Legal
Last updated: 31 August 2026 (draft)
DRAFT: pending legal review, not yet approved for reliance
This page explains the cookies and similar technologies — including browser local storage and session storage — that Hyper uses on hyper-planning.com and within the product.
We do not use any analytics, advertising or tracking cookies, and we do not allow any third party to use our site for those purposes. Everything listed below is needed to deliver the service you asked for: keeping you signed in, remembering how you have arranged the interface, protecting the sign-in form from bots, and our map provider’s own metering.
Because none of it is used for analytics, advertising or tracking, we do not ask you for consent to store it — under the Privacy and Electronic Communications Regulations we are required to tell you about it clearly instead, which is what this page does. If that ever changes, we will ask for your consent first, and this page will change with it.
| Name | Type | Purpose | Duration |
|---|---|---|---|
sb-<project-ref>-auth-token | Local storage | Keeps you signed in (set by our authentication provider, Supabase). | Until you sign out or your session expires |
hyper-cookie-consent | Local storage | Remembers that you have seen the cookie notice, so it isn’t shown on every visit. | Until cleared |
These record interface preferences so the product looks the way you left it. They hold no personal information beyond the setting itself, and they are never used to build a profile of you.
| Name | Type | Purpose | Duration |
|---|---|---|---|
sidebar_open, sidebar_state | Cookie | Remembers whether the app’s navigation sidebar is expanded or collapsed. | 30 days / 7 days |
copilot_open | Cookie | Remembers whether the AI copilot panel is open. | 30 days |
tsr-scroll-restoration-v1_3 | Session storage | Returns you to the same scroll position when you navigate back to a page. | Until you close the tab |
tanstack_router_reload:<message> | Session storage | Set only if part of the app fails to load, so that an automatic retry cannot loop indefinitely. | Until you close the tab |
| Name | Type | Purpose | Duration |
|---|---|---|---|
| None stored on your device | Script access to device and browser characteristics | Cloudflare Turnstile protects our sign-in and sign-up forms from automated abuse. It sets no cookie and stores nothing on your device, but it does read browser and device characteristics — including your IP address, browser user-agent and TLS fingerprint — and returns a single-use token to our server. It does not read what you type into the form. Cloudflare also uses these signals, as an independent controller, to improve its own bot detection. See Cloudflare’s Turnstile Privacy Addendum. | Nothing stored; the verification token is single-use and short-lived |
The map is provided by Mapbox. When a map loads, the Mapbox library stores its own metering values on your device and reports the map load to Mapbox. Mapbox states that these are billing values, that it does not track users between billing cycles, and that it does not build profiles from them. We cannot switch this off: Mapbox provides no option to disable it in the browser, and its terms do not permit us to suppress it by other means.
These values are only created once you open a page containing a map, which is inside the signed-in product. Clearing your browser storage removes them, and a new value is generated the next time you load a map.
| Name | Type | Purpose | Duration |
|---|---|---|---|
mapbox.eventData:<id>, mapbox.eventData.uuid:<id>, mapbox.eventData.uuidTimestamp:<id> | Local storage | Mapbox’s own metering. Holds a random identifier that is not linked to your Hyper account and is not used by us for any purpose. | Identifier is regenerated every 24 hours |
No analytics, no advertising, no marketing or social-media pixels, and no third-party tracking cookies. We do not use Google Analytics or any equivalent. Our error-monitoring provider, Sentry, stores nothing on your device; session replay is deliberately switched off, because it would record the contents of your screen. Our fonts are served from our own domain rather than a third-party font service.
You can clear or block cookies and local storage through your browser settings — see your browser’s help pages for how. Because everything listed above is needed for the product to work, blocking it will break things: most obviously, you will not be able to stay signed in.
We’ll update this page whenever what we store changes, and update the “last updated” date above.
Questions about this policy: hello@hyper-planning.com. See also our Privacy Policy.