Cookie Policy

Our cookie policy and how we use them

Draft — not yet legally effective

This document is pending review and has unset details (entityName, entityAddress, privacyEmail, legalEmail, governingLaw, venue, lastUpdated). It does not yet form an agreement. See config/legal.config.ts.

Last updated: TODO: date these documents were approved · How Meconi Labs uses cookies and local storage

1. The short version

Meconi Labs uses a small number of cookies, and only for things the product needs in order to work: keeping you signed in, and remembering your language. We do not use advertising cookies, we do not run third-party tracking or social-media pixels, and we do not sell or share what we collect for advertising.

Every cookie listed below is either required for the product to function or records a display preference, and none is used to profile you or to track you across other websites. That is why you are not asked to accept cookies on arrival. If we ever introduce a cookie that requires consent, we will ask for it first.

2. What a cookie is

A cookie is a small text file a site stores on your device and sends back to the server on later visits. Related technologies do the same job: local storage and session storage keep data in your browser but, unlike cookies, are never sent to a server. This policy covers both.

3. Cookies we set

NamePurposeTypeRetention
sb-*-auth-tokenKeeps you signed in and holds your session so each page load can verify who you are. Set by our authentication provider, Supabase. May be split across several numbered cookies when the value is large.Strictly necessaryUntil you sign out or the session expires
langRecords the interface language, so it stays consistent between visits. Written automatically when a language is detected or selected.PreferencePersistent, until cleared
themeRecords whether you chose light or dark appearance. Sent with each request so the correct theme renders on the server and the page does not flash.Preference1 year
sidebar:stateRecords whether the navigation sidebar is expanded or collapsed.Preference7 days

Strictly necessary cookies cannot be switched off without breaking sign-in. If you block them you will not be able to use the application.

4. Analytics

We measure aggregate website usage — which pages are visited, roughly where visitors come from, and which browsers are used — with Umami, running on infrastructure we control rather than a third-party analytics network.

Umami does not set cookies and does not build a cross-site profile of you. It records page views without storing an identifier on your device, and it does not follow you to other websites. Analytics only runs if it has been configured for the deployment you are visiting.

5. Cookies set by payment processing

When you enter card details, those fields are hosted by Stripe so that card numbers never reach our servers. Stripe may set its own cookies in that context, for fraud prevention and to make payment work. These are governed by Stripe’s own cookie and privacy policies. We do not control them and cannot read them.

6. What we do not do

  • No advertising or retargeting cookies.
  • No social-media tracking pixels.
  • No selling or sharing of personal information for cross-context behavioural advertising.
  • No use of cookie data to train machine-learning models.

7. Managing cookies

Every major browser lets you view, block, and delete cookies, and clear local storage, from its settings — usually under Privacy or Security. You can also browse in a private window so everything is cleared when you close it.

Blocking the strictly necessary cookies above will prevent you from signing in. Clearing the preference entries simply resets your language and appearance to their defaults.

Most browsers also send a “Do Not Track” or Global Privacy Control signal. Since we set no advertising or profiling cookies, there is no tracking for these signals to disable.

8. Changes to this policy

If we start using cookies for new purposes we will update this page and, where the law requires it, ask for your consent first. The date at the top shows when this policy last changed.

9. Contact

Questions about this policy: TODO: privacy contact email. For how we handle personal information more generally, see the Privacy Policy.