Updated: 路 cookies-2026-09-11
01Operator and purposes
Swissi Holding AG operates the first-party storage listed below on the EAID website. Cookies support registration, authentication and language selection. Browser storage also retains presentation choices and cryptographic access material. Their permitted purposes are service delivery and security. Our core policy excludes selling personal information or sharing it for advertising or data brokerage.
Storage needed for a requested function operates for that function. A further use that requires consent must obtain it before that use begins. The Privacy policy governs the associated personal-data processing, recipients and your rights.
02Cookies
Cookies are sent to the site on requests within their domain and path, subject to browser security rules. Account cookies identify your registration or authenticated session.
| Name / provider | Purpose | Expiry |
|---|---|---|
| NEXT_LOCALE 路 Swissi EAID | Remembers the language selected for this website. | Browser session; session restoration can preserve it. |
| eaid-signup 路 Swissi EAID | Binds the browser to the current registration procedure. HttpOnly; Secure on HTTPS; SameSite=Lax. | 24 hours, or earlier when registration is completed or cancelled. |
| eaid_session 路 Swissi EAID | Authenticates your EAID account session. HttpOnly; Secure on HTTPS; SameSite=Lax. | 12 hours after signup; 24 hours after password or passkey sign-in. Signing out clears it. |
03Browser storage and device keys
Local storage and IndexedDB can persist after the browser closes. Session storage belongs to the tab session. Application code can read the relevant stored values and use them in service requests; storage location alone does not determine whether information is transmitted. All entries below are created by Swissi EAID.
| Storage / name | Purpose | Expiry |
|---|---|---|
| localStorage 路 theme | The light or dark appearance used on the site, including the initial default and any choice you make. | Until changed or cleared. |
| sessionStorage 路 eaid-signup-easy-login:{ceremonyId} | Tracks the device sign-in enrolment step for the current registration. | Tab session; browser session restoration can preserve it. |
| IndexedDB 路 swissi-eaid-signup-custody-v1 / bootstrap | Keeps registration key material and encrypted bootstrap state needed to resume the custody procedure. | Persistent; removed by clearing the relevant site data. |
| IndexedDB 路 swissi-eaid-qualified-device-v1 / device-keys | Stores the registered device鈥檚 cryptographic keys for approving and opening protected information. | Persistent; until removed from the browser鈥檚 site data. Server-side revocation separately ends the device鈥檚 authority. |
04Security checks
Vercel BotID Basic runs a browser challenge for protected registration requests. The browser submits the challenge response for validation; Vercel processes the technical request and challenge signals and returns a result used to admit or refuse the request. This processing supports abuse prevention.
The security check and hosting request can involve device information independently of the first-party cookie names above. A blocked challenge can prevent registration. Contact hello@swissi-ai.institute if a legitimate request is rejected.
05Your controls
Use the language and appearance controls to change those choices. Sign out to end the current account session. Browser settings let you inspect and remove individual cookies or site storage. Blocking required storage can prevent registration, sign-in or device approval.
Before clearing EAID site data, make sure you have working alternative access and your recovery material. Clearing IndexedDB can remove local keys needed to open protected information. Clearing cookies alone does not erase your account, revoke all devices or remove copies held by a recipient. Request account closure or exercise your data rights through hello@swissi-ai.institute.
06Passkeys and connected services
Passkeys can be held by the operating system, a hardware authenticator or your chosen credential provider. Manage deletion and synchronisation through that provider鈥檚 controls. Removing a browser cookie and deleting a passkey are separate operations.
A sign-in provider or connected service operates its own origin and storage under its own notice. Review that notice when using the connection. EAID鈥檚 policy governs the information EAID receives and processes.