Legal · Cookie Policy

Cookie Policy

We believe in transparency. This policy explains exactly what data we store on your device, why we store it, and how you can control it — in plain language.

Last updated: May 14, 2026

No ad tracking

We never use advertising or third-party tracking cookies.

Minimal storage

Only auth tokens and your preferences are stored locally.

Full control

Sign out or clear data any time to remove all stored data.

01

What Are Cookies?

Cookies are small text files placed on your device when you visit a website. They allow the site to recognise your device, remember your preferences, and deliver a consistent experience across sessions. We also use browser-based storage (localStorage and sessionStorage) which serve similar purposes but are not transmitted to our servers on every request.

Session cookies

Temporary cookies that exist only while your browser tab is open. They are deleted automatically when you close the browser and are used to maintain your current session state.

Persistent storage

Data stored in localStorage that remains on your device until you sign out, clear your browser data, or explicitly delete it. We use this for authentication tokens and user preferences.

Similar technologies

We use localStorage and sessionStorage in addition to traditional cookies. These are governed by the same principles and controls described in this policy.

02

Cookies & Storage We Use

Bronsik uses a minimal set of cookies and browser storage — only what is necessary to provide the service and remember your preferences. We do not use advertising cookies or third-party tracking scripts.

Authentication token (JWT)

A secure JSON Web Token is stored in localStorage after you sign in via Supabase. It is used to verify your identity on every API request. Without it, you cannot access your account. Tokens expire after 7 days of inactivity.

Onboarding state

A boolean flag stored in localStorage indicating whether you have completed the onboarding flow. This prevents the flow from being shown repeatedly once completed.

Language & voice settings

Your selected language, reply length, voice model, and speech settings are stored locally so they persist across sessions without requiring a server round-trip.

Theme preference

Your dark or light mode preference is stored in localStorage and applied immediately on page load to prevent a flash of the wrong theme.

Data control preferences

Toggles for conversation memory, voice processing, and analytics are stored locally and synced to your account when you are signed in.

03

Cookie Categories

We classify our cookies and storage into three categories based on their purpose and necessity.

Strictly necessary

Authentication tokens and session data are required for the service to function. Without them, you cannot sign in, use voice chat, or access any personalised features. These cannot be disabled while using Bronsik.

Functional

Preference cookies — including theme, language, and voice settings — enhance your experience but are not required for the core service to work. You can clear these at any time via your browser settings and the service will revert to defaults.

Analytics & advertising

We do not currently use any third-party analytics cookies (e.g. Google Analytics, Mixpanel) or advertising/tracking cookies (e.g. Facebook Pixel, Google Ads). If this changes, we will update this policy and request your explicit consent before setting any such cookies.

04

Third-Party Cookies

Certain third-party services integrated into Bronsik may set their own cookies or use storage on their own domains. We do not control these technologies and they are subject to each provider's own privacy and cookie policies.

Supabase (Authentication & Database)

Supabase manages our authentication and real-time database. It may use secure HTTP-only cookies or browser storage to maintain your session. These are scoped to our domain and are not shared with unrelated third parties.

LemonSqueezy (Payments)

LemonSqueezy is our payment processor. During checkout, you are redirected to their hosted payment page where LemonSqueezy may set cookies on their own domain to secure your payment session. We do not have access to these cookies and they are governed by LemonSqueezy's Cookie Policy.

OpenAI (Voice & AI)

Voice transcription and text generation are processed by OpenAI via server-side API calls. OpenAI does not set cookies on your browser as part of our integration.

No social or ad tracking

We do not embed Facebook, Twitter, TikTok, or Google tracking pixels or ad tags on any page of our platform.

05

How Long Data Is Retained

Different types of storage have different lifespans. Here is a summary of how long each type of data persists on your device.

Session data

Session storage is cleared automatically when you close the browser tab. It is used only for short-lived state within a single browsing session.

Authentication tokens

Your JWT auth token persists in localStorage until you sign out or the token expires (7 days of inactivity). Signing out immediately removes it from your device.

Preference data

Settings and preferences stored in localStorage persist indefinitely on your device until you clear your browser data or use the "Clear All Data" option in Settings.

No permanent fingerprinting

We do not use device fingerprinting, browser fingerprinting, or any long-lived tracking identifiers beyond your authenticated session. Once you sign out, no persistent identity link remains.

06

Your Choices & Controls

You have full control over the cookies and storage used by Bronsik. Below are the ways you can manage or remove them.

Browser settings

All major browsers allow you to view, block, and delete cookies and localStorage data. Blocking strictly necessary storage will prevent sign-in and disable core features. For browser-specific instructions, visit your browser's help center.

Sign out

Signing out of Bronsik immediately removes your authentication token from localStorage. Your preferences may remain until manually cleared but no authenticated API requests can be made.

Clear all data

The "Clear All Data" option in Settings → Data Controls permanently deletes your stored preferences, conversation history, and memory from our servers. Browser-side localStorage must be cleared separately via your browser settings.

Future analytics opt-out

If we introduce analytics tracking in the future, we will present an explicit opt-in consent banner. No analytics cookies will be set without your affirmative consent.

07

Legal Basis (GDPR)

For users in the European Economic Area (EEA) and United Kingdom, we process cookie-related data under the following legal bases as required by the General Data Protection Regulation (GDPR) and the UK GDPR.

Contractual necessity

Strictly necessary cookies and authentication tokens are processed on the basis of contractual necessity — they are required to deliver the service you have signed up for.

Legitimate interests

Functional preference storage is processed on the basis of legitimate interests — it allows us to deliver a consistent and personalised experience. You may object to this processing at any time.

Consent

Any non-essential cookies (e.g. analytics or advertising cookies, if introduced in the future) will be set only with your explicit prior consent, which you can withdraw at any time.

Data subject rights

You have the right to access, rectify, erase, and port your personal data, and to object to or restrict processing. Contact us at privacy@bronsik.com to exercise any of these rights.

08

Changes to This Policy

We review and update this Cookie Policy periodically to reflect changes in technology, law, or our practices.

Notification of changes

When we make material changes to this policy — such as introducing new types of cookies or third-party integrations — we will update the "Last updated" date and notify you via email or an in-app notice at least 14 days before the changes take effect.

Continued use

Continuing to use Bronsik after a policy update constitutes acceptance of the revised policy. If you disagree with any changes, you may delete your account at any time from Settings → Account.

09

Contact Us

If you have any questions about our use of cookies, or if you would like to exercise your data rights, please reach out to us.

Privacy inquiries

Email: privacy@bronsik.com — We aim to respond to all privacy-related requests within 5 business days.

General support

Email: support@bronsik.com — For general questions about your account or the service.

Data Protection Officer

For formal GDPR-related requests or complaints, you may also contact your local data protection authority. Our DPO can be reached at privacy@bronsik.com.