Interface language

Legal

Cookie policy

Last updated

This policy lists every cookie and every item of browser storage that finmind.uz and the Finmind Telegram Mini App use, what each is for, how long it lasts and who sets it. It forms part of the privacy policy.

The short version: Finmind uses only the storage it needs to work. There are no analytics, advertising or tracking cookies, no third-party trackers and no consent banner theatre: because nothing here is optional, we show a short notice with a link to this page instead of asking you to accept something you cannot refuse.

1.Cookies

Finmind itself sets one cookie:

  • fm_locale (first party, functional). Remembers the interface language you chose (en or uz). Set by our server when you first open a page in a language, and by the language switcher. Lasts one year. SameSite=Lax, sent only over HTTPS. Not readable by anyone but finmind.uz.

Two more may appear only for staff: the Django administration pages at /admin, which ordinary users never open, use the standard sessionid and csrftoken cookies. The application itself does not use cookies to sign you in: your session is a token held in local storage (below).

finmind.uz is delivered through Cloudflare, which protects the site from attacks. Cloudflare may set a cookie of its own (such as __cf_bm or cf_clearance) while it checks a request for automated abuse; on 26 September 2026 none was observed on our pages. Such a cookie is set by Cloudflare under Cloudflare's cookie policy, not by us, and is used only to protect the site.

Back to contents

2.Local storage

Local storage stays in your browser until you sign out or clear your browser data. It is never sent to anyone; the page reads it. Finmind keeps:

  • ef-auth: your sign-in session (an access token valid for 30 minutes and a refresh token valid for 7 days), so a reload keeps you signed in. Removed when you sign out. ef-auth-refresh-lock is a marker so that only one open tab renews the session at a time.
  • ef-theme: the dark or light theme you chose.
  • ef-sidebar-collapsed, ef-sidebar-groups and ef-nav-recent: whether the sidebar is collapsed, which of its groups you folded, and the pages you opened recently, for the navigation menu.
  • ef-terminal-watchlist: the symbols on your terminal watchlist.
  • ef.dismissedAnnouncements: the platform announcements you dismissed.
  • fm_pending_ref: a referral code you arrived with, kept until you register.
  • fm_cookie_notice: that you have seen the storage notice, so it is not shown again.
  • tf: and per-view keys: the chart timeframe and the cards-or-list view you chose on a page.
  • fm-tg-session and fm-tg-pref:: in the Telegram Mini App only, which Telegram user this session belongs to and the Mini App's own preferences (such as its language).

Back to contents

3.Session storage

Session storage is cleared when you close the tab. Finmind keeps in it short-lived steps of a sign-in and per-tab dismissals:

  • fm.emailChallenge, oneid.flow, oneid.reauth and oneid.reauth.owner: the step you are in while confirming an email address, a second factor or a OneID sign-in. Removed when you sign out.
  • fm_locale_chosen: that you switched the language in this tab, so it wins over the language stored on your profile.
  • fm_social_twofa: a second-factor step handed from the registration page to the sign-in page after a Google or Telegram sign-in.
  • ef.onboardingBannerDismissed, ef.onboardingReminded and fm.verifyEmailBannerDismissed: banners you closed or were shown in this tab.
  • fm.trade.openChecks: the identifiers of orders whose outcome the page is still checking with your broker.
  • fm-tg-cache:: in the Telegram Mini App only, a short-lived cache of the screen you just read.

Back to contents

4.Third-party scripts and embeds

No script from anyone else runs on our pages, except where a feature needs it, and only on the pages that offer that feature:

  • Google Identity Services (accounts.google.com), which draws the "Sign in with Google" button. Loaded only on the sign-in and registration pages and under Sign-in methods in Settings, and only after the server says Google sign-in is offered; it is not loaded anywhere else. The button is a Google frame: Google may set its own cookies inside it under Google's privacy policy.
  • Telegram login (oauth.telegram.org or telegram.org), which opens the "Sign in with Telegram" window. Loaded on the same pages, only when the server offers Telegram sign-in.
  • Telegram Web App script (telegram.org), which every Telegram Mini App needs. Loaded only on /tg, inside Telegram.
  • Looker Studio (datastudio.google.com), the exchange's own dashboard, which the Top liquid stocks page can show as a Google frame. It is not needed for Finmind to work, so it is loaded only when you press "Show the dashboard here" on that visit; the choice is not remembered, and until you press it nothing is requested from Google. Once loaded, Google may set cookies inside that frame under its own policy.

Fonts are served from finmind.uz itself, not from Google Fonts. There is no analytics or advertising script, no pixel and no fingerprinting.

Back to contents

5.Your choices

Everything above is needed for the part of the service it belongs to, so there is nothing to opt into or out of, and we do not ask for consent for it. What you can do:

  • Sign out to remove your session from this browser.
  • Clear this site's data in your browser to remove everything else; the language and theme return to their defaults.
  • Block the Google or Telegram scripts with a browser setting or an extension: email sign-in keeps working and the page says the button could not load.
  • Open this page from the "Cookie policy" link in the footer at any time. The "Cookie settings" link shows the storage notice again.

If we ever add storage that is not needed for the service to work, we will ask for your consent before setting it, with equal choices to accept or refuse, and this page will list it.

Back to contents

6.Changes to this policy

We update this page whenever the code changes what it stores. The date at the top shows the latest version.

Back to contents

7.Contact

Questions about storage or privacy: Support in the app (Settings, then Support), the contact form on the home page, or [email protected].

Back to contents