharta.ai, or LifeSage LLC, 600 1st Ave Ste 102, PMB 2132, Seattle, WA 98104, USA. EU/UK data subjects may exercise their rights and lodge complaints as described in the Dharta Privacy Policy.