Cookie Policy
Before anyone types a word to one of our agents, a shorter exchange has already happened: your browser asked this site for a page, and the site answered. This policy annotates that opening exchange — what gets left on your device by it, why, and for how long.
1. The exchange this policy describes
Every page view is a short conversation of its own. Your browser opens with a request, our host answers with the page, and along the way it may ask your browser to hold a small piece of information for the next request. That is the whole subject of this document: the opening handshake between a browser and veronaai.co, annotated the same way our Privacy Policy annotates a conversation with an agent.
The short version, before the detail: the only things this site asks your browser to keep are security items placed by our host to tell people apart from automated traffic. Nothing here measures you, follows you or builds a picture of you.
2. What a browser can be asked to keep
A cookie is a small text file that a site asks your browser to store and hand back on later requests. Cookies are described as first-party when the site you are visiting sets them and third-party when they come from another organisation whose code the page has loaded; and as session when they vanish with the browser window or persistent when they outlive it. Several neighbouring technologies do a similar job, and all of them are treated identically here:
- Local and session storage — key-value stores the browser keeps for one site. The first survives until something clears it; the second disappears with the tab.
- Pixels and beacons — miniature images or scripts pulled in so that opening a page or an email can be registered.
- Device and SDK storage — the equivalent facilities inside a mobile app, the operating system keychain or keystore among them.
- Fingerprinting — deducing an identifier from the characteristics of a browser or device rather than storing one on it.
UK law regulates writing to or reading from your device whichever technique is used and whether or not personal data is involved, which is why all of them appear here and not cookies alone.
3. The two rulebooks
The Privacy and Electronic Communications (EC Directive) Regulations 2003, usually shortened to PECR. Regulation 6 says that putting information onto a user's device, or reading information already there, calls for clear and comprehensive information about why — and for that user's consent. A narrow exemption exists where the storage or access is strictly necessary to deliver a service the user expressly asked for, which reaches genuine security and delivery functions and stops well short of measurement, personalisation and advertising.
The UK GDPR. Wherever PECR calls for consent, that consent has to meet the standard at Articles 4(11) and 7: freely given, specific, informed, unambiguous, signalled by a clear affirmative act, as easy to take back as to give, and recorded so it can be evidenced. Boxes ticked in advance, consent inferred from someone continuing to scroll, and notices announcing that using the site implies agreement all fall short of it. Where a cookie also involves processing personal data, an Article 6 basis is needed on top.
The Information Commissioner's Office supervises both, and this policy is written against its published guidance on cookies and similar technologies.
4. What this site leaves behind
Our host, Cloudflare, may place the security items below to keep the site clear of bots and abuse. Which of them you receive depends on the protections active at that moment and on how your request was routed; a quiet visit may leave you with none at all.
| Name | Set by | What it does | Category | Lifetime |
|---|---|---|---|---|
| __cf_bm | Cloudflare, Inc., placed on our own domain | Bot management — separates a person from automated traffic so that abusive requests can be turned away | Strictly necessary — security | Up to 30 minutes, extended while you are active |
| cf_clearance | Cloudflare, Inc., first-party | Notes that a security challenge has already been passed, so that you are not stopped again on the next page | Strictly necessary — security | Up to 30 minutes, or whatever the challenge that issued it specifies |
| _cfuvid | Cloudflare, Inc., first-party | Applies rate limiting per visitor so a single source cannot swamp the site; carries no recognition of you between sessions | Strictly necessary — security | Session — discarded when the browser closes |
Cloudflare places these acting as our processor. None of them feeds advertising or cross-site tracking, none is sold or passed on for another purpose, and none can be tied by us to who you are. Cloudflare documents them itself at developers.cloudflare.com. Beyond the three above, this site writes nothing of its own to local or session storage.
Because everything on this page falls inside the strictly necessary exemption at PECR regulation 6(4), there is no consent to collect and therefore no banner to click through. A prompt asking for permission that the law does not require would teach visitors to dismiss prompts without reading them, which is the opposite of what consent is for.
5. Storage in the platform and apps
The signed-in Verona AI platform and the mobile apps need a small amount of storage in order to function at all. It is listed here for completeness and will carry exact names once those products are released.
| Item | Kept where | What it does | Category | Lifetime |
|---|---|---|---|---|
| Session or authentication token | Browser cookie, or the device keychain or keystore | Holds your signed-in state and stops the session being reused by anyone else | Strictly necessary | Until sign-out or expiry, typically 30 days |
| CSRF token | Browser cookie | Guards forms and actions against cross-site request forgery | Strictly necessary | Session |
| Interface preferences | Local storage | Remembers choices such as list density, or a notice you have dismissed | Strictly necessary to the service requested | Until cleared |
| Offline cache of recent items | Local storage or app storage | Lets the app open quickly and keep working through a short loss of connection | Strictly necessary | Wiped at sign-out |
None of it supports tracking, advertising or profiling. Section 9.2 of the Privacy Policy sets out what the apps hold on a device and what travels back to us.
6. Measurement and advertising
Clarity beats reassurance, so plainly: this website carries no analytics whatsoever — not Google Analytics, not a privacy-minded alternative, not server-side measurement beyond the security logs described in section 8 of our Privacy Policy. The consequence is that we know very little about how the site is used, and we would rather sit with that than ask for permission we have no need of.
There is likewise no advertising technology here: no network tags, no conversion pixels, no remarketing lists, no cross-site identifiers, no data brokers. Nothing is sold or shared for advertising, our apps carry no advertising SDK, and no advertising identifier is read.
7. The web font request
This site embeds no video, map, social feed, comment system or advertising frame, each of which routinely brings third-party cookies with it. It does fetch a stylesheet and font files from Google Fonts. That request stores nothing on your device for the purpose, though your IP address is necessarily visible to the service delivering the files, exactly as it is to any host your browser asks for a file. Should we bring the fonts onto our own domain, this section will be updated to say so. Follow a link away from here and that organisation's own practices take over.
8. If anything non-essential is ever added
A modest amount of privacy-respecting measurement may appeal to us one day. It would not simply appear. Before a single non-essential cookie or storage item is written we will:
- revise this policy and the tables above first, naming the item, who provides it, what it does and how long it lasts;
- ask for opt-in consent beforehand, through a notice where refusing is as easy and as visible as agreeing, with nothing pre-ticked and no wall barring entry to those who decline;
- offer choice category by category rather than as a single switch, and write nothing in a category you have not accepted;
- record what was consented to and provide a permanent, obvious way to change or withdraw it, withdrawal being no harder than agreeing was; and
- keep serving the whole site to anyone who says no.
Implied or assumed consent will never be treated as a licence to write a non-essential cookie here.
9. Taking control in your browser
Every major browser lets you inspect, block and delete cookies and site storage, and set rules for individual sites. Blocking the security items in section 4 may cause a check to fail or a signed-in session to drop, but this website will otherwise behave normally without them.
- Chrome on desktop: the ⋮ menu, then Settings, Privacy and security, Third-party cookies; and Site settings, Cookies and site data, where “See all site data and permissions” clears one site at a time.
- Safari on macOS: the Safari menu, then Settings, Privacy, where “Block all cookies” and “Manage Website Data…” live. Intelligent Tracking Prevention is already on.
- Firefox: open ☰, then Settings, then Privacy & Security. Enhanced Tracking Protection sits there with its Standard, Strict and Custom settings, and Manage Data sits under Cookies and Site Data.
- Edge: the … menu, then Settings, Cookies and site permissions, then Manage and delete cookies and site data; Tracking prevention sets the site-wide default.
- Safari on iPhone and iPad: Settings, Apps, Safari, then Block All Cookies; Advanced then Website Data removes data site by site.
- Chrome on Android: the ⋮ menu, then Settings, Site settings, Cookies; or Privacy and security, Delete browsing data.
- Our mobile apps: signing out clears app storage. On iOS, removing the app does it; on Android, Settings, Apps, Verona AI, Storage, Clear storage.
A private or incognito window, offered by most browsers, throws away cookies and storage when it closes. Independent guidance worth reading is published at aboutcookies.org and by the ICO at ico.org.uk.
10. Do Not Track and Global Privacy Control
Do Not Track is a header a browser can send asking not to be tracked. It was never standardised, most sites disregard it, and several browsers have dropped the setting entirely. We place no weight on it — but since nothing here tracks anyone to begin with, sending it changes nothing about how this site behaves.
Global Privacy Control came later and carries a different message: an objection to personal data being sold or shared, and in certain jurisdictions to advertising aimed at the individual. Nothing is sold or shared here and no advertising technology runs, so the signal has nothing to switch off. Were non-essential cookies ever introduced as section 8 describes, a Global Privacy Control signal would be treated as a valid objection to any advertising or sale-related processing, and this page would say so at that point.
11. How this connects to your rights
The security items in section 4 involve limited processing of technical data, your IP address among it, for the purpose of protecting the site. Storing it is permitted by the strictly necessary exemption in PECR; the processing that follows rests on Article 6(1)(f) UK GDPR — our legitimate interest in a site that stays available and free of abuse. Section 8 of our Privacy Policy describes it in full, alongside the rights you hold and how to use them, including the right to object and the route to the ICO.
12. Revisions, and where to write
This page is revised whenever the technologies in use change, and always before a new cookie or storage item appears rather than afterwards. Each release carries an effective date, a last-updated date and a version number at the head of the page; this is version 3.0, effective 5 August 2026. Superseded versions are available on request.
Questions about this page, or about something you have found in your browser that it does not list:
VERONA AI LIMITED
ask@veronaai.co
Find a cookie on veronaai.co that is missing from the table in section 4 and we would genuinely want to hear about it: write in and we will either correct the table or take the cookie out. The Privacy Policy and the Terms of Use complete the set.
Published by VERONA AI LIMITED, Company No. NI738464. Version 3.0 — effective 5 August 2026.