Cookie Policy
Last updated: 18/09/2026
We use cookies and similar storage (localStorage, sessionStorage) to run the Service and, with your consent, to understand product usage. You control non-essential categories from the banner or the button below at any time.
Categories we use
| Category | Purpose | Basis | Retention |
|---|---|---|---|
| Strictly necessary | Sign-in session (Supabase auth token), security (CSRF), consent record. | Exempt from consent (PECR reg. 6(4)). | Session - 12 months |
| Analytics | Aggregate product usage to improve features. Off by default. | Consent (Art. 6(1)(a)) | Up to 14 months |
| Marketing | Reserved for future ad measurement. Not currently active. Off by default. | Consent (Art. 6(1)(a)) | Not applicable today |
Exactly what we store in your browser
| Name | Type | Purpose | Lifetime |
|---|---|---|---|
| cce.consent.v1 | localStorage | Remembers your cookie choices. | 6 months, then we ask again |
| sb-*-auth-token | localStorage | Keeps you signed in. Strictly necessary. | Until you sign out |
| cce.analytics.session | sessionStorage | Random visit marker so page views can be grouped into one visit. Only set after you accept analytics. Contains no personal data. | Cleared when you close the tab |
Visitor statistics never store your IP address. We derive a one-way code from a daily-rotating secret purely to count unique visitors, and all visitor records are deleted automatically after 14 months.
Do Not Track / Global Privacy Control
If your browser sends a Global Privacy Control (GPC) signal, we treat it as an opt-out of analytics and marketing. This satisfies the CCPA/CPRA "Do Not Sell or Share" right, which is a right we honour globally even though we do not sell personal data.
Third-party cookies
Payment processing and OAuth sign-in with Microsoft/Google may set cookies on their own domains during checkout or connector authorisation. Those are governed by the respective providers' cookie policies.