Cortex
MethodWhat We BuildEvidenceAbout
Take the Audit

Cookie Policy

Version 1.0 Last updated: [PLACEHOLDER: date]

This policy explains the small number of cookies and browser storage items the Cortex site uses, what each one does, and how long it lasts. It also explains why you are not shown a cookie banner, which is that there is nothing here to consent to.


Contents

  1. Why there is no cookie banner
  2. What a cookie is, and what else counts
  3. Strictly necessary cookies and storage
  4. Analytics
  5. Third party embeds
  6. Fonts
  7. How to control cookies in your browser
  8. The legal basis
  9. Changes to this policy
  10. Contact

1. Why there is no cookie banner

Most websites show a consent banner because they set cookies that are not needed to deliver the service: advertising cookies, tracking pixels, analytics cookies that identify a returning device, and cookies set by embedded third parties on page load.

We set none of those. The site sets no advertising cookies, no tracking cookies and no analytics cookies. It builds no profile of you, it does not identify a returning visitor, and it shares nothing about your visit with an advertising network.

The only cookies the site sets are strictly necessary ones, and they only appear once you sign in to the Cortex Portal. Under the Lithuanian Law on Electronic Communications, strictly necessary storage does not require consent, so there is nothing for a banner to ask.

A banner that asked for consent it did not need would be theatre. If we ever add something that does need consent, we will ask for it properly, we will make refusing as easy as accepting, and nothing will be set before you choose.


2. What a cookie is, and what else counts

A cookie is a small text file a website asks your browser to store, and which the browser sends back on later requests.

The law does not only cover cookies. It covers any storage of information on your device, and any access to information already stored there. That includes localStorage, sessionStorage and similar browser storage. So this policy covers those too, even where they are not technically cookies.

We list everything the site stores on your device, whether or not it is a cookie.


3. Strictly necessary cookies and storage

These are needed to deliver something you asked for. They are set only on the pages listed.

3.1 Cortex Portal and administrative sign in

These cookies exist only if you have a Cortex Portal account and sign in. They are set on /portal and /admin and nowhere else. A visitor to the public site never receives them.

| Name pattern | Set by | What it does | Type | Duration | |---|---|---|---|---| | sb-<project-ref>-auth-token | Supabase, first party on our domain | Holds the signed session that keeps you logged in, so you do not have to click a new magic link on every page | Strictly necessary | Session, subject to the session time box. A client session lasts up to 7 days with a 24 hour inactivity timeout. Cleared on sign out | | sb-<project-ref>-auth-token.0, sb-<project-ref>-auth-token.1 and further numbered parts | Supabase, first party on our domain | The same session, split across several cookies where it exceeds the size a single cookie can carry | Strictly necessary | As above | | sb-<project-ref>-auth-token-code-verifier | Supabase, first party on our domain | Holds the one time PKCE verifier between clicking a magic link and completing sign in, so that a sign in link cannot be replayed by anyone who intercepts it | Strictly necessary | A few minutes, then deleted. The magic link itself is valid for 15 minutes and single use |

<project-ref> is the identifier of our database project and is the same for every visitor. It identifies our project, not you.

How they are set. These cookies are HttpOnly, so page scripts cannot read them, Secure, so they are only sent over HTTPS, and SameSite=Lax, so they are not sent on cross site requests. Where the browser supports it they carry the __Host- prefix, which locks them to our exact origin.

Why they are strictly necessary. Without them you would have to authenticate on every page load. They exist only to deliver the authenticated service you asked for, they carry no advertising or analytics function, and they are read only by us.

You can end them at any time by signing out, or by listing and revoking your sessions at /portal/settings.

3.2 The Cortex AI Audit form

| Name | Type of storage | What it does | Duration | |---|---|---|---| | cortex.audit.v1 | sessionStorage, first party. Not a cookie | Holds your answers to the audit questions while you are working through the six steps, so that you can go back to a previous step, and so that an accidental page refresh does not lose nine minutes of work | Until you close the browser tab. It is never sent to a server on its own, and it is deleted by the browser when the tab closes |

This is why the form can say that nothing is stored until you ask for the report. Your answers live in your own browser tab. They reach our servers only twice: once to compute your score, which is done in memory and stored nowhere, and once when you submit the gate and ask for the report. That submission is the only thing written to our database. The Privacy Policy, section 3.2, sets out exactly what that row contains.

sessionStorage is not shared between tabs, is not sent with requests, and cannot be read by another website.

You can clear it by closing the tab, or through your browser's site data controls.

3.3 Bot protection on the audit form

The audit form is free, public and unauthenticated, and each submission triggers a paid model call and an email. We run Cloudflare Turnstile on it to stop automated submissions.

| What | Type | Cookie set | |---|---|---| | Cloudflare Turnstile challenge on /audit | Strictly necessary, security | None. Turnstile is configured with pre-clearance disabled, so it does not set the cf_clearance cookie or any other cookie on your device |

Turnstile receives your IP address, browser and device signals and a challenge token, and returns a pass or fail result to us. That is processing of personal data, and it is covered in the Privacy Policy, section 3.1, under legitimate interest in preventing abuse of our service. It is not storage on your device, so this policy has nothing to ask you for.

If that ever changes, we will ask. If we enable pre-clearance, or adopt any bot protection that stores something on your device beyond what is strictly necessary, we will update this policy, we will ask for consent before anything is stored, and refusing will be as easy as accepting.


4. Analytics

We measure how the site is read. We do it without cookies.

| Service | What it collects | Cookie | Device identifier | |---|---|---|---| | Plausible | Page path, referrer, country, browser, operating system, device type, screen size, and aggregate visit counts | None | None. No cookie, no localStorage entry, no persistent identifier | | Vercel Web Analytics | Page path, referrer, country, browser, device type, and aggregate visit counts | None | None |

What this means.

  • Nothing is stored on your device, and nothing already on it is read. That is why no consent is required.
  • No profile is built. We cannot tell that the person reading the method page today is the person who read the home page yesterday, and we do not try to.
  • The data is aggregate. We see that a page was read a number of times from a number of countries. We do not see who read it.
  • Nothing is shared with an advertising network and nothing is used for advertising.

Where analytics do not run at all.

No analytics script loads on /report, /portal or /admin.

That exclusion is deliberate and it matters. A page view event carrying a report URL would put a company's operating data into an analytics service, and a page view event from inside a client workspace would tell an analytics service what a client was reading. Neither happens, because the script is not on those pages.

[PLACEHOLDER: confirm before publication that the Vercel Web Analytics implementation in use remains cookieless and sets no device identifier. If that changes, this section must move to a consented category and a banner must be added.]


5. Third party embeds

We embed one third party service, and only after you ask for it.

Cal.com, for booking a consultation

Booking a call is optional and it appears on the report page and on the pages that offer a consultation.

The embed does not load when the page loads. Instead you see a button and a one line notice. Nothing is requested from Cal.com, and no Cal.com cookie is set, until you click to show available times.

| Before you click | After you click | |---|---| | No connection to Cal.com. No request, no cookie, no data sent | The Cal.com embed loads. Cal.com sets its own cookies and processes your data under its own privacy notice and cookie policy |

This is a deliberate two click design. It means the choice to involve Cal.com is yours, and it is made before anything happens rather than after.

If you would rather not use the embed at all, you can open Cal.com in a new tab from the same button, or write to us at [PLACEHOLDER: contact email] and we will arrange a time by email.

Cal.com's own cookie and privacy notices are at [PLACEHOLDER: link to the Cal.com privacy policy and cookie policy].

Fathom

Fathom is not on the website. It records and transcribes calls and interviews, which happen on a call platform and not on our site. It sets no cookie on our site and loads no script into any page. What it does with recordings is covered in the Privacy Policy, sections 3.3 and 3.5.

Nothing else

There is no advertising network, no retargeting pixel, no social media widget, no embedded video player, no chat widget and no tag manager on the site.


6. Fonts

We serve our web fonts from our own domain. They are self hosted files. No request is made to Google Fonts or to any other font service when you load a page, which means your IP address is not disclosed to one and no font provider learns which page you are reading.

Fonts set no cookie.


7. How to control cookies in your browser

You do not need to do anything to avoid non essential cookies on this site, because we set none. If you want to control cookies generally, every browser lets you see what is stored, delete it, and block cookies by site or entirely.

| Browser | Where to look | |---|---| | Chrome | Settings, then Privacy and security, then Third-party cookies and Site settings | | Firefox | Settings, then Privacy and Security, then Cookies and Site Data | | Safari | Settings, then Privacy, and Develop or Advanced for stored data | | Edge | Settings, then Cookies and site permissions |

You can also use your browser's private or incognito mode, which discards cookies and browser storage when you close the window.

What happens if you block cookies on this site. The public site works normally, because it does not need any. The Cortex Portal will not work, because the session cookie in section 3.1 is what keeps you signed in. If you block sessionStorage, the audit form will still work but you will lose your answers if you refresh the page or navigate back.

For general guidance on cookies you can also see the material published by the State Data Protection Inspectorate at https://vdai.lrv.lt.


8. The legal basis

Lithuania. The Law on Electronic Communications of the Republic of Lithuania, Article 73(4), implements the ePrivacy Directive. It permits storing information on, or gaining access to information already stored on, a user's terminal equipment only with the user's consent, given after clear and comprehensive information, except where the storage or access is strictly necessary for the provision of a service explicitly requested by the user.

That exception is the basis for everything in section 3. The Portal session cookies exist solely to deliver the authenticated service you asked for by signing in. The audit form's sessionStorage entry exists solely to deliver the form you asked for by starting it. Neither has any advertising or analytics function.

Our cookieless analytics fall outside Article 73(4) altogether, because they neither store information on your device nor access information already stored there.

Guidance we follow. The State Data Protection Inspectorate's position is that legitimate interest cannot be used as a basis for non essential cookies, that analytics cookies require consent, and that refusing must be as easy as accepting. We follow that position, and we have designed the site so that the question does not arise: there are no non essential cookies to ask about, the analytics are cookieless, and the one third party embed loads only on a click.

Personal data. Where the information involved is also personal data, its processing is governed by the General Data Protection Regulation and is described in our Privacy Policy. Consent under Article 73(4) and a lawful basis under the GDPR are two separate requirements, and this policy addresses the first while the Privacy Policy addresses the second.

Provider information. Our name, address, registration number, VAT number and contact details are published on the About page, in the site footer, and in the Terms of Service, as the Law on Information Society Services requires.


9. Changes to this policy

We update this policy whenever what the site stores changes. When we do, the version number and the date at the top change.

If we ever add something that needs consent, we will not add it quietly. We will publish the updated policy first, ask for consent through a proper banner before anything is stored, offer a genuine choice in which refusing is as easy as accepting, and let you change your mind afterwards from a link in the footer.


10. Contact

Questions about cookies, about this policy, or about anything the site stores:

Cortex
Cason Consulting MB
J. Savickio St. 4-7, LT-01108 Vilnius, Lithuania
[PLACEHOLDER: contact email]

Every message is read by the practice. We reply within two working days.

Related documents. Privacy Policy at /privacy. Terms of Service at /terms. Security page at /security.


Counsel review

These documents were drafted as working versions on 3 September 2026. They reflect the architecture and the front end implementation of the site as designed on that date, and the regulatory position verified on that date.

They must be reviewed by Lithuanian counsel before publication, together with the Terms of Service, the Privacy Policy and the Data Processing Agreement. Specific matters flagged for counsel in this document: whether the strictly necessary exemption in Article 73(4) is correctly applied to each item in section 3, whether the cookieless analytics implementations actually in use fall outside Article 73(4) as described in section 4, and whether the two click Cal.com embed as built is sufficient to place the setting of Cal.com's cookies within the visitor's own request.

The cookie table in section 3 must be verified against the deployed application before publication, by inspecting the cookies actually set on /portal and /admin, and it must be re-verified whenever the authentication library is upgraded.

Every [PLACEHOLDER: ...] must be resolved before publication.

Cortex is a trading name of Cason Consulting MB.

Company code 307655812. Register of Legal Entities of the Republic of Lithuania.

J. Savickio St. 4-7, LT-01108 Vilnius, Lithuania. Not VAT registered.

hello@[domain]

Cortex

Organisational intelligence.
Operated by Cason Consulting MB.

The Practice
The MethodWhat We BuildThe Audit
The Work
EvidenceThe PortalSecurity
Company
AboutJournalContact
Legal
PrivacyTermsCookiesHow we use AI
The Journal, by email

One essay a month on how companies actually run. Unsubscribe in one click.

Follow
in
© 2026 Cortex. Operated by Cason Consulting MB. All rights reserved.Back to top ↑