Strictly necessary
Two items, both stored in your browser's localStorage (not in actual
HTTP cookies):
sposa_id_token— the Cognito-issued ID token that proves you're signed in. Without it, you can't access the dashboard or any/api/*endpoint. Cleared automatically when you sign out, or after the token's natural expiry (currently one hour).sposa_cookie_choice— remembers that you've seen and acknowledged this notice, so the banner doesn't reappear on every page you load. The only value we store is the literal stringacknowledged. Cleared if you clear site data in your browser.sposa_post_login— holds the page you were on for a moment while you sign in, so we can return you there afterwards. Cleared as soon as it's used.sposa_locale— your language preference (English or Welsh), stored only on your device.sposa:etiquette-journal— your saved etiquette questions and answers, stored only on your device — they never leave your browser.
No consent is required for strictly-necessary storage of this kind under PECR §6(4)(b) or UK GDPR.
What we don't use
- No analytics cookies (no Google Analytics, no Plausible, no Mixpanel, no Segment).
- No advertising cookies (no Facebook Pixel, no Google Ads, no LinkedIn Insight tag).
- No third-party social-media embeds that drop cookies.
- No A/B-testing cookies.
- No fingerprinting.
If we change this
The first time we add anything beyond strictly-necessary storage, we'll show a proper consent banner and update this page first. We won't add tracking quietly.
Third parties we link to
When you click an external link from Sposa (for example to a vendor's website from inside an extracted message), the destination site sets its own cookies under its own privacy policy. We have no control over what those sites do.
Questions
Write to our Data Protection Officer at dpo@sposa.ai.