Cookie Policy

Effective: 8 August 2026 · Version 1.2

This Cookie Policy explains what Aeloria stores on your device when you visit aeloria.ai or use the Aeloria application, and why. It sits alongside our Privacy Policy, which describes how we handle personal data more generally.

The short version. Aeloria uses no tracking cookies, no advertising cookies, and no third-party profiling. Our website analytics provider does not use cookies at all. The only things we store are what is needed to keep you logged in, keep that session secure, and record which language the interface is in. You will not see a cookie banner on aeloria.ai — not as a design choice, but because none of that storage is what consent exists to protect you from: it is either strictly necessary to run the Service, or a bare language code carrying no identifier. Sections 2.1 and 2.2 set out the basis for each.

1. What a cookie is

A cookie is a small text file a website asks your browser to store and send back on later visits. Related technologies — localStorage, sessionStorage and similar browser storage — work differently but serve comparable purposes, and this Policy covers them too.

2. What we use

2.1 Strictly necessary cookies

These are required for the Service to work. They are first-party (set by Aeloria, not by anyone else), and they cannot be switched off without breaking sign-in.

NamePurposeTypeRetention
Session cookieKeeps you signed in as you move between pages of the applicationFirst-party, HTTP-only, Secure, SameSiteCleared when the session ends or expires
CSRF tokenProtects forms and requests against cross-site request forgeryFirst-party, Secure, SameSiteSession

Under Article 5(3) of the EU ePrivacy Directive and Article 45c of the Swiss Telecommunications Act, storage that is strictly necessary to provide a service the user has requested does not require consent. That is the basis on which these are set.

2.2 Functional cookies

NamePurposeTypeRetention
preferred_langRemembers the interface language you selected, so you are not returned to English on your next visitFirst-party, readable by JavaScript, Secure over HTTPS, SameSite=Lax12 months
PARAGLIDE_LOCALESet by the translation library the site is built on, recording the language a page is being displayed inFirst-party, readable by JavaScript, no Secure or SameSite attribute set400 days

Both cookies store a language code and nothing else. Neither contains an identifier. preferred_lang is written only if you actively choose a language; PARAGLIDE_LOCALE is written by the interface itself when a page loads.

Why these are set without asking you. Choosing a language from the switcher is a request for the site to remember that choice, so preferred_lang falls within the same Article 5(3) exemption as the cookies in 2.1. PARAGLIDE_LOCALE is different: nothing you did triggers it, so we do not rest on that argument. We consider it exempt on the narrower ground that it records only the language the page is already being displayed in — a value also present in the address bar — with no identifier, no way to tell one visitor from another, and no readability by any site but this one. If that reading were ever challenged, our answer would be to stop setting the cookie rather than to put a banner in front of it.

2.3 Analytics — without cookies

We measure aggregate website traffic with Umami, configured to run without cookies. It records page-level counts (pages viewed, referring source, approximate country, browser and device type) in aggregate form. It does not set a cookie, does not assign a persistent identifier, does not follow you between sites, and does not build a profile. We cannot identify an individual visitor from it. Umami's measurement script is loaded from Umami's own servers, and it is the only third-party script aeloria.ai loads.

2.4 What we do not use

We do not sell or share personal data for advertising purposes, and there is no advertising infrastructure on aeloria.ai for us to do it with.

3. Controlling what is stored

For the reasons set out in sections 2.1 and 2.2, we do not ask for consent to any of this storage, so there is nothing here to accept or reject. You remain in full control regardless:

4. Changes

If we ever introduce storage that requires consent, we will ask for it before setting it, publish an updated version of this Policy, and change the version date at the top. The Service's design intention is to keep that from becoming necessary.

Version history. Version 1.2 (8 August 2026): published as a standalone document aligned with Privacy Policy v1.2 — the cookie inventory now matches the Service as built (two strictly necessary cookies plus the language cookies preferred_lang and PARAGLIDE_LOCALE), the cookieless nature of the analytics provider is stated explicitly, and the basis for setting each category without consent is given per category rather than asserted once — including the fact that PARAGLIDE_LOCALE is written automatically rather than on a choice you make.

5. Contact

Questions about this Policy, or about anything stored on your device by Aeloria, can be sent to privacy@aeloria.ai.

Aeloria · Im Lindengut 15 · 8803 Rüschlikon · Switzerland · privacy@aeloria.ai · aeloria.ai
Aeloria is a business name of Matteo Panzavolta, sole proprietor, registered in Rüschlikon, Switzerland.