Cookie Policy
Last updated: 17 June 2026
1. About this policy
This Cookie Policy explains how cookies and similar client-side storage technologies are used by AI Super Hub ("we", "us", "our"), a web application and installable Progressive Web App (PWA) available at https://aisuperhub.app.
AI Super Hub is operated by Koby Bryant, an individual operating as a sole trader trading as "AI Super Hub", based in Queensland, Australia. This policy relates to the single service we operate.
This Cookie Policy should be read together with our Privacy Policy. It uses the term "cookies" broadly to cover cookies and similar technologies such as browser localStorage and sessionStorage.
Where a business customer uses AI Super Hub to operate their own storefront tracking (for example, embedding our analytics snippet or chatbot widget on their own website), that business is the controller of the data collected from their visitors and we act as their processor. In that context, the business customer is responsible for obtaining any consent required from its own visitors. This policy describes the cookies and storage used by the AI Super Hub application itself.
2. What are cookies and similar technologies?
Cookies are small text files placed on your device by a website or web app. They allow the site to recognise your device, keep you signed in, remember your preferences, and operate securely.
Local storage and session storage are browser storage mechanisms that let the app store small amounts of data on your device. localStorage persists until cleared; sessionStorage is cleared when the browser tab is closed.
We use these technologies in three broad ways:
- Strictly necessary — required for the app to function and to keep your account secure (for example, authentication and anti-forgery protection). These cannot be switched off within the app.
- Functional / preference — remember choices you make (for example, your light/dark theme).
- First-party analytics — measure activity on storefronts and chatbot widgets that our business customers embed on their own sites.
3. Important: no third-party advertising or cross-site tracking
We want to be clear and honest about this:
- We do not use third-party advertising cookies.
- We do not use cross-site behavioural tracking or programmatic advertising pixels.
- We do not load Google Analytics, Facebook/Meta Pixel, Segment, Mixpanel, Amplitude, Hotjar, FullStory, DoubleClick, or similar third-party analytics or ad-tech trackers.
- We do not sell data to, or share it with, data brokers, demand-side platforms (DSPs) or data-management platforms (DMPs) for advertising purposes.
All cookies and storage used by AI Super Hub are first-party and fall into one of the following categories: strictly necessary (authentication, security), functional preference (theme/mode), or first-party analytics (storefront and chatbot widget measurement for our business customers). Data flows to our third-party processors (such as Supabase, Anthropic, OpenAI, PayPal and others) occur server-side via our own API keys, not through tracking cookies placed in your browser by those processors.
4. Cookies we use
4.1 Strictly necessary cookies (always active)
These cookies are essential for AI Super Hub to operate, to sign you in, and to protect against cross-site request forgery during third-party connection flows. They cannot be disabled through the app, and the service will not function correctly without them.
| Cookie | Purpose | Type | Duration |
|---|---|---|---|
sb-*-auth-token | Authentication session (set and managed by our authentication provider, Supabase) | First-party, HttpOnly, SameSite=Lax, Secure in production | Session + refresh token lifetime |
sb-*-auth-token-code-verifier | Secures the sign-in (PKCE) flow | First-party, HttpOnly, SameSite=Lax, Secure in production | Session |
shopify_oauth_state, shopify_oauth_shop | Anti-forgery (CSRF) protection when connecting a Shopify store | First-party, HttpOnly, SameSite=Lax, Secure in production | ~10 minutes; deleted on completion |
vm_yt_oauth_state | Anti-forgery (CSRF) protection when connecting a YouTube channel (Video Manager) | First-party, HttpOnly, SameSite=Lax, Secure in production | ~10 minutes; deleted on completion |
pos_oauth_state_xero, pos_oauth_state_myob | Anti-forgery (CSRF) protection when connecting Xero or MYOB accounting | First-party, HttpOnly, SameSite=Lax, Secure in production | ~10 minutes; deleted on completion |
The authentication cookies are set automatically by our authentication provider and are handled transparently by the app. The OAuth state cookies are short-lived and are automatically deleted once the relevant connection flow completes.
4.2 Functional / preference cookies (optional)
These cookies remember choices you make so the app behaves the way you expect. They are not essential, but disabling them will mean your preferences are not remembered between visits or devices.
| Cookie | Purpose | Type | Duration |
|---|---|---|---|
hub_theme | Remembers your light or dark theme choice (also used for server-side theme rendering) | First-party, not HttpOnly, SameSite=Lax | 1 year |
hub_mode | Remembers your "Personal" vs "Business" dashboard mode | First-party, not HttpOnly, SameSite=Lax | 1 year |
4.3 First-party analytics cookies (optional — used on embedded storefronts and widgets)
These cookies are not set on the main AI Super Hub dashboard. They are placed only when a business customer embeds our storefront tracking snippet or chatbot widget on their own website, to provide that business with first-party analytics about their visitors (for example, page views, product views, add-to-cart, search, checkout activity, and chatbot engagement). They use randomly generated identifiers and are not, by default, used to identify a person by name.
| Cookie | Purpose | Type | Duration |
|---|---|---|---|
_jvid | Storefront visitor identifier (first-party analytics) | First-party, not HttpOnly, SameSite=Lax | 1 year |
_jcv | Chatbot widget visitor identifier (first-party analytics) | First-party, not HttpOnly, SameSite=Lax | 1 year |
Where these analytics cookies are deployed on a business customer's website, that business customer is the controller of the resulting data and is responsible for obtaining any consent required from its own visitors. We act as their processor. The data collected is stored against that customer's account (in our customer_events records) and is subject to row-level access controls so a customer can only see their own data.
5. Local storage and session storage
In addition to cookies, AI Super Hub uses browser storage for a small number of non-essential, privacy-preserving purposes. None of these are used for advertising or cross-site tracking.
| Key | Storage | Purpose | Essential? |
|---|---|---|---|
pwa_install_dismissed | localStorage | Remembers you dismissed the "Install App" prompt (for ~24 hours) | Optional |
portal_install_dismissed | localStorage | Remembers you dismissed the Team Portal "Install App" prompt | Optional |
staff-app-push-dismissed | sessionStorage | Remembers you dismissed the push-notification prompt for the current session | Optional |
form_session_* | sessionStorage | De-duplicates form views within a single page visit | Optional |
_jsid | sessionStorage | Storefront analytics session identifier (embedded storefronts only) | Optional |
_jcs | sessionStorage | Chatbot widget session identifier (embedded widgets only) | Optional |
6. Push notifications (opt-in, no cookies)
AI Super Hub and the Team Portal can send web push notifications (for example, job completions, owner alerts, sick-call alerts, roster changes and team announcements). Push notifications:
- Use the standard Web Push API with VAPID — they do not use cookies.
- Are strictly opt-in: your browser asks for your explicit permission before any subscription is created.
- Result in a push subscription (an endpoint and cryptographic keys generated by your browser) being stored against your record so we can deliver notifications.
You can withdraw permission at any time through your browser or operating system notification settings, or by unsubscribing within the app.
7. Tracking links that do not use cookies
Some features measure clicks without setting any cookie in your browser. These record event data server-side only:
- Referral / partner links (
/r/<code>) — record the partner code, a hashed (SHA-256) and truncated IP address, user-agent and referrer for our affiliate program. - Video Manager tracking links (
/vl/<slug>) and UTM links — record click counts and any UTM parameters server-side for content and marketing attribution.
For account security, we also maintain server-side records of login attempts and device fingerprints (a hash of browser characteristics) to detect suspicious sign-ins. These are security features stored in our database and do not use cookies.
8. Third-party services and where data goes
AI Super Hub integrates with a number of third-party service providers. With the exception noted below, these integrations operate server-side using our own API credentials — they do not place advertising or tracking cookies in your browser. Depending on which modules and integrations you use, these providers may include:
- Supabase (authentication, database and storage)
- Anthropic and OpenAI (AI features — chat, vision, transcription, image generation)
- ElevenLabs (text-to-speech) and Replicate (music generation)
- PayPal (payments, subscriptions and referral payouts)
- Resend, SendGrid, Postmark or AWS SES (transactional email); Twilio or ClickSend (SMS); Telegram (optional notifications)
- Shopify, Amazon, eBay (commerce); Xero, MYOB (accounting); Shotstack, YouTube/Google (video)
- Google Places / Google Vision (lead generation, OCR); Cloudflare Turnstile (anti-bot CAPTCHA on the sign-in form)
- WalletConnect and read-only crypto exchange connections (Bybit, Binance, OKX, Coinbase, CoinGecko)
The single browser-facing exception is Cloudflare Turnstile, which we use as a privacy-preserving anti-bot CAPTCHA on the sign-in form. It is designed by Cloudflare not to track users across sites for advertising.
For more detail on how these providers process personal information, please see our Privacy Policy.
9. How to control cookies
You can control and delete cookies and clear local/session storage through your web browser. Most browsers let you:
- View what cookies and site data are stored and delete some or all of them;
- Block all cookies, block third-party cookies, or block cookies from specific sites;
- Clear cookies and site data automatically when you close the browser.
Browser help pages for managing cookies and site data:
- Google Chrome — Settings → Privacy and security → Cookies and other site data
- Apple Safari — Settings/Preferences → Privacy
- Mozilla Firefox — Settings → Privacy & Security
- Microsoft Edge — Settings → Cookies and site permissions
You can also withdraw push-notification permission at any time via your browser or device notification settings.
Consequence of disabling cookies
- If you block or delete strictly necessary cookies (authentication and OAuth state cookies), you will not be able to sign in or stay signed in, and you will not be able to connect integrations such as Shopify, YouTube, Xero or MYOB. Core parts of the service will not function.
- If you block functional cookies (
hub_theme,hub_mode), the app will still work, but it will not remember your theme or dashboard mode between visits or devices. - If you block first-party analytics cookies on embedded storefronts or widgets, the business customer's analytics for that visit may be less accurate. This does not affect your ability to use the AI Super Hub application.
10. Changes to this Cookie Policy
We may update this Cookie Policy from time to time to reflect changes in the cookies and storage we use or for legal, operational or regulatory reasons. When we make material changes, we will update the "Last updated" date at the top of this page. We encourage you to review this page periodically.
11. Contact us
If you have any questions about this Cookie Policy or about how we use cookies and similar technologies, please contact us at:
Email: admin@aisuperhub.app
For privacy matters more generally, including your rights under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, please see our Privacy Policy. You may also contact the Office of the Australian Information Commissioner (OAIC) if you have a privacy concern.
Other policies
Questions about this Cookie Policy? Contact us at admin@aisuperhub.app.