Legal · Cyber Roundtable

Cookie Notice

Cyber Roundtable uses a small number of cookies and browser-storage entries to make the service work.

The current inventory · everything we set4 entries · 0 tracking
EntryTypeClassPurpose
Supabase Auth sessionCookieNecessaryAccount sessions and authentication.
Cloudflare TurnstileCookieNecessaryHuman verification, security, and abuse prevention.
cookieConsent=truelocalStorageNotice-onlyRemembers you dismissed the cookie notice, so it doesn't reappear.
crt_ai_disclaimer_dismissedCookie · 1 yrNotice-onlyRemembers the AI disclaimer acknowledgement; does not track browsing behavior.
No analytics cookies · no fingerprinting · no localStorage identifiers
Section 01

Strictly necessary cookies

Strictly necessary cookies support account sessions, authentication, security, and abuse prevention. These do not require optional marketing consent because the service cannot safely operate without them.

Current examples include Supabase Auth session cookies and Cloudflare Turnstile security checks.

Section 02

Local storage

The cookie notice dismissal is stored in localStorage as cookieConsent=true. This prevents the notice from reappearing after you press OK.

The first-time custom-run guide may use localStorage in a later slice so that the same guide is not shown repeatedly.

Section 03

AI disclaimer cookie

The AI disclaimer acknowledgement is stored as a cookie named crt_ai_disclaimer_dismissed for one year. It only remembers that you acknowledged the disclaimer; it does not track browsing behavior.

Section 04

Analytics

Cyber Roundtable application analytics use Plausible as the approved SLICE-322 cookieless provider when NEXT_PUBLIC_CRT_ANALYTICS_PROVIDER=plausible. The provider must run without analytics cookies, browser fingerprinting, or localStorage identifiers.

The baseline event contract is limited to path-level page and zone events such as Today zone reach and persona-page views; it does not send account IDs, email addresses, raw queries, or custom Roundtable content. Launch-funnel events use a random identifier scoped to the current browser tab so steps can be correlated without identifying the account; the authoritative first-launch KPI is computed in Cyber Roundtable's service-only database.

Cloudflare may process limited edge or browser telemetry for security, performance, and infrastructure measurement outside the application analytics provider. Any Cloudflare edge analytics beacon must either remain disabled for the program metrics baseline or be separately approved with IP handling, data-processing terms, and the exact event set before it is treated as Cyber Roundtable analytics.

Section 05

Current consent choice

The current banner has one OK button because the current cookie inventory is limited to necessary cookies, non-tracking storage, approved cookieless analytics, and approved cookieless infrastructure telemetry. The OK button is notice acknowledgement only; it is not used as an analytics opt-in. Granular controls will be added if the inventory changes.

Section 06

Contact

Cookie questions can be sent to [email protected].

End of notice · Draft · Effective May 11, 2026Back to top ↑

Unified Search

Search the public record.