Legal

Cookie and Browser Storage Policy

A precise disclosure of the cookies, local storage, session storage, service workers, caches, and device permissions used by Caseflow and Family Portal.

Legal

Cookie and Browser Storage Policy

A precise disclosure of the cookies, local storage, session storage, service workers, caches, and device permissions used by Caseflow and Family Portal.

Last updated: August 28, 2026

1. Scope

This policy covers information stored on or read from a browser or device when you use the Service. The term cookies includes comparable browser storage where the same legal rules apply.

2. Strictly Necessary Storage

  • Authentication and security: Firebase authentication state, App Check/reCAPTCHA tokens, session identifiers, impersonation safety state, and anti-abuse signals used to sign users in and protect requests.
  • Language and accessibility: the caseflow-locale cookie and local language, theme, and text-size preferences. The locale cookie lasts up to one year; local preferences remain until cleared or replaced.
  • Workspace operation: table settings, draft UI state, selected records, navigation state, timer state, document-editor state, and limited local record caches needed for requested features.
  • Installable app: service workers, Cache Storage, and cached application assets used for installation, updates, performance, and limited offline-tolerant shell behavior.
  • Device permissions: browser-controlled camera, microphone, notification, and file permissions are requested only when you activate the related scanning, voice, upload, or notification feature.

3. Third-Party Storage

Firebase and Google reCAPTCHA/App Check may store or read identifiers and security signals. Stripe may use its own necessary storage on hosted checkout or billing pages. Connected providers may use storage on their own pages during OAuth or payment flows. Their policies apply on those pages.

4. Analytics and Advertising

The current web application does not initialize Google Analytics and does not use advertising or cross-site behavioral tracking cookies. A Firebase measurement identifier may be configured without activating analytics. If non-essential analytics, advertising, or similar technology is introduced, it must remain disabled until the required consent choice and updated disclosure are available.

6. Your Controls

  • Use browser controls to inspect or delete cookies, site data, local storage, service workers, and permissions.
  • Sign out before using a shared device. Clearing authentication storage may sign you out; clearing preferences resets the interface.
  • Blocking necessary storage may prevent sign-in, security checks, uploads, notifications, or installable-app behavior.
  • Withdraw a device permission in browser or operating-system settings at any time.

7. Changes and Contact

We update this policy when storage technology or purposes change. For questions, use the public Support page or in-app Support Center.

Caseflow public contact: Atul Goel · Wittenkamp 24, 22307 Hamburg, Germany · +49-15560061837 · info@caseflow.my.