← Back

Cookie Policy

Last updated: 11 August 2026

This policy explains the cookies and similar technologies setpal.io uses, and how you control them. It sits alongside our privacy notice. We keep this simple on purpose: we use no advertising, marketing or third-party tracking cookies.

1. What we use, and what needs consent

We split what we store on your device into two groups. Strictly-necessary items keep you signed in and let the app work - these are exempt from consent and are always active. Optional preferences remember convenience settings; we only store these after you accept in the consent banner, and you can decline without losing any core functionality.

2. What we store

NameTypePurposeNeeds consent?
sb-*Cookie (Supabase auth)Keeps you signed in securely.No - strictly necessary
cookie-consent-v2Local storageRecords your cookie choice, when you made it and which version of this policy it applied to, so we don’t ask again and can show that you were asked.No - records your choice
themeLocal storageRemembers light/dark mode.Yes
sidebarLocal storageRemembers whether the sidebar is open.Yes
marketLocal storageRemembers your last coaching market (B2B/B2C).Yes

The optional preferences are stored in your browser only. Until you accept, none of them are set; if you decline (or later change your mind), we clear them. We set no analytics, advertising or cross-site tracking cookies of any kind, and no third-party cookies beyond the strictly-necessary sign-in session provided by Supabase.

3. The security check on the sign-in pages

On the sign-in, sign-up and password-reset pages only, we run Cloudflare Turnstile - a check that tells real people apart from automated attacks. It is usually invisible: most people never see anything at all.

This is a strictly-necessary security measure and does not require consent, because without it we cannot protect accounts from automated password-guessing. It runs only on those three pages, never while you are using the app, and Turnstile does not use tracking cookies or profile you across websites. Cloudflare does receive your IP address and limited technical signals about your browser in order to make its decision - see our privacy notice.

4. Third-party requests that are not cookies

Being complete about this: simply loading a page sends nothing to anyone but us. Fonts, stylesheets, images and scripts are all served from our own domain, so no outside company learns your IP address just because you read this page.

A third party only receives anything when you take a specific action: signing in (Supabase, and Google if you choose that option), paying (Stripe), sending a message to the coach (Anthropic), or loading a sign-in page, which runs the Cloudflare security check described above. All of these are set out in our privacy notice.

5. Managing your choice

You chose when you first visited, and you can change it at any time - it is as easy to withdraw consent as it was to give it. Use to bring the banner back, or clear cookies and site data in your browser. Declining leaves only the strictly-necessary sign-in cookie, and the app keeps working exactly as before.

If your browser sends a Global Privacy Control signal, we detect it and treat it as a refusal of all optional storage automatically - we will not show you the banner and we will not store any preference. You do not need to do anything else.

6. Changes and contact

We may update this policy; the “last updated” date above will change. For any question, contact CloseDeck Limited at eric@closedeck.co.uk. See also our privacy notice and terms.