Last updated: August 18, 2026
This Cookie Policy explains how Appa Digital LLC ("Company," "we," "us," or "our"), operating as TonoDesk, uses cookies and similar technologies when you visit tonodesk.com or use the TonoDesk service (the "Service"). It complements our Privacy Policy.
TonoDesk uses cookies for three purposes only:
| Name | Purpose | Retention |
|---|---|---|
sb-*-auth-token | Supabase session (auth). Signed JWT. | 1 hour, refreshed while active |
lf-scope | Remembers your last-selected tenant / brand / account. | Session |
beatura_demo_run | Correlates a demo-mode session with server-side checkpoints (only set when a founder-guided demo is running). | 5 minutes |
cd_analytics_sid (sessionStorage) | Random session ID for first-party analytics event stitching. | Browser session |
cd_analytics_opened (sessionStorage) | Dedupe marker so the app_open event fires once per session. | Browser session |
TonoDesk fires analytics events to a Beatura-operated endpoint (api.beatura.com/api/analytics). Events are attributed to your user + tenant via the Supabase cookie above and stitched into sessions via the cd_analytics_sid value.
Event types we fire:
app_open, session_start, route_view, page_loadfeature_open, paywall_view, checkout_start, signup_started, signup_completed, checkout_successinbox_open, item_view, draft_rotate, item_dismiss, item_reply, keyword_group_editai_spend, api_call, errorEvent bodies never carry PII beyond an opaque identifier — we do not send reply text, source-post bodies, or emails in event props. See the engine-side event allowlist for the exact fields per type.
You can clear cookies via your browser settings; doing so will sign you out of TonoDesk (you can sign back in). Blocking the Supabase cookie prevents sign-in entirely.
Because we don't use any tracking or advertising cookies, we don't show a "cookie banner" — there's nothing to consent to beyond the strictly-necessary session cookies described above.
Questions: privacy@beatura.com.