Cookie Policy
Last updated: September 10, 2026
This document is an initial courtesy version and may be updated; the current version always lives on this page.
1. What this page covers
When you use kalu, we store a few small things in your browser. This page says exactly which ones, what they are for and how long they last.
Two technologies are involved. Cookies are tiny files a site stores in your browser and that get sent back with every request. Local storage (`localStorage` and `sessionStorage`) keeps data in your browser but does not send it anywhere on its own: only kalu's code reads it, while it runs on your screen.
The law treats them the same — the European rules on storing information on a user's device cover both — which is why both are listed here. Most cookie policies leave local storage out; this one does not.
kalu sets no cookies of its own. Your session does not live in a cookie: it lives in local storage. Every cookie you may end up with comes from a third party, and they are all listed below.
2. How consent works
It is not the same everywhere, and the difference is deliberate.
If you visit from the European Economic Area, the United Kingdom or Switzerland: when you open kalu, everything that is not strictly necessary is off. No measurement cookie is written. The banner appears, and nothing is switched on until you answer.
If you visit from Mexico or the rest of the world: measurement is on from the start and we do not show you the banner. We tell you here and in the privacy notice, and the way out stays open: "Cookie preferences" brings the banner back whenever you want, and declining switches measurement off immediately.
Why the difference. European regulation requires permission *before* anything is written. Mexican data protection law works through prior notice and a right to object: we tell you what we do and you may object. Both are valid in their own territory, and we apply each to the people it covers.
How we know where you are without asking: we use the time zone your browser already knows. It is not your real location and does not pretend to be, and the rule always leans towards asking too often: if the time zone cannot be read, you get the banner.
In every region, no matter what, advertising is denied. kalu uses no advertising cookies and no ad trackers. This is not a preference you can change: it is switched off in the code, for everyone.
3. How to change or withdraw your decision
You can change your mind whenever you like, and changing it is as easy as giving it:
- In the app: Settings → Legal → "Cookie preferences".
- On the public site: the "Cookie preferences" button in the footer of the home page, of this page and of the other legal documents.
4. What happens when you decline
- Measurement stops immediately: Google stops writing cookies and switches to a cookieless mode that does not identify you.
- Any measurement cookies already on your device are deleted at that moment.
- Strictly necessary cookies and keys stay: without them you cannot sign in or stay signed in.
- Your decision is stored in your own browser, under the key `kalu:consent`. If you clear the site's data it is forgotten — and in the EEA, the UK and Switzerland we will ask you again.
6. Local storage
Lives in your browser until you clear the site's data.
| Key | What for | Category |
|---|---|---|
sb-<project>-auth-token | Your session: the token that keeps you signed in without retyping your password | Strictly necessary |
kalu:consent | Your own decision about measurement. It is the record of your consent | Strictly necessary |
kalu:invite | An invitation token, so it survives the round trip through email | Strictly necessary |
kalu:beta | A beta invitation token, for the same reason | Strictly necessary |
kalu:campana | A public campaign code and, when the link carried them, its origin parameters (`utm_source`, `utm_medium`, `utm_campaign`). Without it the discount the link promised is not applied when you come back from email | Strictly necessary |
kalu:feed-auto-build:<org> | Stopping your feed from being rebuilt more than once | Strictly necessary |
kalu:lang | Your interface language | Preferences |
kalu:sidebar-collapsed | Whether you left the sidebar collapsed | Preferences |
kalu:recorrido-riel-colapsado | The same, inside the guided demo | Preferences |
kalu:stories-audio-muted | Whether you left stories muted | Preferences |
kalu:search-recent | Your recent searches | Preferences |
kalu:owner-rail-solo-dismissed | That you already dismissed a sidebar notice | Preferences |
kalu:stories-seen:<org> | Which stories you have already seen | Functional |
kalu:onboarding-draft:<org> | The draft of your radar while you fill it in, so you do not lose it. May contain client company names. Cleared when you finish | Functional |
kalu:strategy:<story> | An already computed analysis of a story, so we do not request it twice. Expires after 12 hours | Functional |
kalu:ref | Which email or notification you arrived from. Expires after 7 days | Measurement |
kalu:primer-feed | The marker that you have already built your first feed | Measurement |
7. Session storage
Cleared when you close the tab.
| Key | What for | Category |
|---|---|---|
kalu:next | Where to take you after you sign in | Strictly necessary |
kalu:plan-intent | Which package you chose before creating the account | Strictly necessary |
kalu:feed-build-handoff | Continuity while your feed is being built | Strictly necessary |
kalu:chunk-reload | That a reload was already attempted after a new deployment, to avoid a reload loop | Strictly necessary |
kalu:feed-scroll:<section> | Returning you to where you were in the feed | Preferences |
kalu:ga:purchase | Avoiding counting the same purchase twice | Measurement |
kalu:origen-visita | Which page you entered kalu through and, if the link carried them, its campaign parameters (`utm_source`, `utm_medium`, `utm_campaign`). It is only sent if you request a demo, together with that request. Not written if you declined measurement | Measurement |
8. A precision about the measurement keys
Four keys in the tables above — `kalu:ref`, `kalu:primer-feed`, `kalu:ga:purchase` and `kalu:consent` itself — are labelled "Measurement" or feed measurement, and it is worth being exact about what happens to them when you decline.
They are still written to your browser. They are not cookies, they do not travel on their own and they do not leave your device by themselves: they are markers kalu's code leaves so it does not count the same purchase twice, does not repeat an event, and knows which email you came from.
What does respect your decision is what Google does with them. The event they feed goes through consent mode: with measurement declined, Google processes it without cookies and without identifying you. We prefer saying this to relabelling them so the table looks tidier.
9. Who receives anything, and where they are
The full list of providers, including those that store nothing in your browser, is in section 4 of the privacy notice.
| Third party | What it receives | Where | Their policy |
|---|---|---|---|
| Google (Analytics 4 and Tag Manager) | IP address, browser and pages visited. With measurement declined, cookieless and without identifying you | United States | policies.google.com/privacy |
| Cloudflare (Turnstile) | IP and technical browser signals, on the sign-in screen only | Global | cloudflare.com/privacypolicy |
| Vimeo, Dailymotion and MediaStream | IP and technical data, only if you press play | Per provider | Each provider's own |
Stripe | Your payment details, on its own checkout screen | United States | stripe.com/privacy |
Supabase | Hosting and database | United States | supabase.com/privacy |
Vercel | Hosting for the web application | United States | vercel.com/legal/privacy-policy |
Sentry | Technical application errors | United States | sentry.io/privacy |
11. Changes to this policy
If what we store changes, we update this page and move the date at the top. If the change affects what we do with measurement, we ask you again through the banner.
12. Contact
For any question about this policy, or to exercise your rights over the data it covers, write to our contact email.