Cookie Policy
This Cookie Policy explains the cookies and similar browser storage used on our website and in the Agent Control Panel dashboard. We use only what is strictly necessary to provide the service you ask for. We do not use advertising, analytics, or tracking cookies.
On this page
1. What cookies and browser storage are
Cookies are small text files a website stores in your browser. Local storage and session storage are similar browser features that keep small amounts of data on your device. Some of these are strictly necessary for a service to work; others are used for analytics or advertising. We use only the first kind.
2. Our website
Our marketing website, documentation, Security & Trust page, and legal pages set no cookies of our own, use no browser storage, and load no third-party scripts, fonts, or trackers. Our network provider, Cloudflare, may set a strictly necessary security cookie (such as __cf_bm or cf_clearance) if it needs to check whether a visit comes from a bot; it is not used for tracking.
3. The dashboard
When you sign in to the dashboard, we use the following items. All of them are first-party and strictly necessary to keep you signed in or to remember a choice you made.
| Name | Type | Purpose | Duration |
|---|---|---|---|
acp.sid | Cookie (HTTP-only) | Server session for the legacy sign-in mode. Our hosted service does not use it; listed for self-hosted setups. | 7 days |
sidebar_state | Cookie | Remembers whether you collapsed the navigation sidebar. | 7 days |
sb-<project>-auth-token | Local storage | Your sign-in session from our authentication provider (Supabase Auth), plus short-lived keys it uses while you sign in. | Until you sign out |
acp_user_email | Local storage | Shows your email address in the dashboard without an extra request. | Until you sign out |
theme | Local storage | Remembers your light or dark theme choice. | Until you clear it |
acp_stale_chunk_reload | Session storage | Prevents a reload loop after we release a new version. | Until you close the tab |
acp.auth.next | Session storage | Returns you to an invitation after you sign in with Google or GitHub from it. | Removed as soon as sign-in completes |
acp-login-notice | Session storage | Shows a one-time message on the sign-in page, for example when an account has no access yet. | Removed as soon as it is shown |
ACP staff who sign in to the separate operator console also use two local storage items: acp-operator-auth (The operator sign-in session, kept separate from the dashboard session. Until sign-out or 30 minutes idle.) and acp-operator-last-active (Time of the last activity, used to sign operators out after 30 minutes idle. Until sign-out.)
4. Cookie preferences
There is nothing to switch off. Every item listed above is strictly necessary, so there are no optional cookies and no preference toggles. Strictly necessary storage does not require consent under EU and UK rules, which is why we do not show a cookie banner.
You can still block or delete cookies and site data in your browser settings. If you do, the dashboard will sign you out and forget your interface preferences; the marketing site is unaffected.
5. If this changes
If we ever add analytics or any other non-essential cookie or storage, we will update this policy first and add a consent banner that keeps them off until you agree. We will not load them before you have made a choice.
6. Contact
Questions about this policy: Founders@skaigroup.tech. See also our Privacy Policy.