Legal

Cookie Policy

Last updated: 31 August 2026 (draft)

DRAFT: pending legal review, not yet approved for reliance

Open items before this page can be published

  • The tables below reflect what is actually set in code today (re-verified 2026-08-31 against the deployed bundle, not node_modules). Re-check whenever a storage key is added — don't let this drift.
  • Mapbox's metering values are treated as strictly necessary on the basis of Mapbox's own written position that they are billing values without which GL JS cannot function. Mapbox's own STORAGE.md describes the same values as "aggregate usage statistics". If that wording is reconciled, or the ICO addresses vendor-metering identifiers, revisit — see issue #261.
  • Cloudflare acts as an independent controller when it uses Turnstile signals to improve its own bot detection. That is a second purpose, and the ICO's guidance says a strictly-necessary claim fails where a technology also serves another purpose. Judged defensible for a login-form CAPTCHA, where consent-gating is not viable; recorded here rather than left implicit.

1. What this covers

This page explains the cookies and similar technologies — including browser local storage and session storage — that Hyper uses on hyper-planning.com and within the product.

We do not use any analytics, advertising or tracking cookies, and we do not allow any third party to use our site for those purposes. Everything listed below is needed to deliver the service you asked for: keeping you signed in, remembering how you have arranged the interface, protecting the sign-in form from bots, and our map provider’s own metering.

Because none of it is used for analytics, advertising or tracking, we do not ask you for consent to store it — under the Privacy and Electronic Communications Regulations we are required to tell you about it clearly instead, which is what this page does. If that ever changes, we will ask for your consent first, and this page will change with it.

2. Keeping you signed in

NameTypePurposeDuration
sb-<project-ref>-auth-tokenLocal storageKeeps you signed in (set by our authentication provider, Supabase).Until you sign out or your session expires
hyper-cookie-consentLocal storageRemembers that you have seen the cookie notice, so it isn’t shown on every visit.Until cleared

3. Remembering how you have set things up

These record interface preferences so the product looks the way you left it. They hold no personal information beyond the setting itself, and they are never used to build a profile of you.

NameTypePurposeDuration
sidebar_open, sidebar_stateCookieRemembers whether the app’s navigation sidebar is expanded or collapsed.30 days / 7 days
copilot_openCookieRemembers whether the AI copilot panel is open.30 days
tsr-scroll-restoration-v1_3Session storageReturns you to the same scroll position when you navigate back to a page.Until you close the tab
tanstack_router_reload:<message>Session storageSet only if part of the app fails to load, so that an automatic retry cannot loop indefinitely.Until you close the tab

4. Security

NameTypePurposeDuration
None stored on your deviceScript access to device and browser characteristicsCloudflare Turnstile protects our sign-in and sign-up forms from automated abuse. It sets no cookie and stores nothing on your device, but it does read browser and device characteristics — including your IP address, browser user-agent and TLS fingerprint — and returns a single-use token to our server. It does not read what you type into the form. Cloudflare also uses these signals, as an independent controller, to improve its own bot detection. See Cloudflare’s Turnstile Privacy Addendum.Nothing stored; the verification token is single-use and short-lived

5. Maps

The map is provided by Mapbox. When a map loads, the Mapbox library stores its own metering values on your device and reports the map load to Mapbox. Mapbox states that these are billing values, that it does not track users between billing cycles, and that it does not build profiles from them. We cannot switch this off: Mapbox provides no option to disable it in the browser, and its terms do not permit us to suppress it by other means.

These values are only created once you open a page containing a map, which is inside the signed-in product. Clearing your browser storage removes them, and a new value is generated the next time you load a map.

NameTypePurposeDuration
mapbox.eventData:<id>, mapbox.eventData.uuid:<id>, mapbox.eventData.uuidTimestamp:<id>Local storageMapbox’s own metering. Holds a random identifier that is not linked to your Hyper account and is not used by us for any purpose.Identifier is regenerated every 24 hours

6. What we don’t use

No analytics, no advertising, no marketing or social-media pixels, and no third-party tracking cookies. We do not use Google Analytics or any equivalent. Our error-monitoring provider, Sentry, stores nothing on your device; session replay is deliberately switched off, because it would record the contents of your screen. Our fonts are served from our own domain rather than a third-party font service.

7. How to control these

You can clear or block cookies and local storage through your browser settings — see your browser’s help pages for how. Because everything listed above is needed for the product to work, blocking it will break things: most obviously, you will not be able to stay signed in.

8. Changes to this policy

We’ll update this page whenever what we store changes, and update the “last updated” date above.

9. Contact us

Questions about this policy: hello@hyper-planning.com. See also our Privacy Policy.