Cookie Policy

Last updated: 2 May 2026

What we use

We use only the cookies and storage required to deliver the service securely. Analytics and marketing cookies are off by default and only set after explicit opt-in via the cookie banner.

Strictly necessary (always on)

  • Supabase auth session — HttpOnly, Secure, SameSite=Lax
  • Cloudflare — bot management and WAF (cf_clearance, __cf_bm)
  • Turnstile challenge — bot protection on auth forms
  • enerwise_consent — stores your cookie preference (12 months)

Analytics (off until you opt in)

  • Vercel Analytics — aggregate page views, no IP stored

Functional storage (always on)

  • localStorage — cached map tiles and assessment drafts; cleared on sign-out

Marketing

None. We do not run advertising trackers.

Managing your preferences

Use the "Cookie settings" link in the page footer at any time, or clear cookies in your browser. Disabling strictly-necessary cookies will break login. See also our Privacy Policy.