Cookie Policy
Effective 2 September 2026 · Auric 1.3.0-beta.1
In plain English: Auric uses very few cookies. The marketing site runs cookieless analytics, and we use no advertising or cross-site tracking cookies. If we ever enable a product-analytics tool that sets cookies, we will ask for consent first.
1. Purpose and Scope
This Policy explains every cookie and every piece of browser storage used across auric.cx and the Services, by name. It complements the Cookies and Telemetry section of the Privacy Policy. Capitalized terms follow Auric's Master Definitions in the Terms of Service.
2. Why Minimal
Auric's analytics layer (Vercel Web Analytics and Speed Insights) is cookieless by design. Authentication for the CLI is token-based, not cookie-based. The only routine cookie is a strictly-necessary admin-session cookie (internal), plus a possible Cloudflare Turnstile challenge token for bot protection.
3. Categories in Use
| Category | Example | Purpose | Consent |
|---|---|---|---|
| Strictly necessary | Admin session; Turnstile token | Security, sign-in, bot defense | Not required |
| Analytics (cookieless) | Vercel Analytics / Speed Insights | Aggregate usage and performance | Not cookie-based |
| Product analytics | PostHog — integrated but not enabled | Funnel analysis | Would require consent before being turned on |
| Advertising | None | — | Not applicable |
4. Local storage
Cookies are not the whole story, and a cookie policy that stops at cookies is being economical with it. The website keeps three small values in your browser's local storage. They are named here because "non-tracking state" was too vague a description of one of them.
| Key | What it holds | Why |
|---|---|---|
| auric_waitlist_email | The email address you typed into the waitlist form | So the form remembers you already joined and does not ask twice |
| auric_utm | The campaign parameters in the link you arrived on | So we can tell which posts and links bring people here, even if you visit another page before signing up |
| auric_ref | A referral code, if you followed someone's invite link | So the person who referred you is credited when you join |
All three are first-party: they are readable only by auric.cx, they are never sent to an advertising network, and they carry no identifier that could follow you to another site. The last two are attribution rather than preference, which is why they are listed individually rather than folded into a sentence about interface state.
You can clear all of them at any time through your browser, and the site works normally without them.
5. Managing Cookies
You can control cookies through your browser settings, and clear local storage the same way; blocking the strictly-necessary cookie will break administrator sign-in. If we ever enable a non-essential cookie, we will ask for consent before it is set and update this Policy first.
6. Changes and Contact
If these terms change materially we will update the effective date on this page and, where the change affects you meaningfully, tell you by email before it takes effect. Contact: privacy@auric.cx.
Document control
| Field | Value |
|---|---|
| Document ID | AUR-LEG-003 |
| Applies to | Auric 1.3.0-beta.1 — private beta |
| Status | Published — private beta |
| Owner | Auric |
| Review frequency | Quarterly during beta, or on material change |
| Related documents | Privacy (002), Terms (001) |
| Applies to | Auric 1.3.0-beta.1 — private beta |
Change log
2 September 2026: The beta is described as private throughout, which is how access is actually granted — requested, confirmed, then opened in waves. No right, obligation, party or data practice changed.
1.3.0-beta.1 (2026-08-02): Published for the private beta. Review markers resolved against the implementation, unsupported AI-provider claims removed, and retention stated from the constants that enforce it.
© 2026 Auric. All rights reserved.