COOKIE POLICY

Last Updated: July 2026

1. Introduction and Scope

This Cookie Policy governs the collection, storage, and use of cookies and analogous browser-side storage mechanisms by the Leanvera platform and its associated web properties (collectively, the "Platform"). This Policy is designed to satisfy the disclosure requirements of the European Union General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), and applicable international data privacy frameworks including but not limited to the UK GDPR, Canada's PIPEDA, and Australia's Privacy Act 1988.

By accessing the Platform, users acknowledge and agree to the use of cookies as described in this Policy. Where applicable law requires affirmative consent prior to the deployment of non-essential cookies, such consent will be obtained through Leanvera's consent management interface before any non-essential cookie processing commences.

2. What Cookies Are

Cookies are small text files placed on a user's device by a web server when the user visits a website or web application. Cookies serve a range of technical and operational functions, including maintaining session state, storing user preferences, and enabling platform performance diagnostics. Leanvera uses both session cookies (which expire when the browser is closed) and persistent cookies (which remain on the device until their defined expiry date or until manually cleared by the user). In addition to traditional cookies, the Platform may use analogous local storage mechanisms (including browser localStorage and sessionStorage) for equivalent functional purposes. All references to "cookies" in this Policy encompass these analogous storage mechanisms unless stated otherwise.

3. Cookie Categories

Leanvera operates a three-category cookie framework aligned with standard international classification conventions. Each category is described below with full transparency regarding its purpose, storage duration, and the data it processes.

3.1 Essential and Functional Cookies


Essential and Functional Cookies are strictly necessary for the Platform to operate correctly. These cookies cannot be disabled without materially impairing or entirely preventing access to core Platform functionality. No user consent is required for the deployment of Essential and Functional Cookies under applicable legal frameworks, as their use is justified under the "strictly necessary" exemption recognised by the GDPR, UK ICO guidance, and equivalent international standards.


Essential and Functional Cookies deployed by Leanvera serve the following operational purposes:

●       Secure User Authentication Tokens: Leanvera issues cryptographically signed session tokens upon successful user login. These tokens are stored in secure, HttpOnly, SameSite
restricted cookies and are used exclusively to authenticate the user's session for the duration of their Platform access. These tokens are not accessible to client-side JavaScript and
are invalidated upon logout or session expiry.

●       Active Client Workspace Session State: The Platform maintains isolated session state data for each Active Client Workspace accessed during a user session. Functional cookies
store the identifier of the currently active workspace to ensure that all generation requests, Brand Voice Profile retrievals, and strategic output queries are correctly scoped to the
user's current workspace context. This mechanism is architecturally essential to Leanvera's zero cross-contamination data isolation guarantee.

●     Whop Checkout and Access Management: Leanvera's subscription billing, digital checkout, and user access authentication flows are powered by Whop (whop.com). During an
active user checkout or dashboard access loop, Whop deploys its own technically necessary cookies to manage your secure payment state, verify active subscription membership,
prevent duplicate transactions, and maintain checkout security. These cookies operate under Whop's own independent platform policies. Leanvera does not store or process the
contents of these processing cookies.

●       CSRF Protection Tokens: Cross-Site Request Forgery protection tokens are stored in session-scoped cookies to validate that form submissions and API requests originate from
authenticated Leanvera sessions. These cookies contain no personally identifiable information.

●       Consent State Record: A cookie is stored to record the user's cookie consent preferences as expressed through Leanvera's consent management interface, to prevent repeated
display of the consent prompt during the same or subsequent sessions.

3.2 Performance and Analytics Cookies


Performance and Analytics Cookies collect aggregated, non-personally-identifiable data about how users interact with the Platform. This data is used exclusively for internal operational purposes: diagnosing technical performance issues, measuring interface load times, and identifying navigation patterns that inform platform stability improvements. Leanvera does not share performance analytics data with third-party advertising networks or data brokers. Where applicable law requires prior consent for analytics cookies, they are not activated until the user has provided affirmative consent through the consent management interface.


Performance and Analytics Cookies deployed by Leanvera serve the following purposes:

●       Platform Stability Monitoring: Aggregated error rate data, API response time metrics, and interface rendering performance statistics are collected to support platform reliability
operations. This data is processed at an aggregate level and does not include user identity information.

●       Load Time and Infrastructure Diagnostics: Page and component load time measurements are collected to support capacity planning and performance optimisation. Individual user
sessions contributing to these metrics are anonymised before storage.

●       Interface Navigation Metrics: Aggregated interaction patterns — including which Platform sections are accessed most frequently and at what points in a session users transition
between modules — are collected to inform user experience improvements. This data is not used to build individual user profiles and is not linked to personally identifiable account
data.

3.3 Preference Cookies


Preference Cookies store non-sensitive interface configuration choices made by the user during their session or across sessions. These cookies enhance the user's experience by preserving interface settings that would otherwise reset on each visit. Preference Cookies do not collect personally identifiable information and do not transmit data to third parties.


Preference Cookies deployed by Leanvera serve the following purposes:

●       Dashboard Layout Preferences: Users may customise the layout of their Agency Dashboard, including the arrangement of client workspace panels, the visibility of specific interface
modules, and column display settings in the hypothesis and blueprint views. These preferences are stored in a persistent preference cookie to maintain the user's chosen layout
across sessions.

●       Dark Mode Interface Setting: Leanvera's Platform offers a custom dark mode interface. The user's selected display mode preference is stored in a persistent preference cookie so
that the user's chosen visual configuration is applied automatically on subsequent visits without requiring manual reselection.

●       Regional and Language Preferences: Where applicable, any user-configured regional display preferences (such as date format or currency display settings relevant to billing
overviews) are retained in preference cookies for the duration of the user's subscription.

4. No Third-Party Behavioral Advertising or Retargeting Cookies

Leanvera operates entirely clear of third-party behavioral advertising and retargeting cookie arrays. The Platform does not deploy, permit, or integrate any cookies or tracking technologies from advertising networks, demand-side platforms, data management platforms, or social media advertising pixels (including but not limited to Meta Pixel, TikTok Pixel, Google Ads remarketing tags, LinkedIn Insight Tags, or equivalent third-party advertising trackers) on any page or interface within the authenticated Platform environment. Leanvera does not sell, license, or share cookie-derived user data with any third-party entity for advertising, audience segmentation, or behavioural profiling purposes. This commitment applies to all users of the Platform regardless of their jurisdiction

5. Cookie Retention Periods

Cookies deployed by Leanvera are retained for the following maximum periods, after which they expire automatically:

●       Essential Authentication Tokens: Session-duration only. Tokens are invalidated on logout or browser session closure.

●       Workspace Session State Cookies: Session-duration only.

●       Whop Checkout and Access Cookies: Storage duration is governed directly by Whop's infrastructure frameworks, operating as session-scoped files or persistent identifiers for
security, seat authentication, and fraud prevention compliance.

●       Performance and Analytics Cookies: Up to 12 months from the date of collection, with anonymisation applied within 30 days.

●       Preference Cookies: Up to 12 months from the date of last user login, refreshed on each authenticated session.

●       Consent State Cookie: Up to 12 months from the date the consent was recorded, after which consent is re-requested.

6. Managing and Withdrawing Cookie Consent

Users subject to jurisdictions requiring opt-in consent for non-essential cookies (including all EU, EEA, and UK users) will be presented with a consent management interface upon their first visit to the Platform and upon any material update to this Cookie Policy. Users may withdraw or modify their consent at any time by accessing the Cookie Preferences panel within the Platform settings menu. Withdrawal of consent for Performance and Analytics Cookies or Preference Cookies will take effect prospectively and will not affect any processing that has already occurred on the basis of prior consent. Withdrawal of consent for Essential and Functional Cookies is not operationally possible, as these cookies are required for the Platform to function. Users may also manage cookies directly through their browser settings. Standard browser controls allow users to view, delete, and block cookies on a per-site basis. Blocking Essential Cookies through browser settings will impair or prevent Platform access.

7. Updates to This Policy

Leanvera reserves the right to update this Cookie Policy at any time to reflect changes in Platform functionality, applicable law, or operational cookie use. Material updates will be communicated to registered users via in-Platform notification or email. The revised Policy will take effect from the date displayed in the Last Updated field at the top of this document.

8. Contact

For questions or formal requests regarding this Cookie Policy, contact our team at: support@leanvera.com