Legal
Cookie Policy
Last updated: July 25, 2026
This Cookie Policy explains how Compliance Platform uses cookies and similar browser storage on the public website and platform application.
Essential cookies
The platform uses essential cookies and browser storage for authentication, session continuity, security checks, CSRF/session protection, routing users to the correct workspace, and remembering interface preferences required for normal use.
These cookies are necessary to provide the service and protect accounts. They are not used for advertising.
Security and authentication providers
Authentication and security providers, including Supabase and Cloudflare Turnstile where enabled, may set or use cookies and similar technologies to keep users signed in, verify legitimate traffic, prevent abuse, and support account recovery.
Disabling essential cookies may prevent login, password recovery, registration, security checks, or workspace access from working correctly.
Analytics and marketing
Today neither the public website nor the platform loads advertising pixels, behavioural marketing cookies, heatmaps, session replay or third-party analytics tools. The analytics and marketing categories in the consent banner control nothing yet: they exist so that a consent choice is already recorded if we introduce such a tool later.
If we later add non-essential analytics or marketing cookies, we will update this policy and add a consent choice before those non-essential tools are loaded where required.
Cookies and storage we use
Authentication (sb-…-auth-token, sometimes split into several numbered parts): keeps you signed in and loads the right workspace. Set by our authentication provider Supabase, refreshed while you stay active, and removed when you sign out.
Language (locale, cp_locale, cp_locale_manual): remembers the interface language and whether you chose it yourself instead of having it detected. Stored for 12 months and shared across our subdomains, so the choice survives when you move between the public site and the platform.
Consent (cookie_consent): stores your own cookie choice so the banner does not ask again. Stored for 6 months, after which we ask once more.
Anti-abuse (Cloudflare Turnstile): used on sign-in, password recovery and confirmation resend to tell legitimate visitors from automated traffic. Set by Cloudflare, short-lived, and only on those pages.
Browser storage (taric-password-recovery): lets a password recovery link finish in the browser where it was opened. Held in local storage and cleared once recovery is complete.
All of the above are needed to provide the service or to keep accounts secure. None of them are used for advertising or profiling.
Managing cookies
You can control cookies through your browser settings. Blocking all cookies may break core platform features.
We show a cookie banner where you can accept or reject non-essential cookies and choose categories in the preferences panel. Non-essential analytics or advertising cookies are only set after you give consent.