Legal
Cookie Policy
This Cookie Policy explains how VisibleMax uses cookies and similar technologies on our website and application, and how you can control them.
Effective date: August 6, 2026
Last updated: August 6, 2026
These pages are provided for transparency and operational clarity. They are not legal advice. VisibleMax is not yet legally incorporated; entity name, registered address, and governing law must be updated after incorporation and reviewed by qualified counsel before relying on these policies for commercial launch, regulatory filings, or customer contracts.
1. What are cookies?
Cookies are small text files stored on your device when you visit a website. Similar technologies include local storage, session storage, and pixels. We use "cookies" in this Policy to refer to these technologies collectively where the distinction is not material.
VisibleMax operates under the product operating name VisibleMax. Entity name, registered address, and governing law will be updated after incorporation. Placeholder: [PLACEHOLDER — update after incorporation: registered legal entity name, registered address, and governing law / venue].
2. How VisibleMax uses cookies
We use cookies for the following purposes:
2.1 Essential / strictly necessary cookies
These cookies are required for the Service to function. Without them, you may not be able to sign in, stay signed in, or use protected features.
- Authentication / session cookies (Supabase) — maintain your signed-in session across requests. These cookies enable secure access to your account, projects, scans, billing status, and settings. Session cookies are refreshed as you use the app and are essential for authenticated routes. Supabase Auth cookies are strictly necessary for login and are not used for advertising.
- Security and abuse prevention — support CSRF protections, rate limiting signals, and similar controls where applicable.
- Load balancing / infrastructure — cookies or similar headers set by hosting infrastructure (for example via Vercel) to route requests reliably.
- Cookie consent preference — a small preference record that remembers whether you accepted or declined optional analytics, so we do not re-prompt on every page load.
Because these cookies are necessary to provide the Service you request (or to store your consent choice), they are typically set on the basis of our contract with you and/or legitimate interests in operating a secure product — or consent where that record stores your analytics choice.
2.2 Preference cookies
We may store UI preferences (for example sidebar collapsed state or theme preference) so the interface remembers your choices between visits. These cookies are not used for advertising or third-party tracking.
2.3 Optional analytics cookies (PostHog)
VisibleMax may use PostHog as optional product analytics to understand feature usage, diagnose issues, and improve the product. PostHog may set cookies or use local storage to collect pseudonymous identifiers, page views, and event data.
PostHog analytics is gated by our cookie consent banner. Optional analytics cookies and related storage are set or activated only after you accept analytics (or equivalent optional) cookies through the consent banner. If you decline, we will not enable PostHog analytics tracking for that consent choice. You can change your mind later by clearing site data / cookies and revisiting the site to see the banner again, or by contacting [email protected].
We do not use cookies on the marketing site or app for third-party advertising networks as a core practice. If that changes, we will update this Policy and provide required notices.
Analytics data, like other customer data, is not used to train AI models. See AI Transparency and our Privacy Policy.
3. Cookie categories summary
- Essential — Supabase auth/session, security, core app functionality, consent preference storage
- Preferences — UI and similar non-advertising settings
- Analytics (optional) — PostHog product usage measurement, only when consented via the cookie banner
4. Duration
Session cookies expire when you close your browser or after a short inactivity window, depending on configuration. Persistent cookies (such as longer-lived Supabase auth cookies, preference cookies, or PostHog identifiers when consented) remain until they expire or you delete them. Auth cookie lifetimes are designed to keep you signed in for a practical period while allowing renewal on active use; exact durations may change for security reasons.
5. How to control cookies
- Cookie consent banner — accept or decline optional PostHog analytics. Essential Supabase auth cookies are required for login regardless of analytics choice.
- Browser settings — most browsers let you block or delete cookies. Blocking essential cookies will break login and authenticated features.
- Private browsing — may limit persistence and require more frequent re-authentication and re-consent.
- Sign out — ending your session clears or invalidates auth cookies associated with that session where supported.
- PostHog / vendor controls — when analytics is enabled by consent, PostHog may also offer additional controls; we will honor banner choices first.
Device-level controls differ by browser and OS. Consult your browser's help documentation for instructions.
6. Do Not Track
There is no uniform industry standard for Do Not Track (DNT) browser signals. Our primary control for optional analytics is the cookie consent banner. We will update this section if we implement a consistent additional DNT response mechanism.
7. Updates
We may update this Cookie Policy when our practices or providers change (including after incorporation). The "Last updated" date at the top reflects the latest revision.
8. More information
For broader data practices, see our Privacy Policy. Questions: [email protected].