This document describes the cookies we use on aicolabs.io and its sub-domains. As of the effective date of this policy, we do not use non-essential cookies and we do not run third-party analytics, marketing, or session-replay tools on these sites.
1. What cookies are
Cookies are small text files your browser stores on your device when you visit a website. They help the site work, remember your preferences, or measure how the site is used.
2. What cookies we use
We currently use only the strictly necessary cookies that the site needs to function. These include a session cookie that keeps you signed in to the platform and a CSRF token that protects forms against cross-site forgery.
- Authentication session cookie — strictly necessary, expires when you sign out or close your browser.
- CSRF token — strictly necessary, expires when your session expires.
- Theme preference — strictly necessary (functional), expires after 12 months.
- Consent token — strictly necessary, used by the cookie banner to look up the decision you made. The token is an opaque, unguessable identifier with no personal data in it.
3. What we do not use
We do not use Google Analytics, Meta Pixel, Hotjar, FullStory, or any equivalent third-party tracking, analytics, advertising, or session-replay tool on our public sites. We do not place advertising cookies and we do not sell visitor data.
4. Consent and the cookie banner
On the public marketing sites we display a strict opt-in cookie banner. Until you choose, only the strictly necessary cookies above are set. Analytics and marketing categories are off by default and are only set if you accept them.
Your decision is stored in two places: an httpOnly consent cookie on this device, and a row in our consent audit log on the Convex backend. The audit log records an opaque identifier, the version of this policy you agreed to, the categories you opted into, and the time of the decision. The audit log also records your IP address and User-Agent string as submitted at that moment.
We retain audit-log rows for up to 365 days. After that they are deleted automatically. If you later sign in to the platform, the row is linked to your account so we can answer data-subject requests about consent history. If you want to withdraw your decision, open the cookie preferences link in the site footer and choose Reject all or Essential only.
5. How to control cookies yourself
You can block or delete cookies through your browser settings at any time. The Help section of your browser will tell you how. Blocking strictly necessary cookies will prevent parts of the site from working, including sign-in.
6. Changes
We update this policy when the cookies we use change. The effective date at the top of the page reflects when the latest change took effect.