Cookie Policy
Effective date: August 27, 2026 · Version 1.1
This Cookie Policy explains the cookies and similar technologies used on the Bekap marketing site (bekap.io) and the Bekap application (app.bekap.io), both operated by OhMyLabs LLC. It should be read together with our Privacy Policy.
1. What cookies are
A cookie is a small text file placed on your device by a website. Cookies allow a site to recognize your browser between requests, which is what makes it possible to stay logged in, to protect a session against tampering, to remember a preference, or to measure how a site is used. Similar technologies, such as local storage and client-side scripts that read device signals, can serve comparable purposes and are covered by this policy where we use them.
2. Our approach
We draw a firm line between the two properties covered by this policy. The Bekap application at app.bekap.io, where you sign in and manage backups, uses only strictly necessary cookies - we do not run analytics, advertising or tracking technology there, in any form. The Bekap marketing site at bekap.io, meaning this page and the other public pages that describe and sell the product, additionally uses Google Analytics, but only once you have accepted it through the consent banner described in section 4. Nothing on the marketing site sets an analytics cookie or contacts Google before you accept, and you can decline or withdraw acceptance at any time. We do not use advertising cookies, social media cookies, or cookies that track you across other websites, on either property.
3. The cookies we set
The two cookies below are first-party cookies set directly by the application. Both are HTTP-only, meaning they cannot be read by scripts running in your browser, and both use the SameSite=Lax attribute, which prevents them from being sent on most cross-site requests.
| Cookie | Purpose | Category | Expiry |
|---|---|---|---|
| bekap_session | Maintains your authenticated login session so you do not have to re-enter credentials on every request. | Strictly necessary | Configurable per organization, from 30 minutes to 24 hours; 2 hours by default. |
| active_org_id | Remembers which organization you last worked in, so the correct workspace loads when you return. Relevant mainly to users who belong to more than one organization. | Strictly necessary (functional) | 365 days. |
The session cookie is marked Secure, meaning it is only transmitted over an encrypted connection. The organization preference cookie is marked Secure in our production environment.
4. Analytics cookies on the marketing site
The marketing site at bekap.io uses Google Analytics 4, provided by Google LLC, to understand how visitors find and use the site - for example, which pages are viewed and roughly how visitors arrived. This applies only to the public marketing pages; it is never active on app.bekap.io or on any white-labelled deployment of the application.
Google Analytics does not load, and no analytics cookie is set, until you click "Accept" on the cookie banner shown on your first visit. If you click "Reject," or close the banner without choosing, no analytics request is made and no cookie is set. Your choice is remembered in your browser's local storage, not a cookie, so it persists until you clear your browser's site data.
| Cookie | Set by | Purpose | Category | Expiry |
|---|---|---|---|---|
| _ga | Google Analytics | Distinguishes unique visitors for aggregate usage statistics. | Analytics (consent-based) | Up to 2 years. |
| _ga_<container-id> | Google Analytics | Persists session state for Google Analytics 4 property-specific reporting. | Analytics (consent-based) | Up to 2 years. |
We configure Google Analytics with IP anonymization enabled. We have not enabled Google Signals, advertising features, or cross-device or cross-site ad personalization, and we do not use Google Analytics data for advertising. Data collected is transmitted to and processed by Google LLC in the United States; Google is self-certified under the EU-US Data Privacy Framework. See section 10.1 of our Privacy Policy for how Google Analytics fits into our broader list of sub-processors.
You can withdraw or change your choice at any time using the button below, which reopens the consent banner.
5. Third-party technology in your browser
Cloudflare, Inc. operates the content delivery network and DNS in front of both bekap.io and app.bekap.io, and provides baseline network-level security such as TLS termination, DDoS protection and request routing for every visitor. This does not, on its own, set a cookie in your browser - it is connection-level processing of your IP address and standard HTTP request metadata, described further in our Privacy Policy.
We separately use Cloudflare Turnstile, a bot-mitigation widget, on our sign-up and forgotten-password pages on app.bekap.io. Turnstile runs as a script in your browser and distinguishes human visitors from automated abuse without presenting a puzzle. It is a security control, not an advertising or analytics tool. Our own code does not set a Turnstile cookie. Any cookie, local storage entry or device signal that the Turnstile script itself uses is set by Cloudflare and governed by Cloudflare's own privacy notice. We disclose it here because it executes in your browser on pages we serve, and we would rather over-disclose than leave you to discover it.
5.1 Planned: Cloudflare bot-management cookies
We plan to enable additional Cloudflare bot-management features - Bot Fight Mode (or Super Bot Fight Mode) and Managed Challenge / custom WAF challenge rules - across bekap.io and app.bekap.io. As of the effective date above, these are not yet enabled and the cookies below are not currently set. We publish this table in advance so the policy stays accurate the moment we turn them on, and we will update the effective date when we do.
| Cookie | Set by | Purpose | Category | Expiry |
|---|---|---|---|---|
| __cf_bm | Cloudflare (Bot Fight Mode / Super Bot Fight Mode) | Distinguishes legitimate human and bot traffic from malicious bots, site-wide. | Necessary (security) | 30 minutes. |
| cf_clearance | Cloudflare (Managed Challenge / WAF custom rules) | Records that a visitor has completed a security challenge, so they are not re-challenged on the next request. | Necessary (security) | Up to 1 year. |
Both are set directly by Cloudflare's edge network as part of distinguishing legitimate traffic from automated abuse, not by our own application code. We treat them as necessary for security in the same way as Turnstile above, rather than routing them through the analytics consent banner described in section 4: their purpose is fraud and abuse prevention, not measurement or advertising, which is a recognized basis for processing without consent under Article 5(3) of the ePrivacy Directive. If our use of them expands beyond security purposes, we will revisit that position and this policy.
Other than Google Analytics on the marketing site as described in section 4, no other third-party script runs on either property. In particular, we do not embed advertising pixels, session-replay tools, heatmaps or social sharing widgets anywhere.
6. Why the application does not show a cookie banner, and the marketing site does
Under Article 5(3) of the ePrivacy Directive and equivalent national implementations, consent is not required for storage that is strictly necessary to provide a service the user has explicitly requested. Every cookie the application sets falls within that exemption: two maintain an authenticated session, and the third remembers a workspace selection that the interface cannot function correctly without for multi-organization users. No banner is shown there because there is no optional storage to consent to.
The analytics cookies described in section 4 are not strictly necessary, so they do not qualify for that exemption. That is why the marketing site shows a consent banner before Google Analytics loads, and why your choice - accept or reject - is honored rather than assumed.
7. Managing cookies
You can block or delete cookies through your browser settings. Most browsers allow you to refuse all cookies, refuse third-party cookies only, or clear cookies on exit. The relevant controls are usually found under privacy or security settings.
Blocking the cookies described in section 3 will prevent you from logging in and using the Service. Because they are strictly necessary rather than optional, we cannot offer an in-product opt-out for them: there is no version of the Service that works without a session cookie.
You can decline or withdraw Google Analytics on the marketing site at any time using the "Manage cookie preferences" button in section 4, without affecting your ability to use the marketing site or the application. We do not sell or share personal information for cross-context behavioral advertising, and we do not honor Global Privacy Control as an additional signal because rejecting our consent banner already achieves the same result.
8. Cookies and personal data
The session cookie is linked to your account, and session records associated with it include your IP address, user agent and session timestamps. That data is used for authentication and security, and is described in our Privacy Policy, including the legal basis on which we process it and how long we keep it. Where you accept Google Analytics, your browser and usage data on the marketing site is processed under the legal basis described in section 4 above and section 8 of our Privacy Policy.
9. White-labelled deployments
Where you access the Bekap application through a managed service provider's own branding and domain, the same two application cookies are set, on that domain. Google Analytics, described in section 4, is never active on a white-labelled deployment - it runs only on the bekap.io marketing pages we operate ourselves. Your relationship for privacy purposes is with the managed service provider, which decides how the platform is used to serve you. This policy describes the underlying technology; the provider's own privacy and cookie notices govern its use of it.
10. Changes to this policy
We will update this policy if our use of cookies changes. Material changes will be notified by email to registered account contacts or by in-product notification. The effective date above shows when this policy was last revised.
11. Contact
Questions about this policy can be sent to:
OhMyLabs LLC
75 E 3rd St, Sheridan, WY 82801, United States
Email: legal@bekap.io