Cookie Policy
Contents
1. Scope
This policy covers cookies and similar device-storage technologies used by FundyBee. Cookies are small values sent with web requests. Local storage persists in your browser until it is removed; session storage normally lasts for the current tab or browser session. These technologies are also covered by ePrivacy rules.
We currently use only storage needed to authenticate users, secure and operate requested features, preserve a workflow across navigation, or remember a setting the user selected. We do not use advertising, retargeting, cross-site tracking or analytics cookies.
2. Cookies
| Name | Purpose | Duration and category |
|---|---|---|
sb-* | Supabase authentication and refresh-token chunks used to sign you in, rotate a session and protect authenticated requests. The exact project/chunk suffix varies. | Up to 400 days and refreshed while the session is used; sign-out or account/session invalidation ends access. Strictly necessary. |
gp_active_account | Stores the selected workspace identifier when a user belongs to more than one workspace. | Up to 365 days; strictly necessary for the selected workspace. |
gp_refresh_notifications | Short-lived signal after sign-in or invitation acceptance so the notification list refreshes once. | Up to 120 seconds and then removed/expired; strictly necessary. |
__cf_bm (conditional) | Cloudflare bot-management security when that protection is enabled for the request. | Expires after 30 minutes of inactivity; strictly necessary security. |
cf_clearance (conditional) | Remembers that a visitor passed a Cloudflare security challenge so the requested site can be reached. | Configured challenge-passage period (Cloudflare default: 30 minutes); strictly necessary security. |
cf_chl_* (conditional) | Short-lived Cloudflare challenge state used only while a security check is in progress. | Challenge/session duration; strictly necessary security. |
3. Local storage
| Key | Purpose | Duration |
|---|---|---|
gp_cookie_notice | Remembers that this storage notice was dismissed. It does not enable another technology. | Until browser data is cleared. |
fundybee-theme | Remembers the light/dark theme selected by the user. | Until changed or browser data is cleared. |
fundybee:freeplan-banner-dismissed | Remembers that the user dismissed the free-plan information banner. | Until the subscription flow clears it or browser data is cleared. |
gp.onboardingWizard.dismissed.v1 | Remembers that the account onboarding wizard was dismissed. | Until browser data is cleared or the key version changes. |
gp.onboardingTour.dismissed.v1 | Remembers that the projects tour was dismissed or completed. | Until browser data is cleared or the key version changes. |
fundybee:proposal-pipeline:<project-id> | Lets an active write-and-review run recover its visible phase after a page refresh. | Treated as stale and removed when read after 24 hours; can remain until then or until cleared. |
4. Session storage
| Key | Purpose | Duration |
|---|---|---|
gp-notifications-refresh | One-time client signal to refresh notifications after navigation. | Current tab; removed when consumed. |
gp-studio-concept | Temporarily preserves the current Idea Lab generation state during the session. | Current tab/session or explicit removal. |
gp-studio-client-token | Correlates a browser-side Idea Lab run with the server operation and avoids duplicate work. | Current tab/session or explicit removal. |
gp-partner-prefill | Moves a customer-selected partner/PIF prefill between partner-library screens. | Current tab; removed after it is read. |
gp-studio-discard-notice | Shows a one-time confirmation after an Idea Lab draft is discarded. | Current tab; removed when consumed. |
fb-proposal-assistant-open | Remembers whether the proposal assistant rail is open within the current tab. | Current tab/session. |
5. External resources
Fonts and icon styles are served with the application. An embedded public landing-page demonstration loads the GSAP animation script from jsDelivr, which receives ordinary connection data such as IP address and user agent; no account or proposal content is intentionally sent. When a customer opens the optional DocuSeal signing experience, that embedded provider may use its own cookies or storage needed to load and complete the requested signature workflow. The provider’s own technology and privacy terms apply. See the Privacy Notice provider table.
6. Why there is no optional-cookie selector
The first-visit banner is an informational storage notice, not an “accept all” control. Dismissing it stores only gp_cookie_notice. No analytics or advertising technology is activated by the button. We rely on the ePrivacy exemption for storage strictly necessary to provide the Service or a setting explicitly requested by the user.
If we introduce optional analytics, advertising or another non-essential purpose, it will remain off until the required consent is obtained. We will provide equally accessible accept, reject and preference controls and a way to withdraw consent.
7. Managing storage
Browser settings can inspect, clear or block cookies and site data. Blocking authentication cookies will prevent sign-in; clearing local/session storage resets preferences and temporary workflow continuity but does not delete server-side account or project data. Use Account & privacy or contact us for server-side rights requests.
8. Changes and contact
We update this table when the application adds, removes or changes a browser-storage key. Questions or reports of an unlisted technology can be sent to info@innovationbee.gr. The effective date and version above identify the current policy.

