Falco Connectby Allondon Labs

Your data, explained

Cookies and privacy

Understand what Falco Connect uses to link your organization and your assistant.

Cookies the service needs

When you use the Falco Connect website pages, this version uses cookies for account sign-in, form security and your language choice. It adds no audience analytics or advertising cookies. This notice provides information; it does not ask you to consent to tracking.

Cookies the service needs
CookieWhat is it for?Lifetime of new cookies
falco_localeLanguage

Remembers the selected page language.

Browser session, with no persistent expiry date.
falco_csrf_sessionSecurity

Links the browser to form protection against unwanted requests.

1800 seconds (30 minutes), renewed when a protected form is opened.
better-auth.session_tokenSign-in

Identifies your account session after sign-in.

Browser session, with no persistent expiry date.
better-auth.dont_rememberSession mode

Keeps sign-in in nonpersistent cookie mode, including when the session is checked.

Browser session, with no persistent expiry date.

Sign-in through the Falco Connect website pages uses browser-session cookies. The account session on the server is capped at 24 hours. Under HTTPS, the two better-auth names begin with __Secure-. These cookies belong to this site and are protected against JavaScript access (HttpOnly).

Your account language

The language preference saved in your account is separate from the browser cookie. It restores your choice after sign-in. Deleting the cookie does not erase that preference. Simply opening a page in another language does not change the saved account language.

Your account

Your name, email address and the information needed for authentication are used to create your account and sign you in. The saved language is used to present the service in your chosen language.

Your Falco key

The API key you entrust to Falco Connect is stored encrypted. The server uses it for the Falco requests you authorize. You do not need to paste it into a conversation with your assistant.

What you authorize

You choose the connection and explicitly authorize the assistant. The permissions you choose allow business information reads and changes prepared for confirmation in your browser. The returned information is then shared with that assistant.

Business actions

Existing assistant authorizations keep their old permissions. Request and explicitly accept new permissions; your Falco API key also needs the matching upstream scopes. Downloads need the source read permission and file read access. Uploads need file write access.

Temporary files

Files, cached downloads, saved targets, actions and results are encrypted temporarily and accessible for at most 24 hours. Healthy cleanup targets physical deletion within 24 hours; outages can delay it. Replay tombstones last 7 days. This does not guarantee backup erasure.

What will happen

Writes and UBL debug validation are sandbox only. Each preparation or final check is limited to 16 reads in 30 seconds. Reviews are capped at 10 MiB + 64 KiB; an oversized review must be prepared with a narrower intention, without truncating fields.

Removing a connection

Removing a connection in Falco Connect deletes its stored active key and revokes the associated authorizations to prevent subsequent reads. This does not revoke the key at Falco or delete your account. Use Falco’s controls to invalidate the key there. A read that has already started is not cancelled retroactively.

This page’s typefaces

Bricolage Grotesque, Newsreader and Manrope are loaded from Google Fonts. These external requests share your IP address and the request data sent by your browser with Google. Font loading is separate from the cookies described here. No advertising cookies does not mean no external requests.

Manage cookies in your browser

You can view or delete this site’s cookies in your browser’s privacy settings. Deleting them removes browser sign-in and language state without deleting your account. Some browsers’ session restore features may keep session cookies after a restart. An older persistent language cookie is replaced when the language is next written. Older sign-in cookies are replaced at a fresh sign-in or removed at sign-out. Until replaced, they may retain their earlier behavior. Cookies in a dormant browser are not erased automatically.