Skip to content
LegalBinds: Everyone who uses this website

Cookie Policy

Every cookie and browser-storage identifier this site sets, named, with what it is for and how long it lasts — plus an honest statement of what the analytics loader currently does, which is nothing.
Section 01

What this covers

“Cookies” here means cookies and everything that behaves like one: values stored in your browser’s local storage and session storage, and any tag or pixel loaded from another company. All three can identify a browser, so all three are listed.

This covers xex.to and the consoles and portals served from it. An operator running a programme on its own domain publishes its own notice; where it configures its own analytics or advertising tags, those are its responsibility and are covered in the last section.

Section 02

The consent model

Nothing that is not strictly necessary loads before you decide. That is a property of how the site is built, not a policy statement: no analytics or advertising script element is created, and no request to an analytics or advertising host is made, until a consent decision exists.

  • Before you decide: zero requests to any analytics or advertising host, zero scripts created, and no cookie set beyond the strictly necessary ones a signed-in session needs.
  • Accept all: the purposes you accepted are enabled and their tags load.
  • Reject non-essential: nothing loads, and the site works exactly the same. There is no cookie wall, no degraded mode and no repeated prompt.
  • Choose: per-purpose control, with every optional purpose off until you turn it on.
Consent is a decision you can take back

Your decision is recorded and honoured on your return. You can change or withdraw it at any time from the Cookie preferences control in the site footer, on every page. Withdrawing does not affect what happened while consent was in force.

Section 03

Strictly necessary — set without consent

These exist because the site cannot do what you asked without them: keep you signed in, know which programme you are looking at, avoid taking a payment twice, and remember that you already answered the consent question.

NameKindWhat it is forLifetime
xex-consentLocal storage · first partyYour consent decision itself. Without it you would be asked again on every page — which is why a consent record is itself strictly necessary.Until you change it or clear your browser storage.
xex_member_tokenCookie · first party · HttpOnly, Secure, SameSite=StrictYour member session for the programme you are signed in to. Set only after you sign in.Expires with the session token it holds.
xex_member_wsCookie · first party · HttpOnly, Secure, SameSite=StrictWhich programme the active session belongs to, so the portal shows that programme's data and not another's.Same as the session token.
xex_member_sessionsCookie · first party · HttpOnly, Secure, SameSite=StrictA map of the programmes you are signed in to, so one browser can hold more than one membership without signing out of the others.Same as the session tokens it holds.
xex_link_tokenCookie · first party · HttpOnly, Secure, SameSite=StrictA short-lived token held while you link an account to a programme. It authorises nothing on its own until you confirm the link.Ten minutes, or until the link is confirmed.
xex_op_tokenCookie · first party · Secure, SameSite=Strict — written by the console's sign-in gate in the browser, so unlike the member cookies it is not HttpOnlyYour operator console session. Set only after an operator signs in.One hour, then re-issued while you stay signed in.
xex_op_wsCookie · first party · HttpOnly, Secure, SameSite=StrictWhich workspace an operator is currently working in.30 days, or until you switch workspace.
xex_magiclink_emailLocal storage · first partyThe email address a sign-in link was sent to, so the link can be completed in the same browser. Removed once sign-in completes.Until sign-in completes.
xex_central_redirectSession storage · first partyMarks that a sign-in redirect is in flight, so returning from the identity provider is not mistaken for a fresh visit.Until the browser tab is closed.
xex_buy_ref:…Session storage · first partyThe idempotency reference for one checkout attempt, keyed by package, payment rail and asset. It is what stops a reload creating a second invoice on the operator's payment account.Until the browser tab is closed.
xex_buy_intent:…Session storage · first partyThe identifier of the payment attempt in flight, so a reload resumes the payment instructions instead of stranding a live intent you can no longer see.Until the browser tab is closed.
xex.guide.seenToursLocal storage · first partyWhich in-product tours you have already dismissed, so they are not shown again.Until you clear your browser storage.

Nothing in this table is used for analytics, profiling or advertising, and none of it is shared with a third party.

Section 04

Optional — only after you consent

As at this draft: nothing here loads at all

The analytics loader on this site is currently a stub. It records which tags would have fired for the consent you gave, and loads none of them. That means that today, even after accepting, no analytics or advertising request leaves your browser from this site. This section describes what will load when that work is completed, and it will be corrected if the plan changes.

PurposeWhat would loadIdentifiersLifetime
analyticsGoogle Analytics 4, loaded from googletagmanager.com, with advertising signals denied by default._ga, _ga_<measurement id>[[ To be suppliedanalytics cookie lifetime once configured ]]
advertisingNothing on this website. Advertising destinations exist only in the per-programme tracking configuration described below, and are the operator's.

Where analytics is enabled, the events sent are limited to page views and a small set of product events (which plan was selected, that a workspace was created, that a programme page was viewed). No email address, member identifier or workspace identifier is sent.

Section 05

What happens if you refuse

Nothing. Every page, every programme listing and every sign-in works identically with consent refused. There is no cookie wall on this site, no content held back, and no repeated prompting for a decision you already made.

Refusing does not remove the strictly necessary items above, because those are not consent-based: without them you could not stay signed in, and the site could not remember that you refused.

Section 06

Changing or withdrawing your decision

Use the Cookie preferences control in the footer of any page. It reopens the banner with your current choices, and saving replaces the previous decision.

You can also clear site data in your browser, which removes every item in the first table including the consent record — after which you will be asked again.

Section 07

Tags an operator configures on its own programme

An operator can configure its own measurement and advertising destinations for its programme — a Google Analytics property, a tag manager container, a Meta pixel, a TikTok pixel, or Google Ads conversions. Where it does:

  • those tags are the operator's, on the operator's accounts, under the operator's own cookie notice;
  • the same consent gate applies — nothing fires for a member who has not given the matching purpose, and server-side conversion forwarding is refused without advertising consent; and
  • questions about them go to the operator, not to XEX, because the operator decides why they are there.

The data-protection position for those tags is set out in Privacy Policy and in the Data Processing Addendum.