1. Introduction
This Cookie Policy explains how Cove ("Company", "we", "us", or "our") uses cookies and similar technologies on our website at joincove.io and our application at app.joincove.io (the "Service"). This policy should be read alongside our Privacy Policy.
2. What Are Cookies
Cookies are small text files that are stored on your device (computer, tablet, or mobile phone) when you visit a website. They are widely used to make websites work more efficiently and to provide information to website owners.
Similar technologies include local storage, session storage, and pixel tags, which function in comparable ways.
3. Cookies We Use
We use two categories of cookies: strictly necessary cookies, which are always active, and statistics cookies, which are set only if you consent to them. We do not use advertising, marketing, or profiling cookies.
Consent is collected through the cookie banner on our website, provided by Cookiebot. You can change or withdraw your choice at any time — see Section 5.
3.1 Strictly Necessary Cookies
These cookies are essential for the operation of the Service. They cannot be disabled without affecting core functionality. No consent is required for strictly necessary cookies under the EU ePrivacy Directive.
| Cookie Name | Provider | Purpose | Type | Duration | |---|---|---|---|---| | sb-*-auth-token | Supabase | Authentication session management. Stores encrypted JWT tokens to keep you logged in | HTTP (HttpOnly, Secure, SameSite=Lax) | Session / 1 year (refresh token) | | cove_mfa_trusted | Cove | Trusted device token for multi-factor authentication. Allows you to skip MFA on recognized devices | HTTP (HttpOnly, Secure, SameSite=Lax) | 24 hours or 90 days (user preference) | | NEXT_LOCALE | Next.js | Stores your preferred language/locale setting | HTTP | 1 year | | CookieConsent | Cookiebot | Stores your cookie consent choice per category, so we can honour it and demonstrate that it was given | HTTP | 1 year |
3.2 Statistics Cookies (Consent Required)
These cookies help us understand how the Service is found and used — which pages are visited, which features are clicked, and where visitors run into problems — so that we can improve it. They are set only if you accept the "Statistics" category in the cookie banner. If you decline, they are not set, and no analytics data is collected.
| Cookie Name | Provider | Purpose | Type | Duration | |---|---|---|---|---| | ph__posthog | PostHog | Analytics identifier and session state. Used to recognise a returning visit and to link the pages of a single visit together | HTTP and local storage | 1 year | | _ph_opt_in_out | PostHog | Records whether you have opted in to or out of analytics capture | HTTP and local storage | 1 year |
If you accept this category, we collect:
- Product analytics: pages viewed, clicks and other interface interactions, the site that referred you, and your browser, operating system, device type and approximate location
- Session replay: a reconstruction of your visit — pages, cursor movement, clicks and scrolling — used to diagnose usability problems. Text you type into form fields is masked
- Console and performance data: browser error messages and page loading timings, captured alongside session replay so that we can reproduce faults
- Web vitals and heatmaps: aggregate page performance measurements and click-density maps
Your IP address is anonymised before it is stored, and it is used only to derive an approximate location (country/region level). Analytics data is processed on PostHog's EU infrastructure and is retained for 12 months; session replays are retained for 30 days.
Legal basis: your consent (Art. 6(1)(a) GDPR and the EU ePrivacy Directive). Withdrawing consent does not affect the lawfulness of processing carried out before you withdrew it.
3.3 Cookies We Do Not Use
For transparency, we want to confirm that we do not use:
- Google Analytics
- Facebook Pixel or any advertising cookies
- Any third-party tracking or remarketing cookies
- Any cookies for behavioral profiling or targeted advertising
- Any social media cookies (like buttons, share widgets)
4. Third-Party Cookies
All of the cookies listed in Section 3 are set on our own domains (joincove.io and app.joincove.io). Analytics requests are routed through our own servers rather than sent directly to an external analytics domain. The data those cookies collect is nevertheless processed on our behalf by the providers named above, which act as our processors under written agreements; they are listed on our Sub-processors page.
When you use features that connect to third-party services (e.g., Google OAuth login), those services may set their own cookies on their domains during the authentication process. Those cookies are governed by the respective third party's cookie policy:
- Google: policies.google.com/technologies/cookies
- Microsoft: privacy.microsoft.com/en-us/privacystatement
5. Managing Cookies
5.1 Changing or Withdrawing Your Consent
You can change or withdraw your consent for statistics cookies at any time using the Cookie settings link in the footer of our website, which reopens the consent banner. Withdrawal takes effect immediately and stops any further analytics collection. It is as easy to withdraw consent as it was to give it.
5.2 Browser Controls
Strictly necessary cookies cannot be disabled without breaking the Service: blocking them would prevent you from logging in or maintaining a session. Blocking statistics cookies has no effect on functionality.
You can also manage cookies through your browser settings:
- Chrome: Settings > Privacy and Security > Cookies
- Firefox: Settings > Privacy & Security > Cookies and Site Data
- Safari: Preferences > Privacy > Cookies and Website Data
- Edge: Settings > Privacy, Search and Services > Cookies
Please note that blocking strictly necessary cookies will prevent you from using the Service.
6. Do Not Track
Some browsers offer a "Do Not Track" (DNT) signal. We do not track you across other websites and we do not build advertising or behavioural profiles. Because statistics cookies are set only after you give consent through the cookie banner, that banner — not DNT — is the mechanism by which we take your choice into account.
7. Introducing New Cookies
If we introduce further non-essential cookies in the future, we will:
- Update this Cookie Policy before deploying them
- Request your consent before setting them, through the existing consent mechanism
- Keep granular, per-category control available
- Ensure "Reject all" is as accessible as "Accept all"
8. Changes to This Policy
We may update this Cookie Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the effective date. If we introduce further non-essential cookies, we will provide advance notice as described in Section 7.
9. Contact Us
If you have questions about our use of cookies, please contact us at:
- Email: filip@joincove.io
- Support: filip@joincove.io