1. What this policy covers
This Cookie Policy explains the cookies and similar technologies (such as browser localStorage) that kott uses, why we use them, and how you can control them. It supplements our Privacy Policy. kott is deliberately light on cookies: we use what is needed to sign you in, to remember your studio preferences on your device, and to record your consent choices.
2. Categories we use
Strictly necessary (essential). Required for the Service to work — for example to keep you signed in. These cannot be switched off through the consent banner because the Service cannot function without them.
Functional (device-only preferences). Remember choices you make in the studio — such as theme and editor settings — stored locally in your browser and not transmitted to us as tracking.
Consent state. Records whether you accepted or declined non-essential storage, so we do not ask you again on every visit.
Analytics (only with consent, when enabled). Privacy-respecting product analytics that we will only set where enabled and, where required, only after you consent.
3. The cookies & storage we set
| Name / key | Type | Purpose | Category |
|---|---|---|---|
| Supabase auth cookies [AUTH COOKIE NAMES] | First-party cookie | Keep you signed in (session / refresh token) across the site and the studio | Essential |
kcs.* (e.g. theme, editor prefs) | Browser localStorage | Remember your studio/theme preferences on this device; never sent to us as tracking | Functional |
| Consent record [CONSENT COOKIE NAME] | First-party cookie / localStorage | Store your accept/decline choice so the banner is not shown again | Consent state |
| PostHog analytics | First-party cookie / storage | Product analytics — set only where enabled and after consent | Analytics — when enabled |
| Sentry (error reporting) | Storage / request context | Diagnose crashes and errors — set only where enabled | Diagnostic — when enabled |
Note: the studio also stores your projects and larger working data locally in your browser (for example so local/browser projects work offline). That on-device storage is described in the Privacy Policy and is not tracking. [PLACEHOLDER — confirm exact cookie names once the auth and consent components are finalized.]
4. Managing your choices
When you first visit, a consent banner lets you accept or decline non-essential storage. You can change your choice at any time through the consent controls (re-open the banner / cookie settings link), and you can also block or delete cookies in your browser settings — though blocking essential cookies will stop you from signing in. Declining analytics does not affect your ability to use the Service.
5. Global Privacy Control & Do Not Track
We honor the Global Privacy Control (GPC)signal as an opt-out of any “sale” or “sharing” of personal information (we do neither — see the Privacy Policy). Because there is no consistent industry standard for browser Do Not Track (DNT) signals, we do not currently respond to DNT separately, but our default posture is privacy-minimal and analytics are off until enabled and consented.