> For the complete documentation index, see [llms.txt](https://help.getlfg.app/p/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://help.getlfg.app/p/agreements/cookie-policy.md).

# Cookie policy

**Effective date: 13th September 2026**

This Policy explains cookies and comparable device technologies used by **Layer Flow Gateway, Inc.**, 131 Continental Dr, Suite 305, Newark, DE 19713, United States. Contact **<legal@getlfg.app>**. Read it with our [Privacy Policy](https://help.getlfg.app/p/agreements/privacy-policy).

## 1. Our web applications

LFG’s own web applications currently use one strictly necessary authentication cookie, **lfg\_access**. They do not currently run optional website analytics, advertising pixels or behavioural advertising cookies.

| Item        | Purpose                                    | Provider         | Duration                                             |
| ----------- | ------------------------------------------ | ---------------- | ---------------------------------------------------- |
| lfg\_access | Maintain and validate authenticated access | LFG, first party | \[\[30 days; renewed when the user signs in again.]] |

The authentication cookie is needed for the sign-in service you request. You can block or delete it through your browser, but authenticated features may stop working. We do not ask you to accept optional cookies where none are used. Essential server security logs are described separately in the Privacy Policy.

LFG may use country, residence and account-eligibility information described in the Privacy Policy to apply the market and feature rules in the Global Availability Statement. This includes disabling USDT payments and swaps into USDT for EU/EEA customers. This is an access-control function, not advertising or behavioural profiling, and the cookie itself does not determine legal eligibility.

A help page, embedded checkout or other page operated by a third party may have its own technologies and notice. We identify the provider when you enter its service. Where LFG controls the loading of non-essential technologies that require consent, we obtain it before loading them. A provider relationship does not remove that responsibility.

## 2. Mobile technologies

| Tool      | Function and information                                                                                                               | Choice and retention                                                                                                                                                                                                                                         |
| --------- | -------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Sentry    | App error and crash diagnostics; configured event information can include device/app details, error context and identifiers            | Ordinary crash records are kept for up to 30 days. Optional diagnostic collection requiring consent is off until agreed and can be disabled in the app’s privacy controls. Necessary security processing is separately explained.                            |
| OneSignal | Deliver enabled notifications, using push tokens, relevant app/device identifiers, preferences and delivery or interaction information | Notification permission can be changed in device settings. Separate optional data collection is controlled through the app’s privacy choices. Unnecessary identifiers are removed within 30 days of opt-out or closure, and unwanted sending stops promptly. |

The fact that a tool reports crashes or delivers notifications does not make every use of that tool strictly necessary. We limit collection to the functions described and apply the relevant consent rules to optional device access or storage. An operating-system notification prompt does not authorise unrelated analytics or marketing.

Wallet and sign-in integrations may also use local secure storage necessary for functions you request. Wallet recovery material is not an advertising identifier. Before deleting the app or its local storage, export and retain the recovery phrase or appropriate private key for every wallet. LFG cannot recover the wallets afterwards if the required access material has not been retained independently.

## 3. Refusing or changing choices

You can refuse optional diagnostic or notification-related collection where offered and later change the choice in the app’s privacy settings. Where consent is required, refusing must be as straightforward as accepting. Withdrawing consent stops future optional collection; deletion of existing records follows the Privacy Policy and any applicable erasure right.

Device notification settings control whether notifications can be delivered. The app’s privacy controls additionally govern any separate optional collection. Closing the account stops account notifications; unsubscribing from marketing does not prevent a necessary contractual or security notice sent through an appropriate channel.

We do not use third-party behavioural advertising or sell device data to advertising brokers. If the tools or purposes change, we update this information and request any required new consent before the new processing begins.

## 4. Processing locations and contact

Sentry’s EU ingestion configuration does not establish that all processing by every vendor occurs in the EU. The Privacy Policy explains international transfers, data rights and safeguards. Questions or requests can be sent to **<legal@getlfg.app>**.

***
