Legal

Cookie Policy

Last updated: 13 June 2026

1. What cookies are

Cookies are small text files placed on your device when you visit a website. Some are essential for the site to work; others are optional and only set with your consent. We also use similar technologies such as browser local storage to keep you signed in and to remember your preferences. In this policy, "cookies" refers to all of these technologies.

2. The categories we use

Strictly necessary: required for the site to function, such as authentication, keeping you securely signed in, security, and remembering your cookie choices. These are always on and cannot be switched off.

Analytics (optional): help us understand how the product is used, in aggregate, so we can improve it. Only set if you accept them.

Marketing (optional): used to measure campaigns and personalise content. Only set if you accept them.

3. Cookies and technologies we rely on

Authentication & session (strictly necessary): set by our authentication provider (Supabase) and stored in your browser to keep you securely signed in.

Cookie preferences (strictly necessary): we store your consent choices in your browser so we don't ask again on every visit.

Checkout (strictly necessary at the point of payment): our payment provider, Paddle, which acts as Merchant of Record, sets cookies needed to process a subscription securely.

Analytics (optional): if enabled, a privacy-focused analytics tool records aggregated, non-identifying usage to help us improve the product.

4. Managing your preferences

When you first visit, a banner lets you accept all, decline non-essential cookies, or customise by category. You can change your choice at any time by clearing your saved cookie preference and reloading the page, which brings the banner back. You can also block or delete cookies in your browser settings. Note that strictly necessary cookies are required for the site to function, so disabling them may break sign-in.

5. Third-party cookies

Some cookies are set by trusted third parties we use to operate Citeon, such as Supabase (authentication), Paddle (payments) and, where enabled, our analytics provider. These providers process data under their own terms. See our Privacy Policy for more on how we handle personal data and the sub-processors we use.

6. Do Not Track

Some browsers offer a "Do Not Track" signal. Because there is no agreed industry standard for how to respond to it, we currently do not change our behaviour based on these signals. Instead, you control non-essential cookies through the banner described above.

7. Changes to this policy

We may update this Cookie Policy as the product and applicable laws change. We will revise the "last updated" date above whenever we do.

8. Contact

Questions about how we use cookies? Email us at support@citeon.dev.