Legal · Last updated: 16 August 2026
Cookie Policy
1. Controller
AGICYis the brand / project operator of agicy.ai, pending incorporation of the planned Cap. 113 vehicle AGICY Holdings Ltd (target / not yet formed — no company yet registered; no HE number published). Contact: agi@agicy.ai.
2. Consent banner
On first visit we show a cookie preferences panel. You can Accept all, Reject non-essential, or open Preferences. A persistent Cookies control (bottom-left) reopens preferences at any time. Functional cookies (agicy_ref, agicy_utm) and optional analytics are not set until you consent.
3. What are cookies?
Cookies are small text files stored on your device. We also use similar technologies (localStorage / sessionStorage) where noted below.
4. Cookies & storage in use
| Name | Purpose | Type | Duration | Set by |
|---|---|---|---|---|
| agicy_consent | Stores cookie preference choice (necessary / functional / analytics) | Strictly necessary | 365 days | AGICY (CMP) |
| Supabase auth tokens | Authenticated session (dashboard, data room login) | Strictly necessary | Session / refresh per Supabase config | Supabase (first-party) |
| agicy_nda_jwt | Investor data-room NDA gate (HttpOnly JWT bound to session email) | Strictly necessary | 365 days (HttpOnly) | AGICY /api/nda/sign |
| agicy_nda_signed | Legacy NDA flag — production prefers agicy_nda_jwt; may appear in non-prod | Strictly necessary | 365 days | AGICY server / legacy client |
| agicy_invite | Invitation waitlist (corporate email + The Ledger). Lets the browser skip the /gate video after signup | Strictly necessary | 180 days (HttpOnly) | AGICY /api/access-gate |
| agicy_ref | First-touch referral attribution (partner / affiliate code) | Functional — consent required | 30 days | AGICY after Functional consent |
| agicy_utm | Campaign attribution (UTM source / medium / campaign) | Functional — consent required | 30 days | AGICY after Functional consent |
| cf-turnstile-* | Cloudflare Turnstile bot challenge (Playground and AI Readiness Audit, when enabled) | Strictly necessary | Session | Cloudflare |
| agicy_dev_session | Development-only auth bypass — disabled in production builds | Strictly necessary (dev only) | Session / 365 days in dev | AGICY (non-production) |
Browser storage (not cookies): agicy_nda_session (NDA UI display), playground / chat session keys, access-gate helpers, SRA draft state. These support features you request; clear site data in your browser to remove them.
5. Legal basis
- Strictly necessary — ePrivacy Art. 5(3) exception / GDPR Art. 6(1)(f) for secure operation (auth, NDA gate, invitation waitlist cookie, consent memory, bot protection).
- Functional (agicy_ref, agicy_utm) — GDPR Art. 6(1)(a) consent via the banner before storage (ePrivacy Art. 5(3)).
- Analytics — Art. 6(1)(a) consent. First-party product events only; Google Analytics / Meta Pixel / ad retargeting are not deployed. No GTM container is loaded until counsel-approved and consent-gated.
6. Third-party cookies
We do not deploy Google Analytics, Meta Pixel, or advertising retargeting cookies. Cloudflare Turnstile may set session cookies when the Playground bot challenge is enabled.
7. Your choices
Use the on-site Cookies control, or block cookies in your browser. Blocking strictly necessary cookies will prevent login, dashboard access, and investor data-room entry. Questions: agi@agicy.ai.
8. Related policies
See our Privacy Policy for personal data processing, retention, and sub-processors.