> ## Documentation Index
> Fetch the complete documentation index at: https://docs.setor.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Setor AI Cookie Policy — Categories, Consent and Controls

> How Setor AI uses strictly necessary, analytics, and marketing cookies on setor.ai and app.setor.ai. Manage or withdraw your consent at any time.

Setor AI uses cookies and similar tracking technologies on its website (setor.ai) and application (app.setor.ai). This page explains what they are, what they do, how the legal bases differ between categories, and how you control them. No non-essential cookie or tracking script loads until you provide prior, active, granular consent — there are no pre-ticked boxes.

<Note>
  Cookie consent on **setor.ai** and **app.setor.ai** are managed separately. Full details on how personal data collected via cookies is processed are in the [Privacy Policy](/legal/privacy-policy).
</Note>

## Cookie Categories

<Tabs>
  <Tab title="Strictly Necessary">
    These cookies are required for the website and app to function. They manage your authenticated session, protect against CSRF attacks, remember your login state, and store your cookie consent preferences. No consent is required for these cookies — and they cannot be disabled.

    | Cookie name      | Provider | Purpose                                             | Duration |
    | ---------------- | -------- | --------------------------------------------------- | -------- |
    | `__session`      | Setor AI | Maintains your authenticated session                | Session  |
    | `csrf_token`     | Setor AI | Protects against cross-site request forgery attacks | Session  |
    | `cookie_consent` | Setor AI | Stores your consent preferences                     | 1 year   |

    **Legal basis:** GDPR Article 6(1)(b) (contract performance) and Article 6(1)(f) (legitimate interest — security). No consent is required under EU Directive 2002/58/EC Article 5(3) because these cookies are strictly necessary for the service you have requested.

    <Tip>
      You can still use all public content on setor.ai and full functionality on app.setor.ai if you reject all non-essential cookies. Setor AI does not operate a cookie wall.
    </Tip>
  </Tab>

  <Tab title="Analytics">
    Analytics and session recording cookies help us understand how visitors use the site — which features are used, where navigation is unclear, and where errors occur. These cookies **require your prior active consent** and are not loaded until you accept them.

    | Cookie / tool     | Provider                 | Purpose                                                              | Duration        |
    | ----------------- | ------------------------ | -------------------------------------------------------------------- | --------------- |
    | `ph_*`            | PostHog (EU — Frankfurt) | Page views, clicks, feature usage, error tracking                    | Up to 12 months |
    | Session recording | Microsoft Clarity        | Replays cursor movement, scrolling, and clicks to identify UX issues | Session         |

    **PostHog:** Data is stored in the EU (Frankfurt); not shared with third parties for advertising; not used for PostHog's own advertising. See [posthog.com/privacy](https://posthog.com/privacy).

    **Microsoft Clarity:** Setor AI has configured Clarity to **mask all text input fields** — no form content, passwords, or personal text entered into fields is ever captured in a session recording.

    **Legal basis:** Consent (EU Directive 2002/58/EC Article 5(3); Polish Electronic Communications Act Article 399; GDPR Article 6(1)(a)).

    **Retention:** Up to 36 months, then deletion or anonymisation. Withdrawing consent stops all future recording immediately.
  </Tab>

  <Tab title="Marketing">
    Marketing cookies measure advertising campaign effectiveness and enable conversion attribution. These cookies **require your prior active consent** and are not loaded until you accept them.

    | Cookie name       | Provider                   | Purpose                                                           | Duration |
    | ----------------- | -------------------------- | ----------------------------------------------------------------- | -------- |
    | `_fbp`            | Meta Platforms, Inc. (USA) | Browser identification for ad measurement and conversion tracking | 90 days  |
    | `_fbc`            | Meta Platforms, Inc. (USA) | Stores the click identifier (`fbclid`) for attribution            | 90 days  |
    | `setor_marketing` | Setor AI                   | Records UTM campaign parameters at first visit                    | 30 days  |

    By consenting to marketing cookies, you enable Meta to link activity on setor.ai with activity on other Meta Pixel sites and your Meta account for personalised ads. Setor AI does not access your Meta advertising profile — we receive only aggregated campaign results.

    **Hashed identifiers:** When Setor AI transmits conversion data via the Meta Conversions API, it uses SHA-256 hashed identifiers (email, phone, first name, last name, external ID). **Raw IP addresses are never stored in analytics systems.** An `ip_hash` pseudonym may be used to link events across devices — it is never used as a standalone identity key.

    **Legal basis:** Consent (EU Directive 2002/58/EC Article 5(3); Polish Electronic Communications Act Article 399; GDPR Article 6(1)(a)). Consistent with CJEU C-252/21 (Meta Platforms v. Bundeskartellamt), marketing and ad-tech processing is based solely on consent — not legitimate interest.

    **US transfers:** Covered by the EU-US Data Privacy Framework (DPF) with SCC (2021/914) as automatic fallback. You can manage Meta ad preferences at [facebook.com/adpreferences](https://www.facebook.com/adpreferences).
  </Tab>
</Tabs>

***

## Managing Consent

When you first visit setor.ai or app.setor.ai, a consent banner appears for all non-essential cookie categories.

<Steps>
  <Step title="See the banner">
    On your first visit, a consent banner is displayed before any non-essential scripts load. The banner offers **Accept all**, **Reject all**, and **Manage preferences** options with equal visual prominence — no dark patterns, no hidden rejection buttons.
  </Step>

  <Step title="Make granular choices">
    Select **Manage preferences** to accept or reject each category (Analytics, Marketing) independently. No categories are pre-selected. Your consent must be active and deliberate per CJEU C-673/17 (Planet49).
  </Step>

  <Step title="Change your mind anytime">
    Click **Cookie Settings** in the website footer at any time to review and update your consent choices. Changes take effect immediately — withdrawing consent stops non-essential tracking instantly.
  </Step>
</Steps>

<Info>
  Most browsers also allow you to manage cookies directly. To clear or block cookies in your browser:

  * **Chrome:** Settings → Privacy and Security → Cookies and Site Data
  * **Firefox:** Settings → Privacy & Security → Cookies and Site Data
  * **Safari:** Settings → Privacy → Manage Site Data
  * **Edge:** Settings → Cookies and Site Permissions → Manage Cookies and Site Data

  Blocking strictly necessary cookies will impair login and session functionality. Blocking non-essential cookies has no effect on your access to website content or app functionality.
</Info>

***

## Third-Party Cookies

Some cookies listed in the Marketing tab are set or read by Meta Platforms, Inc. (USA) when you consent to marketing tracking. These cookies operate under Meta's own data policies and retention schedules. Setor AI does not control how Meta uses data collected via Meta Pixel once it leaves our website.

PostHog cookies (`ph_*`) are **first-party cookies** — they are set by Setor AI and PostHog processes the data as a processor in the EU under a Data Processing Agreement. PostHog does not conduct cross-site tracking.

`setor_marketing` is a first-party cookie used only by Setor AI to record which marketing campaign brought you to the site.

***

## Consent Evidence and Record-Keeping

Setor AI records the following for each consent decision, per GDPR Articles 5(2) and 7(1):

* Timestamp (UTC) and categories accepted or rejected
* Policy version and consent mechanism version
* Browser user agent string

Consent decisions are logged server-side so evidence survives browser cookie deletion. Logs are retained for **36 months** from the consent date. Consent is re-requested when this policy is materially updated, when a consent record expires (one year from last decision), or when technical changes require fresh consent.

***

## Supervisory Authorities

GDPR oversight is provided by the **President of the Polish Data Protection Office (UODO)**, ul. Stawki 2, 00-193 Warsaw — [uodo.gov.pl](https://uodo.gov.pl). Cookie and electronic communications law oversight is provided by the **President of the Office of Electronic Communications (UKE)**. You may file a complaint with either authority; we encourage you to contact us first at [office@setor.ai](mailto:office@setor.ai) so we can address concerns directly.
