Required authentication cookies

When Supabase accounts are configured, authentication tokens are stored in cookies used to establish and refresh a session. They are required for signed-in functions and are not advertising cookies. Production attributes depend on the approved domain and provider configuration.

Local storage

Theme, learning progress, drafts, Practice/Coach/Mentor history and privacy acknowledgements may be stored in browser localStorage. localStorage is not a cookie but is a similar browser technology and persists until cleared.

Analytics and marketing

A disabled first-party product analytics architecture accepts only allowlisted metadata and rejects learner or workplace content. No third-party analytics provider, advertising tracker, analytics cookie, or marketing cookie is configured. Any future provider or nonessential identifier requires a new founder/counsel decision and appropriate notice or consent controls.

Controls

Browser controls can clear cookies and localStorage, but clearing required session cookies signs the user out and clearing local drafts can remove unsynchronized work. Account settings provide server-data controls only after live account activation.

Attorney review