This policy supplements the Privacy Policy. Effective 18 August 2026. Version 2026-08-18.
1. What we use
| Name | Type | Why | Duration |
|---|---|---|---|
| icmAccessToken / icmRefreshToken | localStorage | Keep you signed in to the workspace | Until you sign out or we rotate tokens |
| icmTheme | localStorage | Remember light or dark theme | Until you change it or clear the site |
| icmAuthHeroPair | sessionStorage | Keep the same sign-in poster for this tab | Until the tab closes |
| Google OAuth state | Cookie (HttpOnly, short-lived) | CSRF protection for Google Sign-In | Minutes, then deleted |
Older keys named careerLabs* are migrated once to the icm* keys and then removed. Referral codes may be stored briefly so a sign-up can attach a referral.
2. Why we do not show a marketing cookie banner
EU/UK ePrivacy rules require consent before non-essential cookies. Strictly necessary cookies (sign-in, security, load balancing) do not need that consent. We do not set advertising, social, or product-analytics cookies, so there is no optional cookie to accept. India's DPDP Act does not require a separate cookie banner when the only storage is needed to provide the service you requested.
If you buy credits, Stripe Checkout runs on stripe.com and sets its own strictly necessary cookies to complete Strong Customer Authentication and fraud checks. Those cookies are Stripe's, not ICM's.
3. How to control storage
- Sign out to drop access and refresh tokens from this browser.
- Use your browser settings to clear cookies and site data for career-matrix.com.
- Blocking all cookies will break Google Sign-In and may break staying signed in.
4. Contact
Questions: support@career-matrix.com. Website: https://career-matrix.com.