Cookie Policy

Last updated: September 10, 2026

This document is an initial courtesy version and may be updated; the current version always lives on this page.

1. What this page covers

When you use kalu, we store a few small things in your browser. This page says exactly which ones, what they are for and how long they last.

Two technologies are involved. Cookies are tiny files a site stores in your browser and that get sent back with every request. Local storage (`localStorage` and `sessionStorage`) keeps data in your browser but does not send it anywhere on its own: only kalu's code reads it, while it runs on your screen.

The law treats them the same — the European rules on storing information on a user's device cover both — which is why both are listed here. Most cookie policies leave local storage out; this one does not.

kalu sets no cookies of its own. Your session does not live in a cookie: it lives in local storage. Every cookie you may end up with comes from a third party, and they are all listed below.

3. How to change or withdraw your decision

You can change your mind whenever you like, and changing it is as easy as giving it:

  • In the app: Settings → Legal → "Cookie preferences".
  • On the public site: the "Cookie preferences" button in the footer of the home page, of this page and of the other legal documents.

4. What happens when you decline

  • Measurement stops immediately: Google stops writing cookies and switches to a cookieless mode that does not identify you.
  • Any measurement cookies already on your device are deleted at that moment.
  • Strictly necessary cookies and keys stay: without them you cannot sign in or stay signed in.
  • Your decision is stored in your own browser, under the key `kalu:consent`. If you clear the site's data it is forgotten — and in the EEA, the UK and Switzerland we will ask you again.

5. Cookies

kalu sets none. These are set by third parties:

Video players only load if you press play. Until you do, neither Vimeo, nor Dailymotion, nor MediaStream receives anything. YouTube sets no cookies on kalu: every YouTube URL is rewritten to `youtube-nocookie.com` before it is shown.

Cookies third parties may write while you use kalu
CookieWho sets itWhat forCategoryLifetime
_gaGoogle Analytics 4, via Google Tag ManagerTelling unique visitors apartMeasurement2 years
_ga_<id>Google Analytics 4Keeping measurement session stateMeasurement2 years
vuidVimeoPlaying the video in a storyThird-party measurement2 years
Player cookiesDailymotion, MediaStream (mdstrm.com)Playing the video in a storyThird-party measurementPer provider
Challenge cookiesCloudflare TurnstileTelling people from bots on the sign-in screenStrictly necessarySession

6. Local storage

Lives in your browser until you clear the site's data.

localStorage keys kalu writes
KeyWhat forCategory
sb-<project>-auth-tokenYour session: the token that keeps you signed in without retyping your passwordStrictly necessary
kalu:consentYour own decision about measurement. It is the record of your consentStrictly necessary
kalu:inviteAn invitation token, so it survives the round trip through emailStrictly necessary
kalu:betaA beta invitation token, for the same reasonStrictly necessary
kalu:campanaA public campaign code and, when the link carried them, its origin parameters (`utm_source`, `utm_medium`, `utm_campaign`). Without it the discount the link promised is not applied when you come back from emailStrictly necessary
kalu:feed-auto-build:<org>Stopping your feed from being rebuilt more than onceStrictly necessary
kalu:langYour interface languagePreferences
kalu:sidebar-collapsedWhether you left the sidebar collapsedPreferences
kalu:recorrido-riel-colapsadoThe same, inside the guided demoPreferences
kalu:stories-audio-mutedWhether you left stories mutedPreferences
kalu:search-recentYour recent searchesPreferences
kalu:owner-rail-solo-dismissedThat you already dismissed a sidebar noticePreferences
kalu:stories-seen:<org>Which stories you have already seenFunctional
kalu:onboarding-draft:<org>The draft of your radar while you fill it in, so you do not lose it. May contain client company names. Cleared when you finishFunctional
kalu:strategy:<story>An already computed analysis of a story, so we do not request it twice. Expires after 12 hoursFunctional
kalu:refWhich email or notification you arrived from. Expires after 7 daysMeasurement
kalu:primer-feedThe marker that you have already built your first feedMeasurement

7. Session storage

Cleared when you close the tab.

sessionStorage keys kalu writes
KeyWhat forCategory
kalu:nextWhere to take you after you sign inStrictly necessary
kalu:plan-intentWhich package you chose before creating the accountStrictly necessary
kalu:feed-build-handoffContinuity while your feed is being builtStrictly necessary
kalu:chunk-reloadThat a reload was already attempted after a new deployment, to avoid a reload loopStrictly necessary
kalu:feed-scroll:<section>Returning you to where you were in the feedPreferences
kalu:ga:purchaseAvoiding counting the same purchase twiceMeasurement
kalu:origen-visitaWhich page you entered kalu through and, if the link carried them, its campaign parameters (`utm_source`, `utm_medium`, `utm_campaign`). It is only sent if you request a demo, together with that request. Not written if you declined measurementMeasurement

8. A precision about the measurement keys

Four keys in the tables above — `kalu:ref`, `kalu:primer-feed`, `kalu:ga:purchase` and `kalu:consent` itself — are labelled "Measurement" or feed measurement, and it is worth being exact about what happens to them when you decline.

They are still written to your browser. They are not cookies, they do not travel on their own and they do not leave your device by themselves: they are markers kalu's code leaves so it does not count the same purchase twice, does not repeat an event, and knows which email you came from.

What does respect your decision is what Google does with them. The event they feed goes through consent mode: with measurement declined, Google processes it without cookies and without identifying you. We prefer saying this to relabelling them so the table looks tidier.

9. Who receives anything, and where they are

The full list of providers, including those that store nothing in your browser, is in section 4 of the privacy notice.

Third parties that receive data when you use kalu
Third partyWhat it receivesWhereTheir policy
Google (Analytics 4 and Tag Manager)IP address, browser and pages visited. With measurement declined, cookieless and without identifying youUnited Statespolicies.google.com/privacy
Cloudflare (Turnstile)IP and technical browser signals, on the sign-in screen onlyGlobalcloudflare.com/privacypolicy
Vimeo, Dailymotion and MediaStreamIP and technical data, only if you press playPer providerEach provider's own
StripeYour payment details, on its own checkout screenUnited Statesstripe.com/privacy
SupabaseHosting and databaseUnited Statessupabase.com/privacy
VercelHosting for the web applicationUnited Statesvercel.com/legal/privacy-policy
SentryTechnical application errorsUnited Statessentry.io/privacy

10. How to block cookies from your browser

You can block or delete them without going through us. Bear in mind that blocking the strictly necessary ones means you will not be able to sign in.

  • Chrome: Settings → Privacy and security → Cookies and other site data.
  • Safari: Preferences → Privacy → Manage website data.
  • Firefox: Settings → Privacy & Security → Cookies and Site Data.
  • Edge: Settings → Cookies and site permissions.
  • To switch Google Analytics off across every site you visit, Google publishes an opt-out add-on at `tools.google.com/dlpage/gaoptout`.

11. Changes to this policy

If what we store changes, we update this page and move the date at the top. If the change affects what we do with measurement, we ask you again through the banner.

12. Contact

For any question about this policy, or to exercise your rights over the data it covers, write to our contact email.