This page explains what cookies Undersignal uses and why. Short version: we use the minimum necessary to keep you logged in. We don't track you, show you ads, or sell your data.
Cookies are small text files stored in your browser. They're used for everything from keeping you signed in to tracking you across websites for advertising. We only do the former.
Undersignal uses essential cookies only — the kind that are strictly required for the service to work. Without them, you can't stay logged in.
| Cookie | Purpose | Type | Duration |
|---|---|---|---|
| Beta access authentication — verifies you have a valid session to use the app | Essential | 12 hours | |
| Supabase Auth access token — keeps you logged into your Undersignal account | Essential | 1 hour (auto-refreshed) | |
| Supabase Auth refresh token — used to silently renew your access token so you stay logged in | Essential | ~1 week | |
| Admin access bypass — used only for internal administration. Not set for regular users. | Essential | Session |
| Cookie Type | Status |
|---|---|
| Analytics (e.g., Google Analytics, Mixpanel) | Not used at launch |
| Advertising / retargeting (e.g., Facebook Pixel, Google Ads) | Not used |
| Social media tracking pixels | Not used |
| Third-party marketing cookies | Not used |
If we add analytics or other non-essential cookies in the future, we will update this policy and add a proper consent mechanism before they are set.
Under GDPR (and the ePrivacy Directive), essential cookies that are strictly necessary for the service to function do not require prior consent. We rely on this exemption for all cookies listed above — they exist solely to authenticate you and keep your session alive.
We do not use cookies for any purpose beyond service delivery. No consent banner is legally required for essential-only cookies, but we disclose them here in full.
EU/EEA users have the right to request deletion of personal data associated with your account, including session data. Email privacy@undersignal.ai to exercise this right. We'll process your request within 30 days.
For full GDPR rights, see our GDPR / EU Data Rights page.
You can delete cookies or block them through your browser settings. Note that blocking essential cookies will prevent you from staying logged in to Undersignal.
We also use browser localStorage to store your cookie notice dismissal preference (cookie_notice_dismissed). This is not a cookie — it's local browser storage and is never transmitted to our servers.
Questions about cookies or data: privacy@undersignal.ai