Cookie Policy
x-motion.io marketing website. Last updated: August 20, 2026. Consent policy version: 2026-08-19.
The consent policy version is unchanged because this update added no new cookie purposes or recipients. Choices already recorded under this version stay valid, and a refusal is never re-requested inside the storage period below.
This policy explains how the public x-motion.io marketing website uses cookies and similar browser storage. The separate product application at app.x-motion.io uses additional technologies needed for authentication, account features, demos, and security, and opens Paddle's checkout and customer portal, which set their own payment, fraud-prevention, and tax-calculation cookies under Paddle's Privacy Notice; those practices are described in our Privacy Policy.
Current position
The marketing website does not currently run advertising pixels, cross-site behavioral tracking, or optional analytics cookies. Optional functional, analytics, and marketing categories are available in the preference interface so future technologies cannot be activated silently. Any material new purpose requires a policy-version change and a fresh choice before activation.
Cookies currently used or conditionally set
| Name | Provider | Purpose | Category | Duration |
|---|---|---|---|---|
| xm_cookie_consent | X-Motion | Stores a signed receipt identifier, consent-policy version, timestamp, and category choices so the site can remember and enforce your decision. The host-only cookie is HttpOnly, uses SameSite=Lax, and is sent only over HTTPS in production. | Strictly necessary | 183 days (six months) |
| __cf_bm | Cloudflare | May be set when Cloudflare bot protection is active to distinguish automated traffic and protect the site. | Strictly necessary security | 30 minutes after inactivity |
| cf_clearance | Cloudflare | May be set after a security challenge to remember that the browser passed the challenge. | Strictly necessary security | Configured challenge period |
| _cfuvid | Cloudflare | May be set when a Cloudflare rate-limit rule needs to distinguish visitors who share an IP address. | Strictly necessary security | Configured security-rule period |
Conditional Cloudflare cookies appear only when the associated security feature or challenge is used. Cloudflare describes these cookies as necessary for its security and traffic-management services.
Consent categories
- Strictly necessary: consent memory, request security, abuse prevention, and delivery. These technologies do not require optional consent and cannot be disabled through the preference panel.
- Functional: optional convenience preferences beyond the service you explicitly request. No functional cookies are currently active on this marketing site.
- Analytics: optional measurement used to understand and improve marketing-site usage. No optional analytics cookies are currently active on this marketing site.
- Marketing: optional advertising or cross-context measurement. No marketing cookies or pixels are currently active on this marketing site.
How consent works
- Optional categories start disabled. Continuing to browse, scrolling, or closing a panel is not treated as consent.
- “Reject all” and “Accept all” are available at the same level, and “Customize” provides purpose-by-purpose controls.
- The “Cookie settings” control in the site footer remains available on every page so consent can be changed or withdrawn as easily as it was given.
- A refusal is stored for six months, and we do not ask again for the same purposes during that period.
- If a browser sends Global Privacy Control, marketing tracking remains disabled even if other optional categories are accepted. When that signal arrives after a broader choice was recorded, the site writes a new receipt so the stored record matches the signal.
- Our support for that signal is published in machine-readable form at /.well-known/gpc.json, as described by the Global Privacy Control specification.
Consent record and security
Each explicit decision creates a random subject ID and receipt ID, server timestamp, policy version, interface source, category choices, and Global Privacy Control status. The record is protected by an HMAC integrity value and stored in a restricted audit store. The public endpoint is protected by same-origin checks, an edge origin lock, strict request validation, body-size limits, and distributed per-client and site-wide rate limits.
Raw IP addresses, full user-agent strings, referrers, request headers, page histories, and browser fingerprints are not stored in consent receipts or application consent logs. A keyed, irreversible IP-derived value is used temporarily only for rate limiting. Consent audit records expire after 400 days; the browser preference expires after 183 days.
Your controls
Use the “Cookie settings” control in the footer of this website to review, reject, accept, or change optional categories. Clearing browser cookies removes the local preference and causes the site to ask again. Blocking all cookies in browser settings may also remove the preference cookie and can interfere with security features.
Contact and changes
Questions or privacy-rights requests can be sent to [email protected]. We will update the date and policy version when cookie purposes materially change and will request fresh consent where required.