Cookie Policy
Version: 1.1
Review Date: 31 July 2026
Effective Date: 1 August 2026
Next Review Date: 1 August 2027
1. Purpose and scope
This Cookie Policy explains how Glimma AI uses cookies and similar technologies on the public Glimma AI website, in the Glimma AI research platform and in the Glimma AI User Research mobile applications for iOS and Android.
In this policy, cookies and similar technologies include HTTP cookies, browser local storage, browser session storage and other technologies that may store or access information on a visitor's, user's or participant's device.
In summary:
- the public website uses cookie-free analytics, strictly necessary security cookies connected to Cloudflare Turnstile, and one item of local storage that remembers a display choice you make;
- the research platform uses only strictly necessary cookies required for authentication, session management, study access and security;
- the mobile applications do not use browser cookies and instead rely on secure device storage and application preferences.
We do not use advertising, retargeting or cross-site tracking technologies anywhere in our Services.
2. Consent and strictly necessary technologies
Where a cookie or similar technology is strictly necessary to provide a service that you have requested, or to keep that service secure, it may be used without consent under applicable electronic communications and privacy rules. This applies to the authentication, session, study access and bot-protection technologies described in this policy.
The relevant legal test is whether information is stored on or read from your device, not whether that information is sent to Glimma AI. Local storage is therefore covered by this policy even when its contents never leave your device.
We do not currently use any optional cookies or similar technologies, and we therefore do not display a cookie consent banner. If we introduce optional technologies in the future, we will update this policy and, where required, request consent before using them.
3. Public website
The public Glimma AI website is hosted on Vercel. This section also applies to any participant-facing or demonstration pages served on the Glimma AI website, as distinct from the research platform described in section 4.
3.1 Strictly necessary security cookies
We use Cloudflare Turnstile to protect our forms from automated abuse. Turnstile loads on the Book a Demo page when that page opens, and on the home page, the Glimma Insights report page and the webinar page when you open a form that requests your details. It does not load anywhere else on the website.
When the Turnstile widget loads, Cloudflare may set strictly necessary security cookies. These cookies are set by Cloudflare on the challenges.cloudflare.com domain, not on the Glimma AI domain, and they are used for challenge and bot-protection purposes only.
| Cookie | Provider and domain | Purpose | Type | Expiry |
|---|---|---|---|---|
cf_chl_* challenge cookies | Cloudflare, Inc. Domain: challenges.cloudflare.com | Set by Cloudflare challenge and bot-protection services when the Turnstile widget loads. Helps verify that the visitor is a person and protects our forms from automated abuse. Not used by Glimma AI for advertising, profiling or cross-site tracking. | Strictly necessary security cookie, set by a third party | Short-lived or session |
The exact cookies Cloudflare sets depend on its own configuration and may change. Because these cookies belong to a third-party domain, browsers that restrict or partition third-party cookies may store them in a partitioned form or block them entirely; Turnstile is designed to work in either case. Cloudflare may process this information outside the European Economic Area. See the international transfers section of our Privacy Policy and the Cloudflare privacy policy.
3.2 Analytics
We use Vercel Web Analytics to understand aggregated website usage and improve the website experience. It does not use cookies, and we do not use it for advertising, profiling or cross-site tracking.
| Technology | Provider | Purpose | Type | Expiry or retention |
|---|---|---|---|---|
| Vercel Web Analytics | Vercel Inc. | Counts aggregate page views and helps us understand website usage, such as page views, traffic sources, browser, device type, operating system and approximate location. It does not allow Glimma AI to identify individual visitors. The script is served from a path on our own domain and runs on all pages of the public website. | Cookie-free analytics technology | No cookies are set. Vercel derives a short-lived, daily-rotating hash from request data to deduplicate page views. The visitor-session hash is discarded within 24 hours. |
See the Vercel Web Analytics privacy notice.
3.3 Local storage on the public website
The public website writes one item of local storage. It is written only when you actively dismiss a notice, it holds no personal data, and it is never transmitted to our servers.
| Key | Storage | Purpose | Type | Expiry |
|---|---|---|---|---|
glimma_webinar_dismissed_<event id> | Browser local storage, first party | Records that you closed the announcement bar shown at the top of the website, so the same announcement does not reappear on later visits. Written only when you click the close button, and scoped to a single announcement. | Strictly necessary, records a display choice you made | No automatic expiry; retained until you clear your browser storage |
3.4 Third-party services that do not set cookies
The public website loads the following third-party services. To the best of our knowledge, these services do not set cookies in your browser. They do, however, receive your IP address and browser user agent as part of the request needed to deliver the content.
| Service | Provider | Purpose | Cookie use |
|---|---|---|---|
| Google Fonts | Delivers the Material Symbols Outlined icon font, loaded from fonts.googleapis.com and fonts.gstatic.com. Our main typeface, Raleway, is served from our own domain and does not involve a request to Google. | No cookies identified | |
| LordIcon | LordIcon | Provides the animated icon library used on the website. Loaded on all pages from cdn.lordicon.com. | No cookies identified |
| Cloudinary | Cloudinary | Hosts and delivers website media, such as the video on the home page. | No cookies identified |
| Vercel | Vercel Inc. | Hosts the website and serves every page request. Standard server logs are generated as part of delivering the website. | No cookies set on the public website |
| Resend | Resend | Used on our servers to deliver demo requests and similar form submissions by email. | No client-side cookies |
3.5 Technologies we do not use on the public website
We do not use advertising cookies, retargeting pixels or cross-site tracking cookies on the public website. We do not currently use Google Analytics, Meta Pixel, LinkedIn Insight Tag, HubSpot tracking, Intercom or similar marketing trackers. The public website does not load Sentry or any other error-monitoring script.
If Glimma AI later enables additional analytics, advertising, embedded media, chat, CRM or marketing tools that use cookies or similar technologies, this Cookie Policy will be updated accordingly.
4. Glimma AI research platform
For the purposes of this Cookie Policy, the Glimma AI research platform refers to the secure online environment where researchers, customers and research teams can log in to set up, manage, monitor and analyse research studies, and where participants can access study links, take part in research tasks, complete AI-moderated interviews and interact with study materials.
The research platform uses only strictly necessary cookies required for authentication, session management, study access and security. We do not set analytics, advertising, retargeting or cross-site tracking cookies in the research platform.
These cookies are essential for the platform to function and cannot be switched off through our service. They are usually set in response to actions such as logging in, accessing a study, completing a task or submitting an authentication form.
4.1 Strictly necessary cookies
| Cookie | Provider | Purpose | Type | Expiry |
|---|---|---|---|---|
accessToken | Glimma AI, first party | Authenticates participant sessions and grants access to the participant dashboard. Required to keep participants signed in while completing a study. | HTTP cookie; HttpOnly; Secure; SameSite=Lax | 24 hours |
__Secure-authjs.session-token | Glimma AI, first party, via Auth.js | Authenticates administrator and research-team sessions, so those users remain signed in across pages. | HTTP cookie; HttpOnly; Secure; SameSite=Lax | 8 hours |
__Host-authjs.csrf-token | Glimma AI, first party, via Auth.js | Protects sign-in, sign-out and other authentication form submissions against cross-site request forgery. | HTTP cookie; HttpOnly; Secure; SameSite=Lax | Session |
__Secure-authjs.callback-url | Glimma AI, first party, via Auth.js | Remembers the page the user was trying to reach, so we can return them there after sign-in. | HTTP cookie; Secure; SameSite=Lax | Session |
4.2 Local storage in the research platform
When a study task asks a participant to interact with an external website inside an embedded viewer, we record the cookie-banner choice the participant made on that website so that the banner does not reappear each time the task loads. This gives effect to a choice the participant made themselves. The value is stored locally on the participant's device and is not transmitted to Glimma AI.
| Key | Storage | Purpose | Type | Expiry |
|---|---|---|---|---|
cookie_consent_<domain> | Browser local storage, first party | Records the cookie-banner choice a participant made on an external website loaded inside a research task, so the banner does not reappear on later loads of the same task. | Strictly necessary, records a choice made by the participant | 30 days, enforced by the platform |
4.3 Third-party cookies on embedded websites
Some research tasks load external third-party websites inside an embedded viewer. Those websites may set their own cookies, for example consent-management cookies from tools such as Cookiebot, OneTrust, CookieYes or similar providers.
Glimma AI does not control these third-party cookies. They are governed by the cookie policy of the website the participant visits as part of the research task.
5. Mobile applications
The Glimma AI User Research mobile applications for iOS and Android do not use browser cookies in the way a website does. Instead, they may use secure device storage, application preferences, operating-system keychain or keystore facilities, and similar technologies to keep a participant signed in, to remember study progress and permission status, and to keep the application secure.
The applications may also generate pseudonymous session and diagnostic identifiers so that a study session can be linked to its recordings and so that technical problems can be diagnosed.
The applications do not use advertising identifiers, and they do not track participants across other companies' apps or websites.
Where a research task opens an external website inside the application, that website may set its own cookies, as described in section 4.3.
Information about the personal data processed in the mobile applications, including recordings and device permissions, is set out in our Privacy Policy and in the privacy disclosures published on the Apple App Store and Google Play.
6. Error monitoring and diagnostics
We use error-monitoring and diagnostic tools, including Sentry, in the Glimma AI research platform and in the mobile applications, to detect and resolve technical problems and to keep our Services reliable and secure. These tools are not loaded on the public Glimma AI website.
Where these tools operate in a browser, they may use browser session storage to group the events belonging to a single session. They do not set advertising or cross-site tracking cookies. The personal data processed for error monitoring is described in our Privacy Policy.
7. Managing cookies and similar technologies
Because the cookies used in the Glimma AI research platform are strictly necessary for authentication, session management, study access and security, disabling them may prevent users from signing in, accessing the platform or completing a study.
You can clear cookies and local storage at any time through your browser settings, and you can usually block cookies there as well. Doing so may sign you out, interrupt an active study session, require you to repeat security checks, or cause a dismissed announcement to reappear.
Where Glimma AI uses only strictly necessary technologies, those technologies are required to provide the service you asked for and cannot be switched off through our service.
On mobile, you can clear application storage through your device settings or by uninstalling the application.
8. Changes to this Cookie Policy
We may update this Cookie Policy from time to time, for example if we add or remove a service that uses cookies or similar technologies. The version number and dates at the top of this page show when it was last reviewed. Where a change requires your consent, we will ask for it before the change takes effect.
9. Related documents
This Cookie Policy should be read together with our Privacy Policy and our Terms & Conditions, and, where applicable, the Data Processing Agreement entered into with customers.
10. Contact
For questions about this Cookie Policy or about how we use cookies and similar technologies, please contact:
Glimma AI
Email: privacy@glimma.ai