Cookie Policy

Version 1.0 · Effective date: 5 September 2026

1. What this covers

This policy explains what cookies and similar browser storage technologies (local storage, session storage) Vivora uses today, and what we plan to add.

2. What we use today

Name/typePurposeDurationConsent required?
Supabase authentication token (browser local storage)Keeps you signed in between visits, so you don't have to log in every time you open the appUntil you sign out, or the underlying session expiresNo — strictly necessary for the Service to function
Theme preference (browser local storage)Remembers whether you've chosen light or dark modeUntil cleared by youNo — strictly necessary/functional, no tracking
"Remember email" preference (browser local storage)Pre-fills your email on the login screen if you've opted in to this on that deviceUntil you clear it or uncheck the optionNo — you actively opt in via a checkbox; this is not used for tracking
Onboarding tour / hint dismissal flags (browser local storage)Remembers that you've completed or dismissed the in-app guided tour and contextual tips, so they don't reappearUntil cleared by youNo — functional only, no tracking
Pending signup marker (browser local storage)Temporarily bridges a new company signup across email confirmation, so your company account finishes setting up correctly the first time you log in after confirming your emailDeleted automatically once usedNo — strictly necessary for signup to function

The Supabase authentication token row above also includes an entry that the Supabase login library itself creates (named something like sb-<project-ref>-auth-token) — this is the same sign-in session described in that row, just naming the specific technical key for completeness.

None of the above are third-party cookies, and none are used for advertising or cross-site tracking. This is not, strictly, a "cookie" in the traditional sense for the authentication/theme/email items above — they use the browser's localStorage/sessionStorage APIs rather than HTTP cookies — but we disclose them here under the same standard, since they serve an equivalent function and the distinction is not meaningful to most readers.

3. Planned: product analytics (not yet active)

We intend to add PostHog for product analytics, to understand which features are used and how, so we can improve the Service. As of the effective date above, this integration has not been added to the product — no analytics cookies or scripts are currently loaded. When it goes live, it will use cookies and/or local storage to:

At that time: (a) this policy will be updated with the exact cookie names and durations PostHog sets; (b) for Users in jurisdictions requiring opt-in consent (e.g. under the EU/UK ePrivacy rules, once Vivora operates there), a consent banner will be shown before any non-essential analytics cookie is set; and (c) an opt-out control will be provided in Settings. See PostHog's Privacy Policy for how PostHog itself handles data once integrated.

4. Third-party cookies (Stripe)

When you enter payment details, you interact with Stripe's own checkout interface, which may set its own cookies for fraud prevention and to process your payment. Vivora does not control these cookies; see Stripe's Cookie Policy.

5. How to control cookies/local storage

You can clear local storage and cookies for Vivora at any time through your browser's site-data settings (this will sign you out and reset any saved preferences). Most browsers also let you block all cookies/site data globally, though doing so will prevent the Service's authentication from working, since it depends on local storage to keep you signed in.

6. Do Not Track

The Service does not currently respond differently to browser "Do Not Track" signals, as there is no industry-standard way to honour them consistently. This will be revisited once the PostHog integration (Section 3) goes live.

7. Contact

Questions about this policy: privacy@[yourdomain].