Skip to content
SRC AI — Intelligence, Human Authority, Real-World ImpactSRC AI
SRC MentorSRC LaunchWork with SRC AITechnologyWhy SRCAboutInsights
Work with SRC AI

On this page

  1. 1. What cookies and similar storage are
  2. 2. Essential category
  3. 3. Preference category
  4. 4. Analytics category
  5. 5. Marketing category
  6. 6. First-party and third-party distinction
  7. 7. Duration concepts
  8. 8. Consent and changing a choice
  9. 9. Browser controls and signals
  10. 10. AI and support widgets
  11. 11. Inventory source of truth
  12. 12. Contact and updates
  13. 13. Current technical inventory
  14. 14. Protected-service storage
  15. 15. Consent records and proof
  16. 16. New Provider deployment gate
  17. 17. Troubleshooting and questions
  18. 18. Duration, renewal and expiration
  19. 19. Browser signals and device controls
  20. 20. Analytics minimization and measurement quality
  21. 21. Children and family devices
  22. 22. First-party and third-party responsibility
  23. 23. Preference synchronization and account state
  24. 24. Inventory publication and change record

Published legal document

Cookie Policy

Effective date18 August 2026

Last updated17 August 2026

Document size1,663 words · 24 sections

VERSION 3.1

This Cookie Policy explains the browser cookies and similar storage categories used or designed for SRCAI.co. It is aligned with the current consent system and does not list advertising or analytics cookies that are not actually connected. The exact production inventory must be verified whenever hosting, analytics, support or marketing Providers change.

1. What cookies and similar storage are#

Cookies are small values a site asks a browser to store and return. Similar technologies include local storage and protected operational identifiers. Some are necessary to deliver a requested function; others support preferences, measurement or marketing and may require consent depending on location.

2. Essential category#

Essential storage supports protected services, security, abuse prevention and recording a visitor’s privacy choice. It is time-bounded and separated from optional advertising purposes. Essential technology is not used merely to create an advertising audience.

3. Preference category#

A device-local preference can remember whether the visitor selected necessary-only or allowed first-party measurement. This prevents the banner from asking on every page and lets the footer reopen Cookie Settings. Removing browser storage resets the choice. Other preferences should be added to the inventory before use.

4. Analytics category#

Optional first-party measurement may record bounded page and conversion events after permission where consent is required. No external analytics Provider is represented as connected. A future Provider may set its own cookies only after technical review, public inventory and consent configuration.

5. Marketing category#

Advertising and retargeting trackers are not currently connected. A future advertising integration must not set marketing storage merely because it is technically available. Activation requires an approved purpose, Provider terms, retention, consent behavior and withdrawal path.

6. First-party and third-party distinction#

First-party storage is set for the SRCAI.co domain or managed directly for its service. Third-party storage is controlled by another domain or embedded Provider. A link to an external social profile does not itself mean SRCAI.co set that network’s cookie; the network may process information after the visitor follows the link.

7. Duration concepts#

Temporary browser storage ends with its defined browser context. Persistent preferences remain for a bounded period or until removed. Protected operational records follow their approved purpose and retention schedule rather than a marketing-cookie duration.

8. Consent and changing a choice#

Where consent is required, optional analytics or marketing should remain off until the visitor chooses it. Use Cookie Settings in the footer to change optional preferences. Withdrawal applies prospectively and does not delete essential security records or events already processed under a valid basis. The interface must not treat silence as optional consent where law requires a choice.

9. Browser controls and signals#

Browsers can block or delete cookies and storage. Blocking essential storage may prevent a protected service from working or cause the site to ask for a preference again. Global Privacy Control, Do Not Track and platform consent signals should be assessed against applicable production requirements; this candidate does not claim a universal legal interpretation.

10. AI and support widgets#

The current public AI Assistant uses a first-party request and does not require a third-party chat widget cookie. If an external model, support widget or conversation service later adds browser storage, it must be inventoried and categorized before activation. Full Assistant questions are not intentionally stored as cookie values.

11. Inventory source of truth#

The production inventory should be generated from the deployed application, consent component, response headers and connected Provider disclosures. At this milestone the public browser-side item is the device-local consent preference; optional events are processed by the application. Reviews should be repeated before and after every Provider activation.

12. Contact and updates#

Questions, notices, complaints and requests may be sent through the SRC AI contact form. Use the category that best matches the request and provide enough information for SRC AI to identify the relevant interaction. Do not send account credentials, payment-card data, identity documents or other sensitive records through a public form. SRC AI may ask for proportionate evidence of identity or authority through an appropriate protected channel before acting on a request.

A material storage change will be reflected in the version, Effective Date, public inventory and consent interface before or when the new technology is activated as required.

13. Current technical inventory#

The current public design uses a device-local preference to remember the visitor’s optional measurement choice. Public contact, Launch and newsletter submissions do not require an advertising cookie. Protected services and abuse prevention remain separate from marketing identifiers.

The production inventory should record each cookie or storage key, party, purpose, fields, duration, security attributes and triggering choice. A documented category is not evidence that a cookie exists. The inventory must be updated from the deployed implementation whenever a Provider or key changes.

14. Protected-service storage#

Essential storage may support restricted administrative services. It is separated from public advertising purposes, is unavailable as a marketing audience signal and follows bounded operational retention.

Disabling necessary storage can prevent a protected service from working. Security-related storage must not be misclassified or weakened merely to treat it as optional marketing technology.

15. Consent records and proof#

Where consent is required, the system should record enough information to demonstrate the choice and policy version without collecting unnecessary identity. A visitor can reopen Cookie Choices and change the optional preference. Withdrawal should stop future optional collection on that browser after the control is applied, while prior lawful aggregate records may remain according to retention rules.

Consent must not be inferred from silence, a preselected marketing box or simply continuing to browse where the applicable law requires an affirmative act. Necessary storage and consent-exempt measurement, if any, require a documented legal assessment rather than a marketing label.

16. New Provider deployment gate#

Before analytics, advertising, support, video or model widgets set browser storage, SRC AI should inventory the technology, read Provider documentation, configure the least data, test before consent, test withdrawal, update notices and obtain approval. A script must not be classified as essential merely because it is commercially useful.

If a Provider changes names, domains, purposes or durations, the inventory and consent control must be reviewed. Disabled and disconnected Providers should not load client scripts or receive identifiers. Production network inspection is part of the deployment gate.

17. Troubleshooting and questions#

Browser extensions, privacy modes, device policies and automatic deletion can cause a preference not to persist. A visitor may clear storage and choose again. If optional requests occur contrary to a recorded choice, report the page, time, browser and observed domain without sending account secrets.

Questions about a specific identifier can be submitted through the contact route. SRC AI should answer from the deployed inventory and Provider configuration, not a generic cookie catalogue. Material inventory changes should update this policy’s version and date.

18. Duration, renewal and expiration#

A storage duration should reflect purpose. Short-lived protected operational data expires when its purpose ends; a consent preference may last longer so the choice is remembered; optional analytics should not use an indefinite identifier by default. Exact deployed durations belong in the private technical inventory.

Refreshing a page must not silently extend optional marketing storage forever. A material purpose change requires a new assessment and, where required, a new choice rather than resetting the original date.

19. Browser signals and device controls#

Browsers may offer blocking, deletion, private mode, Global Privacy Control, Do Not Track or similar signals. Their legal effect and technical coverage vary. SRC AI should honor a recognized applicable signal when required and document tested behavior rather than promising support for every browser feature.

Device controls can block necessary authentication or remove a preference. Users may choose again through the Website and can contact SRC AI if the interface and observed requests disagree.

20. Analytics minimization and measurement quality#

Optional first-party analytics should use bounded event names, paths, referrers and pseudonymous visit context needed to understand aggregate use. It should not record form message bodies, Assistant questions, confidential access credentials or identity documents. Test and synthetic traffic should be separated from real reporting.

Measurement error is possible when users block storage, share devices or clear preferences. Analytics counts are operational estimates and should not be represented as exact people, customers or revenue without an appropriate method.

21. Children and family devices#

The current public site does not use advertising storage to profile children. A family device can be shared, so a browser preference may reflect the last choice on that device rather than each person. Adults should help younger users avoid entering personal information into public forms.

A future child-oriented SRC Mentor experience requires a specific review of storage, guardian controls, age-appropriate notice and any consent requirement before activation.

22. First-party and third-party responsibility#

First-party storage is set or controlled for SRCAI.co, while third-party storage is controlled by another domain or embedded Provider. The distinction does not determine whether consent is required or a use is harmless. Purpose, data, duration and law must be assessed for each technology.

A Provider can change behavior after integration. SRC AI should monitor material changes and disable or reconfigure a script that no longer matches the approved inventory and notice.

23. Preference synchronization and account state#

The current public preference is device-local and may not follow a visitor to another browser. A future authenticated preference center should explain synchronization and conflict handling before activation. Public marketing choices remain separate from protected access decisions.

Clearing browser storage removes the local evidence of choice and may cause the panel to appear again. It does not unsubscribe an email or delete an enquiry record.

24. Inventory publication and change record#

Authorized governance should review the technical inventory after releases and Provider changes and record material decisions. A public inventory may list safe descriptive fields while keeping security-sensitive implementation detail private. Test environments and production can differ, so verified production behavior is the acceptance source.

A material new optional purpose should update this Policy and consent interface before collection. Historic policy versions remain in the controlled legal system for evidence and review.

← Legal index
SRC AI

Purpose-built intelligence and custom technology for serious real-world outcomes.

24x7

Public products

SRC MentorSRC Launch

Explore

Work with SRC AIPublic information guideTechnologyWhy SRCInsightsNewsletterContact

Trust

Trust CenterAccessibilityLegal

© 2026 SRC AI. Product and project availability is confirmed explicitly. No unsupported outcome is promised.

Cookie Policy | SRC AI