mainbook.aimainbook.aimainbook.ai
FeaturesHow it worksProductPricing
Log InSign Up
  • Terms
  • API Terms
  • Privacy
  • Refunds
  • Disclaimer
  • DPA
  • AI Disclosure
  • AUP
  • Cookies
  • Sub-processors

Legal

  • Terms of Service
  • Developer API Terms
  • Privacy Policy
  • Refund Policy
  • Disclaimer and Important Notices
  • Data Processing Agreement
  • AI and Data Processing Disclosure
  • Acceptable Use Policy
  • Cookie Policy
  • Sub-Processors

Cookie Policy

Last Updated: 2026-08-10

Effective Date: 2026-08-10 for users first accepting the MainBook Terms on or after that date; 2026-09-10 for users who accepted an earlier version.

This Cookie Policy explains what cookies and similar technologies are used on the MainBook service ("Service") operated by Human Beyond LLC ("MainBook", "we", "us", "our"). This Cookie Policy is incorporated by reference into our Terms of Service and Privacy Policy.


1. Summary

  • We use a small number of cookies and similar local-storage items that are strictly necessary to provide the Service.
  • Only with your consent, we also use Google Analytics 4 cookies for first-party audience and traffic measurement, and the Meta Pixel (Facebook Pixel) cookies (_fbp / _fbc) for advertising conversion measurement.
  • We display a cookie-consent banner with equal Accept and Reject options. Strictly necessary cookies are always set (they are exempt from consent under EU ePrivacy Directive Article 5(3) and analogous laws); non-essential analytics and advertising cookies are set only if you accept them.
  • Until you accept, analytics runs cookieless (Google Consent Mode v2, advanced mode) and the Meta Pixel is held with consent revoked so it does not fire or set cookies — no analytics or advertising cookies are placed on your device.
  • You can change your choice at any time using the "Cookie settings" link in the footer of the Service.
  • A small number of third-party services (Cloudflare anti-fraud and Stripe payment processing) may set their own cookies, on their own domains, when their services are invoked. These are described below.

2. What Is a Cookie

A "cookie" is a small text file placed on your device by a website. We also use other local-storage technologies (browser localStorage and sessionStorage) which serve similar purposes. In this Cookie Policy, "cookie" includes all such technologies unless context indicates otherwise.

3. Cookies and Local Storage We Set

The following tables identify material cookies and browser-storage items set by our service (on mainbook.ai and api.mainbook.ai). We may also use short-lived authentication, purchase-flow, security, and user-interface state with the same purposes described below. Items in Sections 3.1–3.3 are strictly necessary for the operation of the Service.

3.1 Authentication cookies

NameTypePurposeDurationHTTP-only
access_tokenFirst-party cookieAuthenticated session — short-lived JWT access token~15 minutes (rotates)Yes
refresh_tokenFirst-party cookieAuthenticated session — refresh token used to obtain a new access token~7 days (rotates)Yes
mb_csrftokenFirst-party cookieCross-Site Request Forgery (CSRF) protection — issued together with the session and echoed back as a request header on state-changing requests (double-submit pattern)~7 days (rotates)No (by design — the JavaScript in the Service reads this cookie to set the matching request header)
oauth_state, oauth_link_token, and related OAuth stateFirst-party cookiesShort-lived Google OAuth login, account-linking, and reauthentication state; prevents login CSRF and binds a response to the initiating browserMinutesYes where supported

In production, these cookies have Domain=.mainbook.ai, Secure (HTTPS-only), and SameSite=Lax attributes.

3.2 Local storage (browser localStorage)

NamePurposeDuration
mainbook_cookie_consentYour analytics and advertising consent preference, including a denied statePersistent until cleared by you or changed through Cookie settings
mainbook_device_idPseudonymous persistent device identifier/fingerprint used to enforce guest-tier limits and prevent abusePersistent until cleared by you
mainbook_guest_sessionGuest-session state containing a session identifier, signed bearer credential, and expiry; it does not store the uploaded file itselfUntil expiry, reset, signup-linking, or clearing by you
mb_pending_plan and related purchase-flow stateRemembers the Credit package or return state selected while you authenticate or complete checkoutUntil the flow completes, expires, or is cleared by you
mainbook.conversion.divider_ratioUser-interface preference (position of the split divider on the conversion view)Persistent until cleared by you
Other interface/session preferencesDismissed notices, navigation state, purchase-event deduplication, and similar strictly necessary interface stateSession-only or persistent until the relevant flow ends or you clear it

3.3 Session storage (browser sessionStorage)

Our error-monitoring sub-processor (Sentry) may write transient session-storage entries for the duration of a browser tab to maintain diagnostic context across page navigations. These entries are cleared when the tab is closed. The client SDK is configured not to attach default PII and does not use session replay or performance tracing.

3.4 Analytics cookies (Google Analytics 4) — set only with consent

NameTypePurposeDurationHTTP-only
_gaGoogle AnalyticsDistinguishes users for audience and traffic measurement~2 years (Google default)No
_ga_<container-id>Google AnalyticsPersists Google Analytics session state for the specific measurement property~2 years (Google default)No

These cookies are set by Google Analytics only after you accept analytics cookies on our cookie-consent banner. Before consent (and if you decline), Google Consent Mode v2 may send cookieless event pings while analytics and advertising storage are denied, but no analytics cookie or persistent Google Analytics client identifier is placed on your device by us. With consent, browser events and consent-linked backend purchase events may tell Google which pages or product features were used and may include funnel stages, counts and categories, an opaque job or transaction identifier, Credit-package code and page quantity, and the price or amount paid for a MainBook Credit purchase. Google may also receive your Google Analytics client identifier, page URL, device/browser metadata, and your IP address momentarily to derive approximate location. We do not transmit uploaded statements, row-level Output, or the transaction descriptions, amounts, or balances extracted from your statements to Google Analytics.

3.5 Advertising cookies (Meta Pixel) — set only with consent

NameTypePurposeDurationHTTP-only
_fbpMeta PixelBrowser identifier used for advertising conversion measurement and audience building for our Meta (Facebook/Instagram) ad campaigns — set only with consent~90 days (about 3 months)No
_fbcMeta PixelAd-click identifier — set only if you arrive from a Meta ad link that carries a click parameter (fbclid), and only with consent~90 days (about 3 months)No

These cookies are set by the Meta Pixel only after you accept advertising cookies on our cookie-consent banner. Before consent (and if you decline), the Meta Pixel library may load but consent is held revoked, no event fires, and no Meta cookie is set on your device. With consent, browser Pixel events and consent-linked backend Conversions API events may send Meta your _fbp / _fbc identifiers, page URL and referrer, IP address, device/browser metadata, and funnel events such as registration, file upload, conversion, warning status, export, package selection, checkout, and purchase. Parameters may include counts and categories, page count, document kind, export format, Credit-package code, a deduplication identifier, and the price or amount paid for a MainBook Credit purchase. We do not enable Advanced Matching or send hashed email, phone number, or name. We do not transmit uploaded statements, row-level Output, or the transaction descriptions, amounts, or balances extracted from your statements to Meta.

4. Third-Party Services

The following third-party services may set cookies on their own domains when their services are invoked through the Service. These are not cookies on the mainbook.ai domain; they are cookies set by the third party on the third party's own domain.

4.1 Cloudflare Turnstile (anti-fraud)

When the Service requires verification that you are a human user (for example, on signup or guest upload), it loads the Cloudflare Turnstile widget from challenges.cloudflare.com. Cloudflare may set its own anti-fraud and bot-management cookies (such as __cf_bm, cf_clearance, and challenge-related cookies) on Cloudflare's own domain. These cookies are operationally essential to anti-fraud protection of the Service.

4.2 Stripe Checkout (payment processing)

When you initiate a purchase of Credits, you are redirected to the Stripe-hosted checkout page on checkout.stripe.com (or a related Stripe-controlled domain). Stripe sets its own cookies on Stripe's own domain to operate the checkout. These cookies are not on the mainbook.ai domain. When the checkout completes, you return to the Service. We do not store your full payment card details.

For more information about Stripe's cookies, see Stripe's Cookie Policy.

4.3 Sentry (error tracking, server-side primarily)

We use Sentry for error tracking. Our Sentry client-side configuration is minimal: no session replay, no performance tracing, and no default PII attachment. In this configuration Sentry does not set cookies on the mainbook.ai domain; it may use transient session storage (see Section 3.3).

4.4 Google OAuth (only if you sign in via Google)

If you choose to sign in to MainBook using Google, you will be redirected to Google's authentication flow on Google-controlled domains, which may set their own cookies. After authentication, you return to the Service. We do not control Google's cookies.

5. Analytics and Advertising With Your Consent; No Session-Replay

We use Google Analytics 4 for audience, traffic, product-funnel, and purchase measurement, and the Meta Pixel plus consent-linked Meta Conversions API events for advertising conversion measurement. Consent-dependent collection is enabled only with your consent, given through our cookie-consent banner. Until you accept, Google Consent Mode may send cookieless event pings while storage is denied (no _ga cookie or persistent Google Analytics client identifier is set by us), while Meta consent remains revoked so no Meta event fires and no Meta cookie is set. When you consent, Google receives the consent signals (analytics_storage, ad_storage, ad_user_data, and ad_personalization), and Meta may set _fbp and, where applicable, _fbc, as described above. Rejecting, withdrawing consent, or sending a Global Privacy Control signal immediately forces the browser's effective state to denied, expires known analytics/advertising cookies that we can remove from our domain, and prevents identifiers from being attached to a new upload or checkout flow. We also send that denial to our backend. Once it is recorded by our server, pending consent-linked backend conversion or purchase events are rechecked at send time and are not sent. If the device is offline or the update temporarily cannot reach our server, the backend cutoff begins when the server records the denial; processing and event sends completed before that time remain unaffected.

We do not use:

(a) session-replay or behavior-recording tools (such as Hotjar, FullStory, or Microsoft Clarity);

(b) the Meta Pixel's Advanced Matching feature — we do not send hashed email, phone number, or name to Meta; the only advertising or social-media tracking pixel we use is the consent-gated Meta Pixel described in Sections 3.5 and 5 (we do not use any other ad or social pixel);

(c) cookies to build profiles of you for any purpose other than the consent-based analytics and advertising-measurement described above.

We do not sell your personal information for money. Where you consent to analytics and advertising cookies, certain online identifiers (such as a Google Analytics client identifier, the Meta Pixel _fbp / _fbc cookie values, and related cookie data) are shared with Google and Meta for analytics and advertising-measurement purposes; depending on your jurisdiction this may be treated as "sharing" for cross-context behavioral advertising under the California Consumer Privacy Act or other U.S. state privacy laws. You can decline this at any time by choosing Reject on our banner, by changing your choice via the footer "Cookie settings" link, or by sending a Global Privacy Control signal — each of which we honor.

6. Cookie Consent Banner

We display a cookie-consent banner. By default, non-essential (analytics and advertising) cookies are denied until you make a choice — no analytics or advertising cookies are set unless and until you accept them. The Accept and Reject options are presented with equal prominence.

Your choice is stored locally and is not re-prompted on every visit. You may change your choice at any time using the "Cookie settings" link in the footer of the Service; choosing to decline previously accepted analytics or advertising cookies withdraws your consent going forward.

Strictly necessary cookies (authentication, CSRF protection, anti-fraud, payment processing, and the technical operation of the guest mode and conversion view) remain exempt from consent under the EU ePrivacy Directive (Article 5(3)), the GDPR, the UK ePrivacy Regulations, and analogous U.S. state privacy laws, and are always set.

7. How to Control Cookies

You can control cookies through your browser settings:

  • Most browsers allow you to refuse, accept, or delete cookies by adjusting their settings;
  • You can clear localStorage and sessionStorage from your browser settings or developer tools.

If you disable or delete the cookies set by the Service, parts of the Service will not work — for example, you will not stay logged in, and certain anti-fraud and security protections will not function. The Service is not designed to operate without these strictly necessary cookies.

8. Updates to This Cookie Policy

We may update this Cookie Policy from time to time to reflect changes in our cookie practices, third-party services, or applicable law. The "Last Updated" date at the top reflects the date of the most recent change. Material changes take effect on at least thirty (30) days' notice; non-material changes take effect upon posting.

9. Contact

For questions about this Cookie Policy:

Human Beyond LLC Email: hello@human-beyond.ai

mainbook.aimainbook.ai

Convert PDF bank statements to Excel and CSV with automatic reconciliation. Built for bookkeepers, accountants, and anyone who works with financial data.

support@mainbook.ai

Product

  • Formats
  • Features
  • How it works
  • See it in action
  • Bank statement to Excel
  • Bank statement API
  • MCP server
  • Security
  • Pricing
  • Compare
  • Supported banks

Legal

  • Terms of Service
  • Privacy Policy
  • Refund Policy
  • Data Processing Agreement
  • Cookie Policy
  • Sub-Processors

© 2026 mainbook.ai. All rights reserved.

Bank-grade TLS 1.3 + AES-256 encryption