Legal

Cookie Policy

Last updated: 3 September 2026

1. What are cookies and similar technologies

Cookies are small text files stored in your browser when you visit a website. They allow websites to remember your preferences, keep you signed in, and understand how their platform is used.

We also use similar browser storage technologies, principally localStorage, to remember your choices and hold some of your in-app progress on your device. Section 6 explains exactly what we keep there. Where this policy says “cookies” it means cookies and these similar technologies together.

2. Essential cookies

Essential cookies are always on. They are required for the platform to function and cannot be switched off without breaking the service. We do not need your consent for these, because the service cannot work without them.

sb-*-auth-token

Keeps you signed in to your Rich Girl Systems account. Set by Supabase, our authentication provider.

Expires: Session, or until you sign out

rgs-session-only

Records that you unticked “Keep me signed in”, so your sign-in is dropped when you close the browser instead of being remembered. Only set if you untick that box.

Expires: Session

rgs_signup_consent

Carries your acceptance of our terms across the redirect to Google or Apple when you sign up with them, so we can record that you agreed. Read once when your account is created, then discarded.

Expires: 10 minutes

<provider>_oauth_nonce, <provider>_code_verifier, tiktok_oauth_state

One-time security tokens that protect a connection you are setting up from being hijacked (CSRF and PKCE). One is set only at the moment you start connecting that particular service, and it is discarded as soon as the connection completes. The providers are Google, Google Ads, Google Business, YouTube, Microsoft, Instagram, Meta Ads, TikTok, TikTok Ads, TikTok Shop, Pinterest, Pinterest Ads, LinkedIn, Stripe, Etsy, Klaviyo, Calendly and Zoom.

Expires: 30 minutes

3. Functional cookies

These are not analytics and are never shared with ad networks. They remember one small thing each so the app does not repeat itself at you.

rgs_upgrade_moment

Holds today’s date once you have been shown the upgrade prompt, so you are shown it at most once a day rather than on every page. Only set if you are signed in and not already a member.

Expires: 1 day

4. Referral cookies

If you arrive through another founder’s referral link, we set one cookie so that when you create an account we can credit the founder who sent you. It records the referral code from the link and nothing about you. It is read once at signup and deleted at that point, and it is never shared with advertising platforms.

rgs_ref

The referral code from the link you followed. Set only if the code belongs to a real founder, and only when you arrive on a /r/ referral link. Deleted the moment your account is created.

Expires: 30 days, or until you sign up

rgs_ref_signup

A short-lived flag set once your referral has been credited, so the app records the referral signup once and not repeatedly. Cleared by the app immediately after.

Expires: Minutes

If you would rather not be attributed to a referrer, go to richgirlsystems.com directly rather than through a referral link, or clear your browser’s cookies for our site before signing up.

5. Analytics cookies

Off until you accept

Analytics cookies are not set until you choose “Accept all” on our cookie banner. If you choose “Essential only”, or have not yet chosen, no analytics cookies or analytics storage are used.

When you accept, we use product analytics to understand, in aggregate, which features founders use and where the platform can improve. We do not use them for advertising.

ph_* (PostHog)

Product analytics: anonymous-by-default usage events such as page views and feature interactions, so we can see what is working. Routed through our own domain. Provided by PostHog, processed in the United States. Once you are signed in, events are linked to your account ID and email so we can measure your journey; this stops the moment you decline or sign out.

Expires: Up to 12 months

_ga / _ga_* (Google Analytics)

Web analytics about page views, session duration, and navigation. Loaded with Google Consent Mode in cookieless mode by default and only writes cookies after you accept. Active only if a Google Analytics measurement ID is configured for the site.

Expires: Up to 24 months

You can withdraw analytics consent at any time. Use the Cookie settings button below (also in Settings → Privacy & Legal) to re-open the banner and switch to “Essential only”. Withdrawing is as easy as accepting, and takes effect immediately.

6. Other browser storage we use

Alongside cookies, we store a small amount of data in your browser’s localStorage on your own device. This is not transmitted to ad networks. It includes:

  • Your cookie choice - so we do not ask you again on every visit (rgs_cookie_consent).
  • App preferences and progress - things like your earned badges, streaks, saved goals, display preferences and a local copy of your programme schedule and tasks, so the app loads quickly and works smoothly. Your authoritative account data is stored in your account, not only on the device.
  • Things you have written in the app - your notes, your brand kit, and your Boardroom conversations and their outcomes are kept on your device so they are there when you come back. This is content you typed, held locally on your own machine.
  • Analytics state - only if you have accepted analytics (see Section 5).

Clearing your browser’s site data removes this local storage. Doing so signs you out and resets locally-cached preferences, but does not delete the data held in your account.

We also use an error-reporting service (Sentry) so we can find and fix problems in the app. It runs without cookies and without browser storage of its own: when an error occurs it sends a technical report of what went wrong, as described in our privacy policy. Because it stores nothing in your browser and is not used for analytics or advertising, it is not part of the cookie consent choice.

7. No advertising cookies

We do not use advertising cookies, retargeting cookies, or any cookies associated with ad networks. We do not share your data with advertising platforms.

8. Your choices and how to manage cookies

When you first visit, our cookie banner gives you a genuine choice: Accept all (essential plus analytics) or Essential only. No analytics cookies are set before you choose, and choosing “Essential only” keeps analytics off.

You can re-open this choice and change or withdraw your consent at any time using the button below, or from Settings → Privacy & Legal:

You can also control cookies through your browser settings. Most browsers allow you to block cookies, delete existing cookies, or alert you before cookies are stored. Note that blocking essential cookies will prevent you from signing in and using the platform.

Browser cookie settings:

  • Chrome: support.google.com/chrome/answer/95647
  • Firefox: support.mozilla.org/kb/enable-and-disable-cookies-website-preferences
  • Safari: support.apple.com/guide/safari/manage-cookies-sfri11471
  • Edge: support.microsoft.com/en-us/microsoft-edge/delete-cookies-in-microsoft-edge

9. Changes to this policy

We will update this policy and notify you before enabling any new category of cookies. Continued use of the platform after an update means you accept the revised policy.

Questions? Email info@richgirlsystems.com.