Skip to main content

Cookie Policy

Last updated: 26 May 2026

1. What Are Cookies

Cookies are small text files that are stored on your device (computer, tablet, or mobile) when you visit a website. They are widely used to make websites work more efficiently and to provide information to website owners. This Cookie Policy explains how AI-Assist for SMEs (“we”, “us”) uses cookies and similar technologies on our platform.

This policy should be read alongside our Privacy Policy, which provides further details on how we handle your personal data.

2. How We Use Cookies

We use cookies for the following purposes:

  • Essential functionality: To enable core features like authentication, security, and session management
  • Preferences: To remember your settings and preferences (e.g. dark mode, cookie consent)
  • Analytics: To understand how visitors interact with our platform so we can improve it (only with your consent)

3. Types of Cookies We Use

3.1 Strictly Necessary Cookies

These cookies are essential for the Service to function. They cannot be switched off. They are usually set in response to actions you take, such as logging in or filling in forms.

Cookie NamePurposeDurationProvider
sb-*-auth-tokenSupabase authentication session token. Required for login functionality.Session / 1 yearSupabase
sb-*-auth-token-code-verifierPKCE code verifier for secure OAuth authentication flows.SessionSupabase
__stripe_midStripe fraud prevention. Used to detect and prevent fraudulent payment transactions.1 yearStripe
__stripe_sidStripe session identifier for payment processing. Set only when you reach a checkout page.30 minutesStripe
aa_mfa_trustMarks this device as trusted for two-factor authentication. Only set if you have enabled MFA on your account and ticked “Trust this device for 30 days” on the verification screen. HttpOnly, Secure, SameSite=Lax.30 daysAI-Assist

3.2 Functional Storage

These items remember helpful preferences. They are stored in your browser's local storage (not as HTTP cookies) — they never get sent to any server. They remain on your device until you clear your browser data, and can be wiped at any time without affecting the platform.

Storage KeyPurposeDurationProvider
cookie-consentRemembers your cookie banner choice (“accepted” or “essential-only”) so we don't keep asking.Until clearedAI-Assist
themeRemembers your dark / light mode preference.Until clearedAI-Assist
notifications_last_readTracks when you last opened the notification bell so the unread count is accurate. Only present when you're signed in to your dashboard.Until clearedAI-Assist
pwa_install_dismissedRemembers that you dismissed the “Install AI-Assist as an app” banner so it doesn't reappear.Until clearedAI-Assist

3.3 Analytics & Error Monitoring (Require Consent)

These trackers help us understand how visitors use the platform and catch errors so we can fix them. They are only activated if you click “Accept All Cookies” on our banner. Picking “Essential Only” means none of these load — and the platform works the same.

Cookie / TrackerPurposeDurationProvider
_va_idVercel Analytics visitor identifier. Anonymous aggregate page-view counts.1 yearVercel
_va_sesVercel Analytics session tracking.30 minutesVercel
Vercel Speed InsightsPage-load timing telemetry so we can spot slow pages and fix them. No cookies — sends aggregate timing measurements only.No persistenceVercel
SentryCaptures JavaScript errors and stack traces so we can fix bugs quickly. No cookies set in your browser; events are sent to Sentry only when something goes wrong.Per eventSentry

3.4 Privacy-Friendly Analytics (No Consent Needed)

We use one analytics tool that is exempt from the consent requirement under UK PECR because it does not use cookies, does not store anything on your device, does not identify you, and does not track you across sites:

ToolWhat it doesStorageProvider
Plausible AnalyticsCookieless aggregate page-view counts. Your IP address is hashed (irreversibly) and discarded the same day, so visits cannot be tied back to you. No cross-site tracking, no fingerprinting, no personal data leaves your browser.NonePlausible (EU-hosted)

Plausible's privacy model is documented at plausible.io/privacy-focused-web-analytics. If you would still prefer to block it, your browser's tracking-protection settings or any standard ad blocker will do so.

4. Managing Your Cookie Preferences

When you first visit the platform, our cookie consent banner gives you two equally prominent choices:

  • Essential Only — only strictly necessary cookies are set. No analytics, no error monitoring, no third-party trackers. Everything on the site still works.
  • Accept All Cookies — adds the optional analytics + error-monitoring trackers listed in section 3.3.

Changing Your Mind

You can change your choice at any time — withdrawing consent is as easy as giving it. Scroll to the bottom of any page and click the “Cookie Settings” link in the footer. The banner will reappear and you can choose again. If you switch from “Accept All” to “Essential Only”, we will remove the analytics cookies we previously set on your device.

Browser Controls

Most web browsers also let you control cookies directly through their settings. You can typically:

  • See what cookies are stored and delete them individually
  • Block third-party cookies
  • Block all cookies
  • Delete all cookies when you close your browser

Blocking strictly necessary cookies may prevent sign-in, payment processing, or two-factor authentication from working. All optional cookies can be blocked at the browser level with no impact on functionality.

5. Third-Party Services

The following third-party services may set cookies or load scripts on the platform. Each is listed with its purpose and consent status:

  • Supabase (authentication and session management) — strictly necessary
  • Stripe (secure payment processing and fraud prevention) — strictly necessary, only loaded on payment pages
  • Vercel Analytics & Speed Insights (page-view counts and performance telemetry, hosting provider) — only with your consent
  • Sentry (JavaScript error monitoring so we can fix bugs) — only with your consent
  • Plausible Analytics (cookieless, IP-anonymised aggregate page views) — runs without cookies and is exempt from PECR consent; see section 3.4
  • YouTube (only on the homepage demo video, and only after you click Play) — YouTube may set its own cookies on play; if you do not press play, no YouTube cookies are set

We do not control the cookies set by these third parties beyond gating them behind consent where required. Please refer to each provider's own privacy / cookie policy for full details.

6. Local Storage and Service Worker

Alongside cookies, we use two other browser storage mechanisms. Both stay on your device and are not transmitted to any server unless explicitly noted:

Local Storage

The full list of items we put in your browser's local storage is in section 3.2 above (cookie-consent choice, theme preference, notification-bell read state, PWA-install dismissal). None of these are tracked, sold, or shared. Authentication session tokens are stored as HTTP cookies (section 3.1), not in local storage.

Service Worker Cache

When you visit the site, a service worker caches static assets (CSS, JavaScript, fonts, images) so the platform loads faster on repeat visits and can work briefly offline. This is treated as strictly necessary functionality under PECR. The cache is automatically invalidated when we deploy new versions, and you can clear it any time via your browser's “Clear site data” setting.

If you would like us to delete all data associated with your account (including any server-side records), see your rights under our Privacy Policy (section “Your Rights”) and email info@aiassistsmes.co.uk.

7. Updates to This Policy

We may update this Cookie Policy from time to time to reflect changes in our practices or applicable regulations. The “Last updated” date at the top of this page indicates when this policy was last revised.

8. Contact Us

If you have questions about our use of cookies, please contact us:

  • Email: info@aiassistsmes.co.uk
  • Address: AI-Assist for SMEs, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ
    Operational team based in Birmingham, UK

For more information about your rights under UK GDPR and how we protect your data, please read our Privacy Policy.