Cookie Policy

Cookies & local storage

Decoder is privacy-first. It uses only strictly necessary and functional storage to keep you signed in and remember your preferences. No analytics, no marketing, no profiling, no third-party tracking.

Why there is no cookie banner

Under EU ePrivacy and GDPR guidance, strictly necessary and purely functional storage tied to a feature you explicitly use does not require prior consent. We do not load any non-essential trackers, so a consent banner would be unnecessary friction.

What we actually store

The full list of cookies and browser storage used by Decoder:

NamePurposeStorageRetention
sb-* (Supabase auth)Keeps you signed in securelyCookie / localStorageUntil sign-out or token expiry
i18nextLngRemembers your interface languagelocalStorageUntil you clear browser data
themeRemembers dark / light preferencelocalStorageUntil you clear browser data
decoder.disclaimer.acceptedAtRecords that you saw the sign-in disclaimerlocalStorageUntil you clear browser data
user_acknowledgementsStores your BYOK and onboarding acknowledgementServer database (your account)Until you delete your account or the acknowledgement

What we do NOT use

Decoder does not load any of the following:

  • Analytics tools (Google Analytics, Plausible, Vercel Analytics, PostHog, Mixpanel, Amplitude, Segment, …)
  • Marketing or advertising cookies and remarketing tags
  • Heatmaps or session recording (Hotjar, FullStory, …)
  • Third-party pixels (Meta Pixel, LinkedIn Insight, Google Tag Manager, …)

Third-party calls

When you analyze code, requests may be sent to the AI provider you explicitly configure (BYOK) or to a local model you run yourself. Those providers have their own policies. See the Data Flow page for details.

How to clear or withdraw

You can sign out at any time, clear your browser storage, or delete your account and acknowledgements from Settings. Removing an API key stops future calls to that provider.

Last updated: 2026-06-07

DecoderDecoder is an open-source educational code-understanding case study. It is not a certified security audit tool, legal/compliance tool, or production decision system. AI-generated outputs may be inaccurate and must be reviewed by a qualified person.