Haven IQ

Legal

Cookie Policy

This is the short kind of cookie policy, because Haven IQ uses the short kind of cookie list: a handful of cookies that make the product work, plus ordinary visit analytics on the public website — and nothing else.

Last updated: July 20, 2026

1. What we use — and what we don't

Cookies are small files a website stores in your browser. Haven IQ's functional cookies are all first-party, doing three jobs: keeping you signed in (authentication and session), remembering choices you've made (preferences), and protecting your account (security).

On the public marketing website only — these pages, not the app — we also use Google Analytics to see which pages people visit and how they found us: the ordinary counts that tell us what to write and what to improve. It runs only if you allow it: nothing from Google loads until you say yes in the consent banner, and your answer (either answer) is remembered so we don't keep asking.

Two lines we don't cross: we use no advertising cookies and no analytics inside the app itself— the place where your documents, records, and passwords live sets nothing that measures you. No data about your visit is shared with ad networks or social platforms, and if you'd rather not be counted at all, blocking or deleting the analytics cookies (or using your browser's tracking protection) costs you nothing — every page and every feature works without them.

2. The complete list

CookieWhat it doesLastsType
sb-* (authentication)Keeps you signed in. Set by our authentication provider (Supabase); holds your encrypted session and refresh tokens. Marked HttpOnly and Secure — not readable by scripts.While you stay signed in; cleared on sign-outStrictly necessary
hiq-themeRemembers your Light / Dark / System appearance choice so pages paint correctly.1 yearPreference
hiq-household-typeRemembers the household type you picked during onboarding, so your first dashboard can suggest relevant starter templates.90 daysPreference
hiq_td“Remember this device” for multi-factor authentication, so a trusted device can skip the second factor. Only set if you opt in during MFA sign-in (feature availability may vary).30 daysSecurity
hiq-consentRemembers your analytics choice — allow or decline — so the consent banner doesn't ask again. Exists only to record your answer.180 daysPreference
_ga, _ga_*Google Analytics, on the public marketing website only (never inside the app), and only after you allow it in the consent banner. Tells us which pages people visit and how they found us, via a randomly generated identifier. Declining costs you nothing — every page works without them.Up to 2 yearsAnalytics (Google, opt-in)

Payment pages, once paid plans launch, will be handled by Stripe and may involve Stripe's own strictly-necessary cookies for fraud prevention; we'll list them here when that happens.

3. Managing cookies

Your analytics choice can be changed right here, any time — withdrawing is as easy as agreeing was:

Analytics on this website:

Declining takes effect immediately: the analytics cookies are removed and nothing loads on your next page view.

Beyond that, your browser can block or delete cookies at any time (usually under Settings → Privacy). Two honest caveats: blocking the authentication cookies means you can't stay signed in, and deleting the preference cookies just resets choices like your theme. Preference cookies can also be changed from inside the product — your theme in Settings → Preferences, and trusted devices can be revoked in Settings → Security.

4. Questions

How cookie data fits into the bigger picture is covered in the Privacy Policy. Questions about this policy: [email protected].