Effective Date: February 14, 2026
Last updated: April 23, 2026
The data controller responsible for the processing of personal data collected via cookies and similar technologies is:
Cookies are small text files stored on your device when you visit a website. They help websites function properly, remember your preferences, and provide information to the site owner. Some cookies are essential for the website to work, while others help us improve your experience.
The use of cookies is regulated by the ePrivacy Directive (2002/58/EC) and the General Data Protection Regulation (GDPR). Under these regulations:
These cookies are essential for the Service to function and cannot be disabled. No consent is required.
| Cookie | Purpose | Legal Basis | Duration |
|---|---|---|---|
| sb-*-auth-token | Authentication session (Supabase Auth) | Essential | Session / 1 year |
| sb-*-auth-token-code-verifier | PKCE authentication flow verification | Essential | Session |
| NEXT_LOCALE | Remembers your preferred site language (English, German, Spanish, or Italian) | Essential | 1 year |
| lang-chosen | Records that you have chosen a language so the welcome-language prompt is not shown again | Essential | 1 year |
| ref_code | Preserves affiliate referral code during the signup process | Essential | 30 days |
| sma_imp | Short-lived admin impersonation token set only when a Scale Media AI support agent accesses your workspace. All such sessions are audit-logged. | Essential (support) | 30 minutes |
These browser storage items remember your preferences and settings to enhance your experience. They are stored in localStorage and do not require consent as they are limited to UI preferences within the application.
| Key | Purpose | Storage Type | Duration |
|---|---|---|---|
| cookie-consent | Records whether you accepted or declined non-essential cookies so we don't re-prompt | localStorage | Persistent until cleared |
| sidebar-collapsed | Remembers whether you had the in-app sidebar collapsed or expanded | localStorage | Persistent until cleared |
| dashboard_lang_gate_done | One-time flag so the in-app language confirmation prompt is shown only once | localStorage | Persistent until cleared |
We use Vercel Web Analytics to understand page views and site performance. This service is only activated after you give consent via our cookie banner. No data is collected before you accept.
| Service | Purpose | Legal Basis | Data Collected |
|---|---|---|---|
| Vercel Web Analytics | Page views, web performance metrics, visitor count | Consent | Anonymized page view data, no personal identifiers |
Vercel Analytics is privacy-focused and does not use cookies for tracking. It collects anonymized, aggregated data. You can withdraw consent at any time via the "Cookie Settings" link in our website footer.
We do not use any marketing or advertising cookies. We do not track you across other websites, share data with ad networks, or use retargeting pixels.
In addition to cookies, we use browser local storage and session storage to persist certain preferences and application state. These technologies function similarly to cookies but are managed differently by the browser. They are subject to the same policies described here.
You can clear local storage and session storage at any time via your browser's developer tools or privacy settings.
You can manage or withdraw your cookie consent at any time using any of the following methods:
When you first visit our website, a cookie consent banner allows you to accept or decline non-essential cookies and analytics. You can update your preferences at any time by clicking the "Cookie Settings" link in the website footer, which re-opens the consent banner.
Most browsers allow you to control cookies through their settings. Here are instructions for common browsers:
Mobile devices typically offer cookie management options within their privacy settings. iOS users can manage this via Settings → Safari → Advanced → Website Data. Android users can manage via Chrome → Settings → Privacy and Security → Clear Browsing Data.
Note: Blocking or deleting strictly necessary cookies (such as authentication tokens) may prevent the Service from functioning correctly. You may be unable to log in or use certain features.
Scale Media AI implements comprehensive data protection measures to safeguard your personal information:
All payment processing is handled by Stripe, a PCI DSS Level 1 certified payment processor. We never store, process, or have access to full credit card numbers. Payment forms are served directly by Stripe's secure infrastructure.
In the unlikely event of a data breach that poses a risk to your rights and freedoms, we will:
We maintain Data Processing Agreements (DPAs) with all third-party service providers who process personal data on our behalf. These agreements ensure compliance with GDPR Article 28 requirements, including:
You have the right to access, rectify, erase, restrict, object to, and port your data. You also have the right to withdraw consent for non-essential cookies at any time. For a complete overview of your data protection rights, please refer to our Privacy Policy.
To exercise your rights, email info@scalemedia.ai with the subject line "DATA PROTECTION: RIGHTS REQUEST".
When you visit our public demo at scalemedia.ai/demo, the page loads Cloudflare Turnstile for invisible bot-protection. Turnstile may set strictly-necessary first-party cookies and short-lived clearance tokens that are essential for it to function and cannot be turned off without breaking the demo. We additionally write a server-side record of your submission attempt (IP, user-agent, the URL you sent, timestamp, and the exact text of the consent statement you accepted) to our demo_consent_log table and retain it for up to 12 months for fraud-prevention purposes — those records are server-side database entries, not cookies; full detail in our Privacy Policy.
We may update this Cookie & Data Protection Policy from time to time. We will notify you of material changes by updating the "Last updated" date above and, where appropriate, by notifying you via email. We encourage you to review this policy periodically.
For questions related to data protection, cookies, or to exercise your data rights, please contact: