Draft — not yet in force
This is a draft, published so you can read it rather than being told it exists. It has not been reviewed by a lawyer, and parts of it describe how Control is designed to work rather than what has shipped — Control is in private beta and no payment has been taken. Details still to be settled are shown like this: to be confirmed.
Cookie Notice
What is set in your browser, on the app and on this site, and what you are asked about.
Effective date: effective date Last updated: effective date
In short
- The Control app (once you're signed in) sets only the cookies it needs to keep you signed in and remember your settings. No analytics scripts, no advertising, no third-party trackers. Nothing there needs your consent, and we don't show you a banner.
- The public marketing site uses analytics cookies. In the EU and UK, those are only set after you say yes. You can say no, and the site works exactly the same.
- We never use cookies for advertising, and we don't allow anyone to use our site to track you across the web.
1. What this covers
This notice explains the cookies and similar technologies (local storage, session storage, IndexedDB) used on:
- the marketing site — the public pages at take-control.ai, and
- the app — the signed-in product at take-control.ai/app.
They are treated differently, on purpose.
2. The two zones, and why they differ
| Marketing site (take-control.ai) | The app (take-control.ai/app) | |
|---|---|---|
| Who sees it | Anyone | Signed-in users only |
| Strictly necessary cookies | Yes | Yes |
| Functional cookies | Minimal | Yes |
| Analytics cookies | Yes — consent required in EU/UK | No |
| Third-party scripts | Analytics only, after consent | None at all. A strict Content Security Policy blocks third-party scripts on authenticated pages. |
| Advertising / tracking cookies | Never | Never |
| Do we show a consent banner? | Yes, to visitors in the EEA and UK | No — nothing set there requires consent |
Why the app has no analytics script: we do measure how the product is used, but we do it from our own servers rather than by loading a third-party script into a page containing your tasks. That keeps your content behind a strict content security policy and means no external company's code runs alongside it.
3. The legal position, briefly
Under the EU ePrivacy Directive (and its national implementations) and the UK Privacy and Electronic Communications Regulations, we need your consent before storing or reading information on your device — unless the storage is:
- carried out solely to transmit a communication, or
- strictly necessary to provide a service you have explicitly requested.
Keeping you signed in is strictly necessary. Remembering your theme preference is arguably necessary for a service you asked for. Analytics is not, which is why it is behind a consent banner in the EU and UK.
Where we rely on consent, the corresponding GDPR lawful basis is consent (Art. 6(1)(a)).
4. Cookie tables
⚠️ These tables must be verified against the built application before publication. Cookie names set by Supabase Auth and PostHog depend on project identifiers and library versions.
4.1 Strictly necessary — the app and the marketing site
Set by us or by our authentication provider. No consent required. You cannot switch these off and still use Control.
| Cookie / storage | Set by | Purpose | Type | Duration |
|---|---|---|---|---|
sb-project ref-auth-token |
Supabase (first-party) | Holds your session so you stay signed in between page loads | First-party cookie | Rolling 30 days; refreshed while you're active |
sb-project ref-auth-token-code-verifier |
Supabase (first-party) | Protects the sign-in exchange (PKCE) against interception | First-party cookie | Until sign-in completes; a few minutes |
__Host-csrf (name to confirm) |
Control | Cross-site request forgery protection on form submissions | First-party cookie | Session |
rate limit cookie |
Control / Vercel | Abuse and rate-limit protection | First-party cookie | duration |
4.2 Functional — the app only
No consent required (these support a service you have explicitly requested), but we list them for transparency.
| Cookie / storage | Set by | Purpose | Type | Duration |
|---|---|---|---|---|
control_tz (name to confirm) |
Control | Remembers the timezone you're currently in, so "dinner at 8" means 8pm where you actually are | First-party cookie | 1 year |
control_prefs (name to confirm) |
Control | Remembers interface preferences — theme, week start day, reduced motion | First-party cookie or local storage | 1 year |
| IndexedDB — capture outbox | Control | Stores captures you make while offline, so nothing is lost, and drains them when you reconnect. Also caches your items for offline reading. | IndexedDB (on your device) | Until synced, or until you sign out or clear site data |
| Service worker cache | Control (Serwist) | Caches the app so it loads instantly and works offline | Cache Storage | Until updated or cleared |
control_consent |
Control | Remembers your cookie choice, so we don't ask again | First-party cookie | 6 months |
A note on offline storage: the capture outbox and the offline cache hold your actual task content on your own device. That's how Control works offline. Signing out clears it. If you use a shared computer, sign out.
4.3 Analytics — marketing site only, consent required in EU/UK
Only set if you accept. Decline and none of these appear.
| Cookie / storage | Set by | Purpose | Type | Duration |
|---|---|---|---|---|
ph_project api key_posthog |
PostHog | Distinguishes one visitor from another so we can count unique visitors, see which pages get read, and understand which pages lead to a sign-up | First-party cookie | 12 months |
| PostHog session storage keys | PostHog | Groups page views into a single visit | Session storage | Until the browser tab is closed |
We do not enable PostHog session recording, heatmaps, or autocapture of form contents on the marketing site.
4.4 Error monitoring
Sentry's browser SDK does not set cookies. It attaches a randomly generated trace identifier to error reports so that related events can be grouped. It runs on both the marketing site and the app, as strictly necessary for keeping the service working and secure.
4.5 What we never use
- Advertising or retargeting cookies
- Social media tracking pixels
- Data brokers or identity resolution services
- Cross-site tracking of any kind
- Fingerprinting
5. Your choices
5.1 The consent banner
If you're visiting the marketing site from the EEA or the UK, you'll see a banner on your first visit with two equally prominent options: Accept and Reject. There is no pre-ticked box, no cookie wall, and rejecting takes exactly one click.
Your choice is stored in control_consent for six months. You can change it at any time from the
Cookie settings link in the site footer, which is available on every page.
5.2 Withdrawing consent
Withdrawing consent is as easy as giving it — one click in Cookie settings. When you withdraw, we stop setting analytics cookies and delete the ones already set.
5.3 Browser controls
You can also block or delete cookies in your browser settings. Blocking strictly necessary cookies will prevent you from signing in to Control.
Most browsers offer:
- a way to see and delete cookies for a specific site,
- a "block third-party cookies" setting, and
- a private browsing mode that discards everything at the end of the session.
5.4 Do Not Track and Global Privacy Control
We honour the Global Privacy Control (GPC) signal. If your browser sends it, we treat it as a rejection of analytics cookies and as an opt-out of "sale" or "sharing" for the purposes of California law — even though we do not sell or share personal information in the first place.
Browsers' older "Do Not Track" header is not consistently defined and we do not rely on it. GPC is the signal we act on.
6. Changes to this notice
If we add, remove or change a cookie, we will update this page and the "last updated" date. If we add a category that needs consent, we will ask you again before setting anything.
7. Questions
Email contact email. Our full Privacy Policy is at take-control.ai/legal/privacy.
This is a draft prepared for legal review. It is not legal advice and has not been reviewed by a qualified lawyer. The cookie tables must be verified against the built application before publication.