Skip to content

Draft — not yet in force

This is a draft, published so you can read it rather than being told it exists. It has not been reviewed by a lawyer, and parts of it describe how Control is designed to work rather than what has shipped — Control is in private beta and no payment has been taken. Details still to be settled are shown like this: to be confirmed.

Cookie Notice

What is set in your browser, on the app and on this site, and what you are asked about.

Effective date: effective date Last updated: effective date


In short

  • The Control app (once you're signed in) sets only the cookies it needs to keep you signed in and remember your settings. No analytics scripts, no advertising, no third-party trackers. Nothing there needs your consent, and we don't show you a banner.
  • The public marketing site uses analytics cookies. In the EU and UK, those are only set after you say yes. You can say no, and the site works exactly the same.
  • We never use cookies for advertising, and we don't allow anyone to use our site to track you across the web.

1. What this covers

This notice explains the cookies and similar technologies (local storage, session storage, IndexedDB) used on:

  • the marketing site — the public pages at take-control.ai, and
  • the app — the signed-in product at take-control.ai/app.

They are treated differently, on purpose.

2. The two zones, and why they differ

Marketing site (take-control.ai) The app (take-control.ai/app)
Who sees it Anyone Signed-in users only
Strictly necessary cookies Yes Yes
Functional cookies Minimal Yes
Analytics cookies Yes — consent required in EU/UK No
Third-party scripts Analytics only, after consent None at all. A strict Content Security Policy blocks third-party scripts on authenticated pages.
Advertising / tracking cookies Never Never
Do we show a consent banner? Yes, to visitors in the EEA and UK No — nothing set there requires consent

Why the app has no analytics script: we do measure how the product is used, but we do it from our own servers rather than by loading a third-party script into a page containing your tasks. That keeps your content behind a strict content security policy and means no external company's code runs alongside it.

Under the EU ePrivacy Directive (and its national implementations) and the UK Privacy and Electronic Communications Regulations, we need your consent before storing or reading information on your device — unless the storage is:

  1. carried out solely to transmit a communication, or
  2. strictly necessary to provide a service you have explicitly requested.

Keeping you signed in is strictly necessary. Remembering your theme preference is arguably necessary for a service you asked for. Analytics is not, which is why it is behind a consent banner in the EU and UK.

Where we rely on consent, the corresponding GDPR lawful basis is consent (Art. 6(1)(a)).

⚠️ These tables must be verified against the built application before publication. Cookie names set by Supabase Auth and PostHog depend on project identifiers and library versions.

4.1 Strictly necessary — the app and the marketing site

Set by us or by our authentication provider. No consent required. You cannot switch these off and still use Control.

Cookie / storage Set by Purpose Type Duration
sb-project ref-auth-token Supabase (first-party) Holds your session so you stay signed in between page loads First-party cookie Rolling 30 days; refreshed while you're active
sb-project ref-auth-token-code-verifier Supabase (first-party) Protects the sign-in exchange (PKCE) against interception First-party cookie Until sign-in completes; a few minutes
__Host-csrf (name to confirm) Control Cross-site request forgery protection on form submissions First-party cookie Session
rate limit cookie Control / Vercel Abuse and rate-limit protection First-party cookie duration

4.2 Functional — the app only

No consent required (these support a service you have explicitly requested), but we list them for transparency.

Cookie / storage Set by Purpose Type Duration
control_tz (name to confirm) Control Remembers the timezone you're currently in, so "dinner at 8" means 8pm where you actually are First-party cookie 1 year
control_prefs (name to confirm) Control Remembers interface preferences — theme, week start day, reduced motion First-party cookie or local storage 1 year
IndexedDB — capture outbox Control Stores captures you make while offline, so nothing is lost, and drains them when you reconnect. Also caches your items for offline reading. IndexedDB (on your device) Until synced, or until you sign out or clear site data
Service worker cache Control (Serwist) Caches the app so it loads instantly and works offline Cache Storage Until updated or cleared
control_consent Control Remembers your cookie choice, so we don't ask again First-party cookie 6 months

A note on offline storage: the capture outbox and the offline cache hold your actual task content on your own device. That's how Control works offline. Signing out clears it. If you use a shared computer, sign out.

4.3 Analytics — marketing site only, consent required in EU/UK

Only set if you accept. Decline and none of these appear.

Cookie / storage Set by Purpose Type Duration
ph_project api key_posthog PostHog Distinguishes one visitor from another so we can count unique visitors, see which pages get read, and understand which pages lead to a sign-up First-party cookie 12 months
PostHog session storage keys PostHog Groups page views into a single visit Session storage Until the browser tab is closed

We do not enable PostHog session recording, heatmaps, or autocapture of form contents on the marketing site.

4.4 Error monitoring

Sentry's browser SDK does not set cookies. It attaches a randomly generated trace identifier to error reports so that related events can be grouped. It runs on both the marketing site and the app, as strictly necessary for keeping the service working and secure.

4.5 What we never use

  • Advertising or retargeting cookies
  • Social media tracking pixels
  • Data brokers or identity resolution services
  • Cross-site tracking of any kind
  • Fingerprinting

5. Your choices

5.1 The consent banner

If you're visiting the marketing site from the EEA or the UK, you'll see a banner on your first visit with two equally prominent options: Accept and Reject. There is no pre-ticked box, no cookie wall, and rejecting takes exactly one click.

Your choice is stored in control_consent for six months. You can change it at any time from the Cookie settings link in the site footer, which is available on every page.

5.2 Withdrawing consent

Withdrawing consent is as easy as giving it — one click in Cookie settings. When you withdraw, we stop setting analytics cookies and delete the ones already set.

5.3 Browser controls

You can also block or delete cookies in your browser settings. Blocking strictly necessary cookies will prevent you from signing in to Control.

Most browsers offer:

  • a way to see and delete cookies for a specific site,
  • a "block third-party cookies" setting, and
  • a private browsing mode that discards everything at the end of the session.

5.4 Do Not Track and Global Privacy Control

We honour the Global Privacy Control (GPC) signal. If your browser sends it, we treat it as a rejection of analytics cookies and as an opt-out of "sale" or "sharing" for the purposes of California law — even though we do not sell or share personal information in the first place.

Browsers' older "Do Not Track" header is not consistently defined and we do not rely on it. GPC is the signal we act on.

6. Changes to this notice

If we add, remove or change a cookie, we will update this page and the "last updated" date. If we add a category that needs consent, we will ask you again before setting anything.

7. Questions

Email contact email. Our full Privacy Policy is at take-control.ai/legal/privacy.


This is a draft prepared for legal review. It is not legal advice and has not been reviewed by a qualified lawyer. The cookie tables must be verified against the built application before publication.