← Back to TonoDesk

Cookie Policy

Last updated: August 18, 2026

This Cookie Policy explains how Appa Digital LLC ("Company," "we," "us," or "our"), operating as TonoDesk, uses cookies and similar technologies when you visit tonodesk.com or use the TonoDesk service (the "Service"). It complements our Privacy Policy.

1. What we use cookies for

TonoDesk uses cookies for three purposes only:

  • Authentication — keeping you signed in.
  • Scope selection — remembering which tenant / brand / account you last chose.
  • First-party analytics — a session ID so we can count distinct sessions in aggregate. No cross-site tracking.

2. Cookies we set

NamePurposeRetention
sb-*-auth-tokenSupabase session (auth). Signed JWT.1 hour, refreshed while active
lf-scopeRemembers your last-selected tenant / brand / account.Session
beatura_demo_runCorrelates a demo-mode session with server-side checkpoints (only set when a founder-guided demo is running).5 minutes
cd_analytics_sid (sessionStorage)Random session ID for first-party analytics event stitching.Browser session
cd_analytics_opened (sessionStorage)Dedupe marker so the app_open event fires once per session.Browser session

3. First-party analytics

TonoDesk fires analytics events to a Beatura-operated endpoint (api.beatura.com/api/analytics). Events are attributed to your user + tenant via the Supabase cookie above and stitched into sessions via the cd_analytics_sid value.

Event types we fire:

  • app_open, session_start, route_view, page_load
  • feature_open, paywall_view, checkout_start, signup_started, signup_completed, checkout_success
  • inbox_open, item_view, draft_rotate, item_dismiss, item_reply, keyword_group_edit
  • ai_spend, api_call, error

Event bodies never carry PII beyond an opaque identifier — we do not send reply text, source-post bodies, or emails in event props. See the engine-side event allowlist for the exact fields per type.

4. What we do NOT use

  • Google Analytics
  • Segment, PostHog, Amplitude, Mixpanel
  • Facebook Pixel
  • LinkedIn Insight Tag
  • Any ad-network retargeting cookie
  • Cross-domain tracking

5. Your controls

You can clear cookies via your browser settings; doing so will sign you out of TonoDesk (you can sign back in). Blocking the Supabase cookie prevents sign-in entirely.

Because we don't use any tracking or advertising cookies, we don't show a "cookie banner" — there's nothing to consent to beyond the strictly-necessary session cookies described above.

Contact

Questions: privacy@beatura.com.