Legal
Tresor AI - Cookie Notice
Effective date: 22 June 2026
Last updated: 22 June 2026
This Cookie Notice explains how Tresor S.A. ("Tresor", "we", "us") uses cookies and similar technologies on our website (tresor.co) and in the Tresor Workspace. It should be read together with our Privacy Policy , which explains how we handle personal data more generally.
In keeping with our zero-access design, we keep tracking to a minimum: until you give consent, we do not set analytics or marketing cookies.
1. What cookies and similar technologies are
Cookies are small text files placed on your device when you visit a website. We also use comparable browser technologies such as localStorage, which stores information in your browser rather than in a cookie. In this Notice, "cookies" refers to both unless stated otherwise.
Cookies can be:
- First-party (set by Tresor) or third-party (set by a provider we use).
- Session cookies, which are deleted when you close your browser, or persistent cookies, which remain for a set period.
2. Our consent model
Our website is designed to run cookieless until you give consent. This means:
- Before you choose: only strictly necessary cookies are active. No analytics or marketing cookies are set.
- If you accept: we enable the analytics cookies described below. You can withdraw consent at any time.
- If you decline: no analytics or marketing cookies are set.
Strictly necessary cookies do not require consent, because they are essential to provide a service you have requested (for example, keeping you signed in). All other cookies are used only on the basis of your consent (Art. 6(1)(a) GDPR), which you give, refuse, or withdraw via our cookie banner or your browser settings.
3. Strictly necessary cookies
These are required for the website and Workspace to function and cannot be switched off through our banner.
sb-<project>-auth-token (set in several parts)
- Provider
- Tresor (via Supabase)
- Purpose
- Keeps you securely signed in to the Workspace and stores your authenticated session
- Type
- Cookie
- Duration
- Session / refresh-token lifetime
tresor-active-tenant
- Provider
- Tresor
- Purpose
- Remembers which workspace (tenant) is currently active
- Type
- Cookie
- Duration
- Functional; persists across sessions
tresor_locale
- Provider
- Tresor
- Purpose
- Remembers your language preference
- Type
- Cookie
- Duration
- Functional; persists across sessions
llm-mode
- Provider
- Tresor
- Purpose
- Remembers your selected response mode (for example, instant / thinking)
- Type
- Cookie / localStorage
- Duration
- Functional
llm-model
- Provider
- Tresor
- Purpose
- Remembers your selected AI model
- Type
- Cookie / localStorage
- Duration
- Functional
dashboard-sidebar-chat
- Provider
- Tresor
- Purpose
- Remembers your sidebar layout / state
- Type
- Cookie / localStorage
- Duration
- Functional
ph_current_instance, ph_current_project_name, ph_current_project_token, ph_last_login_method
- Provider
- Tresor
- Purpose
- Remember your current project / instance and last login method so the app loads the right context
- Type
- localStorage
- Duration
- Functional
Implementation note: confirm these keys are set by the app itself rather than by PostHog.
__vdpl
- Provider
- Vercel (hosting)
- Purpose
- Skew protection - pins your session to the app version (deployment) you loaded, so a new release while you are browsing does not break asset loading. Stores a deployment ID, not a user identifier; does not track you.
- Type
- Cookie
- Duration
- Functional; honored for Vercel's skew-protection window (default 1 day)
__stripe_mid, __stripe_sid
- Provider
- Stripe
- Purpose
- Fraud prevention during payment - identify the device and session to detect and block fraudulent transactions. Set only when you reach the signup / payment flow, not on the public website.
- Type
- Cookie
- Duration
- __stripe_mid: ~1 year; __stripe_sid: ~30 minutes
The consent preference itself is stored in localStorage under analytics-consent so we do not ask again on every visit.
4. Analytics cookies (consent required)
We use PostHog to understand how our website and product are used, so we can improve them. PostHog events are metadata-only and never contain the content of your prompts, documents, or conversations. These cookies are set only after you consent.
ph_<project_api_key>_posthog
- Provider
- PostHog
- Purpose
- Stores a randomly generated device / distinct identifier, session identifier, and feature-flag state to measure usage of the website and product
- Type
- Cookie (and equivalent data in localStorage)
- Duration
- 365 days
More than one PostHog project may be active (for example, an additional PostHog instance is loaded by the embedded Productlane widget - see Section 7). If you decline, PostHog runs in a privacy-preserving mode that does not store identifying data in your browser.
5. Marketing and advertising cookies
We do not use marketing or advertising cookies. If this changes in the future, we will update this Notice and request your consent before any such cookie is set.
6. How to manage or withdraw your consent
You can change your choices at any time:
- Cookie banner / settings: reopen the cookie settings on our website to update or withdraw consent.
- Browser settings: most browsers let you block or delete cookies and clear localStorage. Disabling strictly necessary cookies may stop parts of the Services from working.
- PostHog opt-out: declining analytics in our banner opts you out of PostHog tracking.
Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.
7. Third-party providers
Where a third party sets cookies through our website, that provider also processes the resulting data under its own privacy terms:
- PostHog - product and website analytics. See PostHog's privacy documentation at posthog.com/privacy .
- Stripe - payment processing and fraud prevention, active only once you enter the signup / payment flow. See Stripe's cookie policy at stripe.com/legal/cookies-policy .
- Productlane - an embedded customer-feedback / changelog widget.
A full list of the processors we work with is set out in Section 5 of our Privacy Policy .
8. Changes to this Notice
We may update this Notice when our use of cookies changes or when the law changes. We will update the "Last updated" date above and, for material changes, ask for renewed consent where required.
9. Contact
Tresor S.A.c/o House of Startups, 9, rue du Laboratoire, L-1911 Luxembourg, Grand Duchy of Luxembourg
Privacy: privacy@tresor.co
You also have the right to lodge a complaint with the Commission nationale pour la protection des donnees (CNPD), 15, Boulevard du Jazz, L-4370 Belvaux, Luxembourg, cnpd.public.lu .