Cookie Policy
Short, because there is not much to say. We set the cookies needed to keep you signed in and nothing else — no analytics, no advertising, no cross-site tracking.
Last updated 10 August 2026
1. What we set
Cookies are small files a site stores in your browser. We use them for one purpose: knowing that a request is coming from someone who has already signed in.
- Authentication cookies. Set by Supabase, our authentication provider, when you sign in. They hold a session token so you are not asked to sign in on every page. They expire when the session does, and signing out clears them.
- Security cookies. Short-lived values used during sign-in and invitation flows to tie a response back to the request that started it.
2. What we do not set
We do not use analytics cookies, advertising or retargeting pixels, social media trackers, or any cookie that follows you to another site. We do not sell or share browsing behaviour, and there is no third-party tag manager on the site.
This is why you are not being asked to accept a banner. Under the UK PECR and the EU ePrivacy Directive, consent is not required for cookies strictly necessary to deliver a service you asked for, and everything we set falls in that category. If we ever add anything that is not strictly necessary, we will ask first and this page will change before it happens.
3. Publicly shared reports
A shared client report is readable without signing in and sets no cookies for the person reading it.
4. Controlling cookies
Every major browser lets you view, block and delete cookies through its settings. Blocking ours is entirely your choice, but signing in will not work without them — the app will have no way to remember you from one page to the next.
5. Changes and contact
Updates appear here with a new date above. Questions: hello@bravepeople.co. How the resulting data is handled is covered in our Privacy Policy.