Cookies policy
Version 1.0 · In force from 2026-08-13
Please read this cookie policy carefully as it contains important information on who we are and how we use cookies on our Services. This policy should be read together with our Privacy Policy which set out who we are, how to contact us, what data is collected, how and why we collect, store, use and share personal information generally, as well as your rights in relation to your personal information and details of how to contact us and supervisory authorities if you have a complaint.
1. Cookies
A cookie is a small text file which is placed onto your device (e.g. your smartphone or other electronic device) when you use our Services. We use only cookies that are essential to provide the Services you have asked for, so you will not see a cookie consent pop-up. If we ever introduce a cookie that is not essential, we will ask for your consent before placing it.
Cookies help us to recognise your device between one request and the next. We use two, and both are listed in full below: one keeps you signed in, and one remembers whether you asked for the light or the dark appearance. We do not use cookies to collect location data, to build a profile of you, or to follow you across other websites.
We do measure how our Services are used — how many pages are viewed, and which parts of the product people reach — but that measurement does not use cookies. The addresses of pages inside the application are stripped of anything identifying before they leave your browser, and what we see is aggregated, so it does not identify you individually. Our Privacy Policy explains this in more detail.
For further information on our use of cookies, including exactly what each one holds and how long it lasts, please see the table below.
For further information on cookies generally, including how to control and manage them, visit the guidance on cookies published by the UK Information Commissioner's Office, www.aboutcookies.org or www.allaboutcookies.org.
2. Consent to use cookies
We will ask for your consent to place cookies or other similar technologies on your device, except where they are essential for us to provide you with a service that you have requested (e.g. to allow you to remain logged-in to the Services as you navigate within the Services and use the Services functionalities).
Both of the cookies we currently use are essential in that sense, so we do not ask for your consent and you will not see a consent banner. The table below explains each one, what it holds, how long it lasts and why it is essential.
3. Our use of cookies
The table below provides more information about the cookies we use and why:
| The cookies we use | Name | Purpose | Whether cookie is essential for us to provide you with a service that you have requested and whether we will seek your consent before we place the cookie |
|---|---|---|---|
| Strictly necessary cookie, first party - set by ImproveDesk (ITSM Ltd) through our authentication provider, Supabase. It is written by our own servers on our own domain; Supabase does not set it from theirs. | sb-<project-ref>-auth-token, where <project-ref> is our Supabase project reference. When the value is larger than 3,180 bytes the browser receives it split across numbered continuations named sb-<project-ref>-auth-token.0, sb-<project-ref>-auth-token.1, and so on. | This cookie is what keeps you signed in. Without it every page you opened would ask you to sign in again, and the service could not tell your organisation's data from anyone else's. It holds your Supabase session - an encoded access token and refresh token - and so contains personal information: your user ID, the email address you signed in with, and technical details of the session such as when it was issued and when it expires. It contains nothing from your register, reviews or corrective actions. It is set when you sign in, refreshed by our servers as you navigate so the session does not lapse mid-task, and deleted when you sign out. Its maximum lifetime in the browser is 400 days, which is the longest any cookie may live under current browser rules; the session inside it expires and is rotated far sooner. | Yes. Essential - you cannot have a signed-in account without it. We will therefore not request your consent before placing this cookie. |
| Preference (customisation) cookie, first party - set by ImproveDesk (ITSM Ltd). No third party is involved and its contents never leave our servers. | id_theme | Remembers whether you asked for the light appearance, the dark appearance, or to follow your device's setting, so the site looks the way you chose on your next visit. It holds one word - system, light or dark. It collects no personal information, no identifier, and nothing that could be used to recognise you. It is only written when you actively use the appearance control. If you never touch it, this cookie is never created. It remains for one year from the moment you make a choice, and you can remove it at any time through your browser's settings without losing anything else. | Yes. Essential to deliver the appearance you explicitly asked for; it is created only by your own action and only stores that action. We will therefore not request your consent before placing this cookie. |
4. Third party services that do not set cookies
Two third party services run on our Services and are worth naming here, because visitors reasonably expect them to set cookies and neither does.
Cloudflare Turnstile protects our sign-up, password reset and public capture forms from automated abuse. The check runs a script loaded from challenges.cloudflare.com, but it places no cookie on our Services. Turnstile issues a cookie (cf_clearance) only where a site turns on its optional "pre-clearance" feature, which we have not: our widget is configured with no pre-clearance. Cloudflare processes some technical information about your browser to decide whether you are a human, which it describes in its Turnstile Privacy Addendum.
Vercel hosts our Services and provides the usage measurement described above. Its Web Analytics does not use cookies: rather than storing an identifier on your device, it derives a hash from the incoming request, and that is discarded after 24 hours, so there is nothing that persists on your device and nothing that follows you to another website. Vercel's own description is in its analytics privacy documentation and its Privacy Policy.
Neither service places a cookie on your device through our Services, so neither appears in the table above and neither requires your consent.
5. How to turn off all cookies and consequences of doing so
If you do not want to accept any cookies, you may be able to change your device settings so that cookies (including those which are essential to the services requested) are not accepted. If you do this, please be aware that you may lose some of the functionality of our Services and of other Services you use on your device. For further information about cookies and how to disable them please go to the guidance on cookies published by the UK Information Commissioner's Office, www.aboutcookies.org or www.allaboutcookies.org.
6. Changes to this policy
This policy was published on 13th August 2026 and last updated on 13th August 2026. We may change this cookies policy from time to time, when we do we will inform you via the Services or by sending an email to the email address you provided when you signed up to the Services.