| Effective Date | [TBD — set on publish] |
| Last Updated | [TBD — set on publish] |
| Version | v0.1 |
| Controller | CronosPMC LLC (UAE formation no. 2219381), Shams Business Center, Sharjah Media City Freezone, Sharjah, UAE |
| Contact | [TBD — privacy@[domain]] |
1. What are cookies (and similar storage)?
"Cookies" are small text files stored on your device by your browser when you visit a website. "Similar storage technologies" include localStorage, sessionStorage, IndexedDB, web beacons, and pixel tags. This Policy uses "cookies" to mean both, except where the distinction matters.
We use cookies and similar storage to keep you logged in, remember your preferences, detect abuse, and (with your consent) improve the Service through analytics and error monitoring.
2. Categories We Use
We classify cookies and similar storage as either strictly necessary (no consent required under PECR / ePrivacy Directive / equivalent) or non-essential (consent required, with equal Reject/Accept prominence on our consent banner).
2.1 Strictly Necessary
These are required to operate the Service. You cannot opt out, but you can clear them from your browser settings (doing so will log you out).
| Cookie / storage | Set by | Purpose | Duration |
|---|---|---|---|
sb-* (Supabase Auth) | Model Council (first-party) via Supabase | Keep you logged in; authenticate API requests | Session + 1-week refresh |
theme (localStorage) | Model Council | Remember dark/light mode preference | Persistent (until cleared) |
cookie-consent (localStorage) | Model Council | Remember your cookie consent choice | Persistent (until cleared or policy changes) |
__vercel_live_* | Vercel | Edge routing, deployment continuity | Session |
2.2 Non-Essential — Consent Required
These are disabled by default and only set if you accept them via our consent banner. You can change your choice at any time via the "Manage cookies" link in our footer.
| Cookie / storage | Set by | Purpose | Duration | Tier |
|---|---|---|---|---|
| Performance error tracking (Sentry) | Sentry (third-party) | Capture JavaScript errors and stack traces to help us fix bugs. PII fields scrubbed before transmission. | 90 days | Paid + Free (if you opt in) |
| Session replay (Sentry) | Sentry | Record sanitised user sessions so we can reproduce reported bugs visually | 90 days | Paid tier only |
| Product analytics ([TBD — PostHog / Plausible / not used at launch]) | TBD | Aggregate, non-identifying usage analytics (page views, feature usage funnels) | 12 months | All tiers if user opts in |
We do not use:
- Third-party advertising cookies
- Retargeting / behavioural-advertising pixels (Meta Pixel, Google Ads, X Pixel, LinkedIn Insight)
- Social-media "share" widgets that set tracking cookies
- Cross-site tracking of any kind
3. Your Choices
3.1 Consent Banner
On your first visit (and after material changes to this Policy), you see a consent banner with equal Reject and Accept buttons at the same level of prominence. You may:
- Accept all — enable analytics + error tracking (subject to tier eligibility above)
- Reject all — only strictly necessary cookies are set
- Customise — granular per-category toggles
3.2 Withdraw Consent
You can withdraw consent at any time:
- Click "Manage cookies" in our footer.
- Clear your browser's site data for our domain — this will reset your consent and log you out.
- Email [TBD: privacy@[domain]] for assistance.
3.3 Browser-Level Controls
Most browsers let you block or delete cookies via their settings. Useful resources:
Blocking strictly necessary cookies will prevent the Service from working (you cannot stay logged in).
3.4 Global Privacy Control (GPC)
We honour the Global Privacy Control (GPC) signal in browsers and extensions that send it. When GPC is detected we treat it as a signal to disable non-essential cookies and (in jurisdictions where this is required, e.g. California) as an opt-out of "sale/sharing" of personal information. We do not sell or share personal information in any case.
4. Cookies Used by Third Parties on Pages You May Visit
Some pages link to third-party services (Stripe checkout, OpenRouter signup, GitHub, etc.). When you click through to those pages, the third party may set its own cookies under its own privacy policy. We do not control those cookies.
5. Children
We do not direct the Service to children under 16. See Privacy §12.
6. Changes to This Policy
We may update this Policy from time to time. Material changes will refresh the consent banner so you can review and re-decide. The "Last Updated" date above reflects the most recent revision.
7. Contact
For cookie-related questions, email [TBD: privacy@[domain]].