Sign in

Legal & policies

How FundyBee works, what we do with your data, and the terms you agree to when you use the service.

TermsPrivacyCookiesData processingRefundsWithdraw

Cookie Policy

Effective date: 31 August 2026 · Version 2026-08-31

Contents

  1. 1. Scope
  2. 2. Cookies
  3. 3. Local storage
  4. 4. Session storage
  5. 5. External resources
  6. 6. Consent for optional analytics
  7. 7. Managing storage
  8. 8. Changes and contact

1. Scope

This policy covers cookies and similar device-storage technologies used by FundyBee. Cookies are small values sent with web requests. Local storage persists in your browser until it is removed; session storage normally lasts for the current tab or browser session. These technologies are also covered by ePrivacy rules.

Essential storage is used to authenticate users, secure and operate requested features, preserve a workflow across navigation, or remember a setting the user selected. Optional Google Analytics cookies are used only after you accept them in the cookie banner. We do not use advertising, retargeting or other cross-site tracking cookies.

2. Cookies

NamePurposeDuration and category
sb-*Supabase authentication and refresh-token chunks used to sign you in, rotate a session and protect authenticated requests. The exact project/chunk suffix varies.Up to 400 days and refreshed while the session is used; sign-out or account/session invalidation ends access. Strictly necessary.
gp_active_accountStores the selected workspace identifier when a user belongs to more than one workspace.Up to 365 days; strictly necessary for the selected workspace.
gp_refresh_notificationsShort-lived signal after sign-in or invitation acceptance so the notification list refreshes once.Up to 120 seconds and then removed/expired; strictly necessary.
__cf_bm (conditional)Cloudflare bot-management security when that protection is enabled for the request.Expires after 30 minutes of inactivity; strictly necessary security.
cf_clearance (conditional)Remembers that a visitor passed a Cloudflare security challenge so the requested site can be reached.Configured challenge-passage period (Cloudflare default: 30 minutes); strictly necessary security.
cf_chl_* (conditional)Short-lived Cloudflare challenge state used only while a security check is in progress.Challenge/session duration; strictly necessary security.
_ga, _ga_* (optional)Google Analytics 4 measurement cookies used to distinguish visitors and remember a session so we can see which pages are used. They are set only after you accept analytics. Advertising signals are disabled in our tag configuration.Up to 24 months, or until you reject analytics or clear site data. Optional, consent required.

3. Local storage

KeyPurposeDuration
gp_analytics_consentStores your analytics choice (granted or denied) so the banner does not ask again until you change it. It does not itself send data to Google.Until you change the choice or browser data is cleared.
fundybee-themeRemembers the light/dark theme selected by the user.Until changed or browser data is cleared.
fundybee:freeplan-banner-dismissedRemembers that the user dismissed the free-plan information banner.Until the subscription flow clears it or browser data is cleared.
gp.onboardingWizard.dismissed.v1Remembers that the onboarding wizard was dismissed on this browser. The answers themselves are stored with the signed-in login.Until browser data is cleared or the key version changes.
gp.onboardingTour.dismissed.v1Remembers that the projects tour was dismissed or completed.Until browser data is cleared or the key version changes.
fundybee:proposal-pipeline:<project-id>Lets an active write-and-review run recover its visible phase after a page refresh.Treated as stale and removed when read after 24 hours; can remain until then or until cleared.

4. Session storage

KeyPurposeDuration
gp-notifications-refreshOne-time client signal to refresh notifications after navigation.Current tab; removed when consumed.
gp-studio-conceptTemporarily preserves the current Idea Lab generation state during the session.Current tab/session or explicit removal.
gp-studio-client-tokenCorrelates a browser-side Idea Lab run with the server operation and avoids duplicate work.Current tab/session or explicit removal.
gp-partner-prefillMoves a customer-selected partner/PIF prefill between partner-library screens.Current tab; removed after it is read.
gp-studio-discard-noticeShows a one-time confirmation after an Idea Lab draft is discarded.Current tab; removed when consumed.
fb-proposal-assistant-openRemembers whether the proposal assistant rail is open within the current tab.Current tab/session.

5. External resources

Fonts and icon styles are served with the application. After you accept analytics, the Google tag loads from googletagmanager.com and measurement hits go to Google Analytics for property G-3Y7PLD3Z6G. That request includes ordinary connection data such as IP address, user agent, page path (with project and invite identifiers removed) and a client identifier stored in the _gacookies. Proposal text and account passwords are not sent as analytics events. An embedded public landing-page demonstration loads the GSAP animation script from jsDelivr, which receives ordinary connection data such as IP address and user agent. No account or proposal content is intentionally sent. When a signer opens the optional self-hosted DocuSeal signing page, that service may use cookies or storage needed to load and complete the requested signature workflow. DocuSeal’s technology and privacy terms apply. See the Privacy Notice provider table.

6. Consent for optional analytics

The first-visit banner is a consent control for optional Google Analytics, not an “accept all” advertising wall. Essential only keeps strictly necessary storage and does not load the Google tag. Accept analytics stores gp_analytics_consent=granted and then loads the tag. You can change the choice at any time.

Essential cookies remain covered by the ePrivacy exemption for storage strictly necessary to provide the Service or a setting you selected. Advertising cookies are not used.

7. Managing storage

Browser settings can inspect, clear or block cookies and site data. Blocking authentication cookies will prevent sign-in; clearing local/session storage resets preferences and temporary workflow continuity but does not delete server-side account or project data. Use Account & privacy or contact us for server-side rights requests.

8. Changes and contact

We update this table when the application adds, removes or changes a browser-storage key. Questions or reports of an unlisted technology can be sent to info@innovationbee.gr. The effective date and version above identify the current policy.