Legal

Tresor AI - Cookie Notice

Effective date: 22 June 2026

Last updated: 22 June 2026

This Cookie Notice explains how Tresor S.A. ("Tresor", "we", "us") uses cookies and similar technologies on our website (tresor.co) and in the Tresor Workspace. It should be read together with our Privacy Policy , which explains how we handle personal data more generally.

In keeping with our zero-access design, we keep tracking to a minimum: until you give consent, we do not set analytics or marketing cookies.

1. What cookies and similar technologies are

Cookies are small text files placed on your device when you visit a website. We also use comparable browser technologies such as localStorage, which stores information in your browser rather than in a cookie. In this Notice, "cookies" refers to both unless stated otherwise.

Cookies can be:

  • First-party (set by Tresor) or third-party (set by a provider we use).
  • Session cookies, which are deleted when you close your browser, or persistent cookies, which remain for a set period.

2. Our consent model

Our website is designed to run cookieless until you give consent. This means:

  • Before you choose: only strictly necessary cookies are active. No analytics or marketing cookies are set.
  • If you accept: we enable the analytics cookies described below. You can withdraw consent at any time.
  • If you decline: no analytics or marketing cookies are set.

Strictly necessary cookies do not require consent, because they are essential to provide a service you have requested (for example, keeping you signed in). All other cookies are used only on the basis of your consent (Art. 6(1)(a) GDPR), which you give, refuse, or withdraw via our cookie banner or your browser settings.

3. Strictly necessary cookies

These are required for the website and Workspace to function and cannot be switched off through our banner.

sb-<project>-auth-token (set in several parts)

Provider
Tresor (via Supabase)
Purpose
Keeps you securely signed in to the Workspace and stores your authenticated session
Type
Cookie
Duration
Session / refresh-token lifetime

tresor-active-tenant

Provider
Tresor
Purpose
Remembers which workspace (tenant) is currently active
Type
Cookie
Duration
Functional; persists across sessions

tresor_locale

Provider
Tresor
Purpose
Remembers your language preference
Type
Cookie
Duration
Functional; persists across sessions

llm-mode

Provider
Tresor
Purpose
Remembers your selected response mode (for example, instant / thinking)
Type
Cookie / localStorage
Duration
Functional

llm-model

Provider
Tresor
Purpose
Remembers your selected AI model
Type
Cookie / localStorage
Duration
Functional

dashboard-sidebar-chat

Provider
Tresor
Purpose
Remembers your sidebar layout / state
Type
Cookie / localStorage
Duration
Functional

ph_current_instance, ph_current_project_name, ph_current_project_token, ph_last_login_method

Provider
Tresor
Purpose
Remember your current project / instance and last login method so the app loads the right context
Type
localStorage
Duration
Functional

Implementation note: confirm these keys are set by the app itself rather than by PostHog.

__vdpl

Provider
Vercel (hosting)
Purpose
Skew protection - pins your session to the app version (deployment) you loaded, so a new release while you are browsing does not break asset loading. Stores a deployment ID, not a user identifier; does not track you.
Type
Cookie
Duration
Functional; honored for Vercel's skew-protection window (default 1 day)

__stripe_mid, __stripe_sid

Provider
Stripe
Purpose
Fraud prevention during payment - identify the device and session to detect and block fraudulent transactions. Set only when you reach the signup / payment flow, not on the public website.
Type
Cookie
Duration
__stripe_mid: ~1 year; __stripe_sid: ~30 minutes

The consent preference itself is stored in localStorage under analytics-consent so we do not ask again on every visit.

4. Analytics cookies (consent required)

We use PostHog to understand how our website and product are used, so we can improve them. PostHog events are metadata-only and never contain the content of your prompts, documents, or conversations. These cookies are set only after you consent.

ph_<project_api_key>_posthog

Provider
PostHog
Purpose
Stores a randomly generated device / distinct identifier, session identifier, and feature-flag state to measure usage of the website and product
Type
Cookie (and equivalent data in localStorage)
Duration
365 days

More than one PostHog project may be active (for example, an additional PostHog instance is loaded by the embedded Productlane widget - see Section 7). If you decline, PostHog runs in a privacy-preserving mode that does not store identifying data in your browser.

5. Marketing and advertising cookies

We do not use marketing or advertising cookies. If this changes in the future, we will update this Notice and request your consent before any such cookie is set.

6. How to manage or withdraw your consent

You can change your choices at any time:

  • Cookie banner / settings: reopen the cookie settings on our website to update or withdraw consent.
  • Browser settings: most browsers let you block or delete cookies and clear localStorage. Disabling strictly necessary cookies may stop parts of the Services from working.
  • PostHog opt-out: declining analytics in our banner opts you out of PostHog tracking.

Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.

7. Third-party providers

Where a third party sets cookies through our website, that provider also processes the resulting data under its own privacy terms:

  • PostHog - product and website analytics. See PostHog's privacy documentation at posthog.com/privacy .
  • Stripe - payment processing and fraud prevention, active only once you enter the signup / payment flow. See Stripe's cookie policy at stripe.com/legal/cookies-policy .
  • Productlane - an embedded customer-feedback / changelog widget.

A full list of the processors we work with is set out in Section 5 of our Privacy Policy .

8. Changes to this Notice

We may update this Notice when our use of cookies changes or when the law changes. We will update the "Last updated" date above and, for material changes, ask for renewed consent where required.

9. Contact

Tresor S.A.
c/o House of Startups, 9, rue du Laboratoire, L-1911 Luxembourg, Grand Duchy of Luxembourg
Privacy: privacy@tresor.co

You also have the right to lodge a complaint with the Commission nationale pour la protection des donnees (CNPD), 15, Boulevard du Jazz, L-4370 Belvaux, Luxembourg, cnpd.public.lu .