1. What cookies are
Cookies are small text files a website places on your device. They allow the site to remember you across page loads (for example, to keep you signed in) and to distinguish one visitor's session from another. Some cookies are set by us; some are set by services we embed (like the payment provider). This page lists them all.
2. Cookie categories we use
- Strictly necessary — required for the site to work (authentication, security tokens, session state). These cannot be disabled from within the site because the site cannot function without them.
- Functional — remember non-essential preferences (like the last dashboard tab you visited). Cleared on logout.
We do not set analytics, advertising, or cross-site tracking cookies from clincue.com. If in future we add privacy-friendly analytics, we will update this policy and provide a consent banner in accordance with UK PECR / EU ePrivacy.
3. Cookie inventory
| Name | Provider | Purpose | Category | Lifetime |
|---|---|---|---|---|
| sb-* (Supabase auth) | Clincue (localStorage-based) | Keeps you signed in to the Clincue dashboard. | Strictly necessary | Session + refresh token (up to 30 days rolling) |
| clincue.pref.* | Clincue | Remembers UI preferences (e.g. sidebar collapse state). | Functional | 1 year |
| __cf_bm | Cloudflare | Distinguishes real browsers from automated bots to protect the site. | Strictly necessary | 30 minutes |
| paddle-* | Paddle.com | Set only during the paid checkout flow to run the payment page and store fraud-prevention state. | Strictly necessary | Session |
4. Cookies set by the embedded chat widget
When a clinic embeds the Clincue chat widget on its own website, the widget stores a lightweight visitor identifier in the visitor's browser (typically in localStorage, not a cookie) so that a single conversation stays coherent across page loads. This identifier is a random UUID; it contains no personal data and is scoped to that clinic's domain and Clincue's own domain. Clinics are responsible for disclosing this in their own privacy notice.
5. How to manage cookies
Most browsers let you view, block, or delete cookies. Because the cookies we set are strictly necessary or functional, disabling them will break parts of the dashboard (typically the sign-in flow). Guidance for common browsers: Chrome, Firefox, Safari, Edge, Brave — each offers cookie controls in Preferences / Settings.
6. Do Not Track
Because we do not use tracking cookies, no additional behaviour is applied when your browser sends the Do Not Track (DNT) signal.
7. Changes to this Cookie Policy
We will update this page whenever we add or remove a cookie. The "Last updated" date at the top reflects the current inventory.
8. Contact
Cookie or tracking questions — privacy@clincue.com.