Pre-launch draft · 2026-09-07-preview
Cookies & Browser Storage
Operator details and legal review are pending. This is not a finalized public-launch policy.
Current preview
This notice covers cookies, local storage and session storage. A cookie-consent plugin is not installed. That does not authorize nonessential tracking to run before any legally required consent.
Authentication
Supabase uses a project-specific sb-*-auth-token local-storage entry to maintain sign-in. It is refreshed during authentication and removed on sign-out. Local storage has no automatic cookie expiry and may remain until cleared. Authentication providers can use their own cookies during sign-in.
Referral and demo state
The kairo-referral session-storage entry holds an invitation reference during signup and is removed after onboarding or when the browser session ends. Supplier-demo answers and points remain only in page memory.
External services
Hosting, external media and sign-in services receive connection information and have their own storage practices. The main site includes Vercel Web Analytics, which Vercel describes as cookie-free; it does not use advertising cookies. Kairo has not added advertising tracking in this release. A vendor audit with actual cookie names and lifetimes is still needed before enabling live suppliers or nonessential tracking.
Your controls
Clear or restrict storage through your browser, or sign out of Kairo. Clearing authentication data signs you out; clearing referral state can remove an invitation reference. A future consent manager should support rejecting nonessential tracking and changing your decision. The signup agreement is not cookie consent.