Last updated 25 July 2026
Cookie Notice
This notice lists every cookie Shengul AI sets and what each one does. There are four, they are all strictly necessary, and none of them tracks you across other websites.
1. What we set, and why
A cookie is a small file a website asks your browser to keep. We use them for one job: to know that a request to the console comes from someone who has already signed in, so you are not asked for your password on every page.
We run no analytics, no advertising, no A/B testing and no third-party tracking of any kind. No other company sets a cookie through this site. Because every cookie below is strictly necessary to a service you asked for, there is no consent banner — there is nothing to consent to, and nothing to switch off that would leave the service working.
2. The complete list
| Name | Purpose | Set by | Expires |
|---|---|---|---|
| sb-…-auth-token | Holds your signed-in session so the console can identify you. May be split across a few numbered cookies when the session record is large. | Us, via our authentication provider | When the session expires or you sign out |
| sb-…-auth-token-code-verifier | A one-time value that proves a sign-in that was started in your browser is being completed in the same browser. | Us, via our authentication provider | A few minutes, as soon as sign-in completes |
| gmail_oauth_state | A single-use random value that proves a Gmail connection being completed was started by you. Prevents a third party from attaching their mailbox to your account. | Us | 10 minutes |
| outlook_oauth_state | The same protection for connecting an Outlook or Microsoft 365 mailbox. | Us | 10 minutes |
All four are set only on our own domain, are marked HttpOnly so page scripts cannot read them, are sent only over HTTPS in production, and carry SameSite protection against cross-site use. The two connection cookies are scoped to the connection routes and are not sent anywhere else.
The public marketing page sets no cookies at all. You can read it without ever being identified.
3. Other tracking technologies
We do not use web beacons, clear GIFs, tracking pixels, fingerprinting, local storage for tracking, or Flash local shared objects.
This applies to the emails we send as well. Outbound emails carry no tracking pixel and no rewritten links, so we do not know whether a message was opened or a link was clicked. That is a deliberate product decision, not an oversight: tracking markup is one of the signals that makes cold email look like bulk mail.
4. Controlling cookies
Every browser lets you see, block and delete cookies from its settings or privacy menu. Because ours exist only to hold your sign-in, blocking them means the console cannot keep you signed in and will return you to the sign-in page. The public marketing page will work normally.
There is no advertising opt-out to give you, because there is no advertising. If a future change to the service required a cookie that was not strictly necessary, we would ask for your consent before setting it and update this notice first.
5. Questions
How cookies fit into the wider picture of what we hold about you is set out in our Privacy Notice at /legal/privacy-policy. For anything else, email support@foundersideai.com or use the contact details at the foot of this page.