Version dated 16 September 2026. This page supplements the Cicora Privacy Policy. It applies to the website, web interface, mobile application, and other interfaces using cookies, local storage, SDKs, pixels, device identifiers, session logs, or comparable technologies. It does not apply to cookies or SDKs of third-party sites a user opens outside Cicora.
1. What these technologies are and why they are used
Cookies are small files or records saved in a browser. Local storage, session storage, SDKs, device identifiers, pixels, web beacons, and similar mechanisms can have a similar role on the web or in an application. Depending on their setting, they can help to:
- maintain sign-in, a secure session, and avoid repeated authentication;
- retain language, basic accessibility preferences, and technical settings;
- remember a user's cookie choice and avoid displaying the same notice repeatedly;
- provide security, identify abuse or an error, and prevent a duplicated request;
- when separately enabled, measure interface performance, improve a feature, or display an optional informational message.
A technology does not automatically receive more data than its specific task needs. For example, a cookie-consent record does not authorise reading the content of a prompt, and a language record does not authorise advertising. Cicora does not use private prompts, attachments, or outputs for third-party behavioural advertising.
2. Categories and the rule for enabling them
| Category | What it can do | Basis and control |
|---|---|---|
| Strictly necessary | maintain sign-in and session security, distribute technical load, prevent abuse, retain a security setting, the cookie choice itself, and a language selection expressly made on the public website | used where needed for a requested service, security, or performance of a contract; disabling them can make sign-in or a particular feature unavailable |
| Functional | retain theme, accessibility, and other expressly chosen preferences | enabled where such a setting is available and needed for the chosen experience; the user is told how to change it |
| Analytics | measure technical use of pages or features, identify faults, and understand interface effectiveness | enabled after the actual supplier, purpose, period, and applicable basis are reviewed; where prior consent is required, they do not operate before it |
| Marketing and advertising | measure a campaign, show an offer, or use an advertising identifier | enabled after publication of the actual register, purpose, recipient, period, and collection of required consent or provision of an opt-out; access to the core paid feature does not depend on consent to optional advertising |
| Application SDKs and local storage | support sign-in, notifications, preferences, functionality, or an expressly selected integration | governed by the same principles of necessity, transparency, minimisation, and control; an operating-system permission does not replace consent to optional processing |
The register contains only technologies, advertising networks, SDKs, and periods actually in use. An optional technology begins to be used after it is included in the verified register and the disclosure and user choice required by law or this Policy have been completed.
3. Register of technologies actually in use
For every technology actually active, including a necessary setting, Cicora publishes in this page or a linked register widget:
1. the technology or SDK name and recipient; 2. its category and exact purpose; 3. the data or identifiers processed; 4. the storage period or criteria for determining it; 5. whether the recipient is an independent controller, processor, or third-party service in the applicable sense; 6. the country/international-transfer mechanism where that information is required; 7. a link to settings, opt-out, or the recipient's policy where needed; 8. the date the record was last checked.
The register reflects the actual website, application, and SDKs rather than a planned architecture. When a technology is removed, its record is marked inactive or removed from the active list after verifying that the code, tag, or SDK no longer runs. A user may ask about a register entry at support@cicora.ai.
Current necessary public-site setting
| Technology and recipient | Category and exact purpose | Data and retention | Scope and control | Last checked |
|---|---|---|---|---|
Browser localStorage key cicora.site.locale; no external recipient | Strictly necessary — stores only a language expressly selected by the user so a later visit to the bare public-site path / can honor that choice | The selected supported language code; retained until the user selects another language or clears site data | Public Cicora website only: it is not used by backend services or for Account/Request Material processing. A first visit to / with no stored choice uses English; an explicit URL for a supported language takes priority. The key does not use browser, country, or IP inference; no analytics, advertising, profiling, or consent banner is activated. | 16 September 2026 |
4. User choice
Where consent is required for an optional category, the banner or settings screen provides these clear actions before the category is enabled:
- “Accept selected optional categories”;
- “Reject optional categories”;
- “Settings,” with categories and an explanation of purpose;
- “Save choice”; and
- a way to change the decision later through a link or setting available from the website or application.
Rejecting is as easy as accepting. The interface does not pre-select optional categories, combine marketing with acceptance of the Terms, or use a refusal as grounds to degrade the core service. Consent relates to the processing described in the register; adding a new recipient, purpose, or material type of tracking is accompanied by a new assessment and, where needed, a new choice.
Withdrawal of consent stops future use of the relevant optional technology to the extent technically possible and permitted by law. It does not make processing already lawfully completed before withdrawal unlawful and does not automatically delete data another party has already received on an independent lawful basis. Where applicable law requires recognition of a global privacy signal or comparable opt-out mechanism, Cicora implements it for the relevant practice after reviewing the technical flow.
5. Browser, device, and third-party elements
A user can delete or limit cookies in a browser, reset an advertising identifier, or change permissions in device settings. These steps do not always equal withdrawal of consent in the Cicora interface: a browser can delete a choice record while an application still uses necessary local data for sign-in or security. For optional categories, use both Cicora settings and device tools where appropriate.
Disabling all cookies or local storage can affect sign-in, security, language retention, or individual features. It does not permit Cicora to enable optional analytics or advertising without a basis. Where an external widget, link, payment page, embedded document, or connected service belongs to a third party, that party's technology is governed by its own policy. Review it before visiting or connecting; Cicora does not control those technologies outside its own surface.
6. Retention and security
Session records usually stop operating when the session ends or the needed security period expires. Persistent records remain only for as long as their purpose requires, until a user removes them through an available tool, or until the lawful retention criterion changes. The specific period for each active record is published in the register. Information about a cookie choice and necessary security can be retained longer than the technical identifier where needed to evidence the choice, provide security, or comply with law.
Access to information collected through Cicora technologies is limited by the purpose for which it was collected. We apply measures proportionate to risk but do not guarantee absolute security of a network or user device. Do not enter a password, full card number, CVV, bank code, or other secret into a field not intended for it.
7. Relationship to other data settings
Cookies do not automatically determine whether chat history is retained, memory is used, a file is sent to a Model Provider, or an external connector is available. Those issues are governed by the Privacy Policy, Data Controls, the setting of the particular feature, and the Model and Policy Registry. For example, disabling an analytics cookie does not cancel the transmission of a prompt necessary for a selected provider to perform a request, and consenting to a functional cookie does not authorise use of material for training.
8. Changes and contact
We update this Policy when a technology, recipient, purpose, period, or legal requirement is added, changed, or removed. A material change in optional processing does not apply retroactively to an existing choice: before enabling it, Cicora publishes the updated register and obtains a new user action where required. Cookie questions and requests may be sent to support@cicora.ai or +998 90 051 48 40.