Cookie Policy
This Cookie Policy explains what cookies and similar technologies CoAgentor uses, why, and how you can control them. It should be read alongside our Privacy Policy.
1. What Are Cookies
Cookies are small text files stored on your device by your browser when you visit a website. They are used to maintain sessions, remember preferences, and gather usage analytics. We also use related technologies including browser local storage and session storage where functionally equivalent.
2. Our Cookie Use
CoAgentor uses a minimal cookie footprint. We do not use advertising cookies, cross-site tracking cookies, or third-party ad network scripts. Our cookies fall into three categories:
Essential Cookies (Always Active)
These are strictly necessary for authentication and security. The Service cannot function without them. They are not subject to consent.
Analytics Cookies (Consent Required)
We use Google Analytics 4 (GA4), loaded via Google Tag Manager (GTM), to understand how visitors use the Service. GA4 collects anonymized usage data including pages visited, session duration, and feature interactions. IP addresses are anonymized before storage. We do not use GA4 for advertising profiling or cross-site tracking unrelated to our own Service. These cookies are only set if you accept via the cookie banner.
Advertising & Conversion Cookies (Consent Required)
We use Google Ads conversion tracking to measure whether visitors who click our ads go on to sign up or subscribe. This helps us understand the effectiveness of our advertising. We do not use these cookies to serve you personalized ads or share your data with ad networks beyond conversion measurement. These cookies are only set if you accept via the cookie banner.
| Name | Purpose | Duration | Party |
|---|---|---|---|
sb-* | Supabase authentication session token. Required to stay logged in. | Session / 1 week | First party |
_ga | Google Analytics 4 — distinguishes unique users via a randomly generated client ID. Does not store personal data. | 2 years | First party (Google) |
_ga_* | Google Analytics 4 — stores session state for the specific GA4 property. | 2 years | First party (Google) |
_gid | Google Analytics 4 — distinguishes users, refreshes every 24 hours. | 24 hours | First party (Google) |
_gcl_au | Google Ads — conversion linker. Associates ad clicks with conversions (sign-ups, subscriptions) on our site. | 90 days | First party (Google) |
_gcl_aw | Google Ads — stores the Google Click ID (gclid) from an ad click to attribute conversions. | 90 days | First party (Google) |
_gtm_* | Google Tag Manager — operational cookie used to load and manage tag configurations. Does not collect personal data directly. | Session | First party (Google) |
Functional Cookies (Consent-Based)
These remember your in-app preferences. Disabling them does not break the Service but may reduce convenience.
| Name | Purpose | Duration | First/Third Party |
|---|---|---|---|
ca_prefs | Dashboard layout and display preferences | 6 months | First party |
ca_billing | Remembers your billing toggle selection (monthly/annual) | 30 days | First party |
Analytics Cookies (Consent-Based)
We use privacy-preserving analytics to understand aggregate usage. We do use Google Analytics, Meta Pixels, and advertising-network analytics. IP addresses are anonymized before any storage.
| Name | Purpose | Duration | First/Third Party |
|---|---|---|---|
_ca_anon | Anonymous session ID for aggregate page-view counts. Not tied to your identity. | 12 months | First party |
3. Third-Party OAuth Cookies
When you connect third-party integrations (Google Drive, HubSpot, Slack, etc.) via OAuth, those providers may set their own session or state cookies during the authorization flow. These are governed by the respective provider’s cookie policies and are cleared from our domain after authorization completes. We have no access to these cookies.
4. Google Data Processing
Google Analytics and Google Ads are operated by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. When analytics or advertising cookies are active, anonymized usage data is transmitted to and stored on Google servers, which may be located in the United States or other countries. This transfer is governed by Google’s standard contractual clauses and the EU-US Data Privacy Framework where applicable. For more information, see Google’s Privacy Policy and Google Analytics opt-out browser add-on.
We have enabled IP anonymization in GA4. This means the last octet of your IP address is zeroed out before any data is stored or processed by Google.
5. Legal Basis for Cookies (GDPR/ePrivacy)
Under the EU ePrivacy Directive and GDPR, essential cookies are deployed under the legal basis of legitimate interests and contractual necessity; they do not require consent. Functional and analytics cookies are deployed only with your explicit consent via the cookie banner. You may withdraw consent at any time by clearing cookies in your browser or using the opt-out link in our footer.
6. Managing Cookies
You can control cookies through your browser settings. All major browsers allow you to view, block, and delete cookies:
Note: Blocking essential cookies (ca_session, ca_csrf) will prevent you from logging into CoAgentor.
7. Do Not Track
CoAgentor does not respond to browser DNT signals as there is no consistent industry standard. However, we do not engage in cross-site behavioral tracking regardless of DNT status.
8. Contact
Cookie questions: — subject: “Cookie Query.”