TRANSCREATE AI

Cookie Policy

Effective date: 2026-09-08 · Version 1.0 (2026-09-08) · Applies to transcreateai.com

DRAFT TEMPLATE — this document is being reviewed by qualified counsel and any updates will be promptly communicated to our clients.

1. What This Policy Covers

This Policy explains every cookie and item of browser storage (localStorage and sessionStorage, which EU law treats the same way as cookies) that the Transcreate AI application sets on your device, why, and for how long.

2. The Short Version

The application sets only what is strictly necessary to sign you in and remember your interface preferences. There are no advertising cookies, no third-party analytics, no tracking pixels, and no cross-site identifiers of any kind. Because every item below is either strictly necessary for the service you requested or stores a preference you explicitly chose, EU law does not require a consent banner for them — which is why you do not see one. If we ever introduce analytics or any non-essential storage, we will add a consent mechanism before it activates and update this Policy.

3. What We Set

Authentication (strictly necessary — exempt from consent under ePrivacy Art. 5(3)):

  • Cookie: sb-[project]-auth-token (and chunked variants). Provider: Supabase Auth (first-party). Purpose: keeps you signed in; carries your session with automatic rotation. Duration: session-based with refresh; cleared on sign-out.

Preferences (user-requested functionality):

  • localStorage: tc-theme. Provider: first-party. Purpose: remembers whether you chose the day or night interface theme. Duration: until you clear it or change the setting. Set only when you use the theme switch.
  • localStorage: tc.locale. Provider: first-party. Purpose: remembers the interface language you selected, where the language preview is enabled for your deployment. Duration: until you clear it or change the setting. Set only when you use the language switch, and cleared automatically if the preview is turned off.
  • sessionStorage: tc-worker-shell. Provider: first-party. Purpose: remembers which navigation shell (client, linguist, or project-manager) your account resolved to, so the correct navigation renders instantly on the next page. Duration: dies with the browser tab; also cleared at sign-in and sign-out.
  • sessionStorage: transcreate.dismissedDraftPlans. Provider: first-party. Purpose: remembers which draft campaign plans you dismissed with the ×, so they stay hidden for the rest of your visit. Duration: dies with the browser tab.
  • sessionStorage: actAsOrg. Provider: first-party. Purpose: set ONLY in a Transcreate AI staff member's own browser, and only while they are working inside a customer workspace they are authorized for; it remembers which workspace, so the request header identifying it is consistent across the pages they open. It is never set in a customer's browser, contains only an organization identifier, and every access it accompanies is written to that organization's own support-access audit log before any data is served (see the Privacy Policy §7). Duration: dies with the browser tab.

Pre-beta access (strictly necessary — present only while the site is behind the pre-launch password):

  • Cookie: tc_gate. Provider: first-party. Purpose: while the site is closed to the public, records that this browser has already presented the pre-beta password, so the browser is asked once rather than on every page. It stores a one-way digest of the credentials and not the credentials, and it changes by itself whenever the password is rotated. Duration: 30 days; httpOnly, Secure, SameSite=Lax. This entry disappears from this Policy on the day the pre-launch gate is switched off, because the cookie stops being set at all.

4. What We Do Not Do

No advertising or retargeting cookies. No third-party analytics (no Google Analytics or similar). No social-media pixels. No fingerprinting. No cross-site tracking. Server logs used for security (see the Privacy Policy §7) are not browser storage and set nothing on your device.

5. Third-Party Pages You May Visit From the App

When you open Stripe-hosted billing pages (checkout or the customer portal), you are on Stripe's domain and Stripe's own cookie policy applies there. When your organization uses single sign-on, your identity provider's pages set their own cookies under their policy. Neither sets cookies on transcreateai.com.

6. Managing Storage

You can clear cookies and site storage at any time in your browser settings; you will be signed out and your theme preference will reset. Because we set nothing non-essential, there is nothing to opt out of beyond this.

7. Changes and Contact

If we add any category of storage, we will update this Policy, and — for anything non-essential — ask for consent first, before the storage is set. Questions: hello@transcreateai.com.

Questions? legal@transcreate.ai