Skip to content
OBJEKTOBJEKT

Cookie Policy

Effective 11 September 2026

A short list of every cookie we use, why we use it, and how to refuse the ones that are not strictly necessary.

1What cookies are.

A cookie is a small text file a website stores in your browser. We also use similar local-storage and session-storage entries; we call all of them “cookies” in this policy. Some cookies are strictly necessary for OBJEKT to function. Others are optional and we only set them with your consent.

2Categories.

We group cookies into four categories:

Strictly necessary

Required to deliver the service you have asked for — for example, keeping you signed in or processing a payment. These are set without consent because, without them, the service does not work.

Functional

Remember your preferences (theme, language). Not essential, but improve your experience. Set with consent.

Analytics

Anonymous usage data that helps us understand which features are used and where the product needs work. Set only with consent.

Marketing

Advertising-measurement tags from Meta and Google run only under the Analytics choice above. We use them to see whether an ad led to a sign-up or purchase and to reach people who already visited OBJEKT. We never sell data, and nothing you upload is ever shared with them.

3The current cookies we set.

This list reflects the current product. We will update it when we add or remove a cookie.

objekt_referral
Records an invitation you accept and protects its attribution from tampering.
30 days
Strictly necessary
OBJEKT
objekt_referral_device
Random browser identifier used to check duplicate referral claims. Contains no email or IP address.
90 days
Strictly necessary
OBJEKT
sb-access-token / sb-refresh-token
Keeps you signed in. Set after you authenticate. Without these you cannot use OBJEKT at all.
Session + refresh (rotating)
Strictly necessary
OBJEKT (via Supabase Auth)
objekt_theme
Remembers your light/dark theme preference between visits.
1 year
Functional
OBJEKT
objekt_consent
Stores your cookie-consent choices so we do not ask again on every page load.
1 year
Strictly necessary
OBJEKT
__stripe_mid / __stripe_sid
Fraud prevention on the Stripe checkout and billing portal. Set only when you open a payment flow.
Session – 1 year
Strictly necessary
Stripe
ph_*
Anonymous product analytics — which features are used, where users drop off — so we can make OBJEKT better. Set only after you opt in.
Up to 12 months
Analytics
PostHog (if enabled)
_gcl_aw / _gcl_au
Links a click on one of our Google search ads to a later sign-up or purchase, so we know which ads work. Set only after you accept analytics cookies; before that the Google tag runs without cookies.
Up to 90 days
Analytics
Google (Google Ads tag)

4How to control them.

On your first visit we show a consent banner with three choices: accept all, reject non-essential, or pick by category. You can change your choice at any time from Settings → Privacy.

You can also block or delete cookies in your browser settings. Strictly necessary cookies cannot be disabled inside OBJEKT; if you block them in your browser, parts of the service (in particular, staying signed in and paying) will stop working.

5Do Not Track and Global Privacy Control.

We honour the Global Privacy Control (GPC) signal where the browser sends one. If your browser broadcasts GPC, we treat that as a rejection of analytics and any future opt-in marketing cookies, without requiring you to interact with the banner.

6Questions.

Cookie questions go to privacy@objekt-ai.com. For the broader picture of how we use data, see our Privacy Policy.