Poliogo
How Poliogo works
Detect & Sync
Code Scanning
Reads package.json and your source to find every service you use.
MCP ServerFor AI editors
Run compliance checks inside Cursor, Claude Code and Windsurf.
No-Code PlatformsNew
Lovable, Bolt.new, v0, Base44, Replit and FlutterFlow.
Drift Monitoring
Add a new service and Poliogo tells you what changed, in plain English.
Automatic Pull RequestsFree plan
Poliogo writes the code and opens a PR. You review and merge.
Generate & Serve
Cookie Banner
Blocks trackers before consent. Geo-aware. Consent Mode v2 and TCF 2.3.
Legal Documents
Privacy Policy, Cookie Policy and Terms of Service.
Privacy Policy
Written from the services your code actually uses — and kept current.
Terms & Conditions
Subscriptions, refunds, liability and user content — fully editable.
Design Customizer
Vibe Presets, brand color auto-detect, and full CSS on Agency.
Accessibility WidgetFree plan
A menu visitors adapt your page with, plus a WCAG 2.2 AA standards scan.
Data Requests (DSAR)
Intake, tracking and deadlines for access and deletion requests.
Trust Center
One public page with your policies. White-label on Agency.
Not sure where to start?Start free — connect a project
Who it's built for
Indie Developers
One subscription covers every side project. MCP built in.
Startups & Product Teams
Daily scans and automatic updates as your product ships.
Agencies & FreelancersWhite-label
Unlimited client sites, your branding, separate client logins.
AI & No-Code BuildersNew
Built for what Lovable, Bolt.new, v0 and Base44 generate.
Managing sites for clients?See agency plans
ConnectorsPricing
Tools & docs
Documentation
MCP setup, CLI commands, config files and API reference.
Setup Guides
Step-by-step instructions for Next.js, Vite, Astro, Remix, SvelteKit and more.
Changelog
What shipped, when — releases, connectors and document updates.
Want us to set it up?Talk to us
About us
About Poliogo
Why we think your policies should keep up with your code.
Security & Trust
What we read, what we keep, and how every clause traces to your code.
Legal Disclaimer
Poliogo is a software tool, not a law firm. What that means for you.
Contact & Support
Real people, same-day replies — and we'll do your setup for you.
Questions from a security team?Get in touch
Sign InStart free — no credit card
Connectors
Pricing
Sign InStart free — no credit card
Contents
  1. Scope
  2. What we mean by "cookies"
  3. Our legal basis for using them
  4. The four categories
  5. What we actually set
  6. Third parties and where the data goes
  7. Managing and withdrawing consent
  8. United States disclosures
  9. Retention and security
  10. Changes
  11. Contact

Poliogo · Legal

Cookie Policy

Effective date: August 7, 2026

Last updated: September 9, 2026

1. Scope

This policy explains how Poliogo uses cookies and similar technologies on poliogo.com and any views embedded in them (together, the "Services"). It applies to everyone who uses them, wherever you are, and it sits alongside our Privacy Policy. Region-specific rights are in section 8.

2. What we mean by "cookies"

"Cookies" here covers every technology that stores or reads data on your device:

  • HTTP cookies — small text files set by us (first-party) or by a provider (third-party).
  • Web storage — localStorage and sessionStorage entries that stay in your browser until they are cleared.

We do not use browser or canvas fingerprinting or CNAME cloaking to disguise third-party tracking as first-party.

3. Our legal basis for using them

Strictly necessary items are set because you asked for a service that cannot work without them (ePrivacy Directive Art. 5(3) exemption; GDPR Art. 6(1)(f)). Everything else is set only after you opt in, and you can withdraw that consent at any time (GDPR Art. 6(1)(a)). In the United States we treat your choices, including the Global Privacy Control signal, as an opt-out of sale and sharing under the CCPA/CPRA and comparable state laws.

We never pre-tick consent boxes, and "Reject all" is always as easy and as prominent as "Accept all".

4. The four categories

CategoryConsentWhat it does
Strictly necessaryNot requiredSign-in, session security, load balancing, remembering your consent choices
Functional and preferencesOpt-inLanguage, region, theme, layout and other choices you have made
Performance and analyticsOpt-inHow many people visit, which features they use, where errors happen
Marketing and targetingOpt-inBuilding interest profiles, retargeting ads, measuring campaign results

Today we use strictly necessary items only.

5. What we actually set

Set by us

NameProviderCategoryPurposeLifespan
__sessionPoliogoStrictly NecessaryCarries the signed token that keeps you signed inUntil you sign out or it expires

We also keep entries in your browser's own storage. The ones that keep you signed in or record your consent are strictly necessary; anything else follows the category it belongs to and is written only after you opt in.

Set by the services we use

NameProviderCategoryPurposeLifespan
__cf_bmCloudflareStrictly NecessaryBot management and abuse prevention30 minutes
firebase:authUser:*FirebaseStrictly NecessaryKeeps you signed in (browser storage, not a cookie)Until you sign out

This schedule is regenerated whenever the services in our product change, so it matches what actually runs.

6. Third parties and where the data goes

The services below act on our behalf. Those that set something on your device are marked as such in section 5; the rest receive data without storing anything here. Any of them may combine what they receive with data they already hold about you:

  • Cloudflare (Cloudflare, Inc.) — CDN, DNS, security filtering and edge compute. Processing location: Edge locations worldwide. Privacy policy: https://www.cloudflare.com/privacypolicy/
  • Firebase (Google LLC) — Sign-in, app data storage and push messaging. Processing location: United States. Privacy policy: https://firebase.google.com/support/privacy
  • PostHog (PostHog, Inc.) — Product analytics and error monitoring, on our public marketing pages only. Sets no cookie and writes nothing to your device: it runs in memory-only mode, so a page reload starts a new anonymous session. It is switched off inside the signed-in product and never runs on a Trust Center served from a customer's own domain. Processing location: European Union. Privacy policy: https://posthog.com/privacy
  • PayPal (PayPal (Europe) S.à r.l. et Cie, S.C.A.) — Subscription billing and payment processing, on the checkout only. Processing location: European Union and United States. Privacy policy: https://www.paypal.com/webapps/mpp/ua/privacy-full

Some of them process data outside your country — processing locations include Edge locations worldwide, the European Union and the United States. Where that means a transfer out of the EEA, the UK or Switzerland, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or the provider's certification under the EU–US Data Privacy Framework.

7. Managing and withdrawing consent

  • Ask us — write to support.polio.ai@gmail.com and we will apply your choice to every non-essential technology listed above.
  • Your browser — Chrome, Safari, Firefox and Edge all let you block or delete cookies. Blocking strictly necessary items will break sign-in.
  • Global Privacy Control — GPC is a signal your browser or an extension can send to ask us not to sell or share your data. We do not read it automatically yet, so please use the controls above.

Whenever we add a technology in a category that needs your permission, we ask before it loads and re-ask at least every 12 months.

8. United States disclosures

Under the CCPA as amended by the CPRA, and comparable laws in Virginia, Colorado, Connecticut, Utah, Texas and Florida:

  • We do not sell personal information for money.
  • We set no analytics or advertising cookies, and we run no advertising technologies at all. The one analytics tool we use runs in memory-only mode on our public marketing pages, stores nothing on your device, and is not used for cross-context behavioural advertising — so no "sale" or "sharing" takes place.
  • We do not knowingly sell or share the personal information of anyone under 16.

9. Retention and security

Lifespans are listed in section 5; none of our own non-essential items lasts longer than 12 months. Consent records are kept for 24 months as proof that consent was given, and are stored encrypted with access limited to the people who need it.

10. Changes

We update this policy when the technologies we use change. The date at the top shows the current version, and we ask for consent again when a change materially affects a category you had turned off.

11. Contact

Questions about this policy, or about any item listed above:

  • Email: support.polio.ai@gmail.com
  • Entity: Poliogo, Israel
  • Website: poliogo.com

Generated by Poliogo from the services detected in this product. Poliogo is a compliance management platform, not a law firm, and this document is not legal advice.

Poliogo

Privacy documents that keep up with your code. We watch what your product uses, propose updates to your policies, and tell you in plain English when one needs your approval.

Product
  • Code Scanning
  • MCP Server
  • Automatic Pull Requests
  • Drift Monitoring
  • Cookie Banner
  • Accessibility Widget
  • Legal Documents
  • Pricing
Solutions
  • Indie Developers
  • Startups & Product Teams
  • Agencies & Freelancers
  • AI & No-Code Builders
Resources
  • Documentation
  • Setup Guides
  • Changelog
  • Connectors
Company
  • About
  • Security & Trust
  • Contact & Support
Legal
  • Legal Disclaimer
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Data Processing Addendum
Alternatives & ComparisonsPoliogo vs TermlyPoliogo vs iubendaPoliogo vs OsanoPoliogo vs Ketch
Cookie Consent by FrameworkNext.jsReactWordPressShopifyVueNuxtSvelteKitAstroAngularRemixLaravelDjangoRuby on RailsWebflowFramerstatic HTML
Compliance by RegulationGDPRUK GDPRCCPA / CPRAEU AI ActCOPPAUS state privacy lawsAmendment 13ePrivacy DirectiveLGPDPIPEDA
Compliance by StackNext.jsSupabaseVercelLovableStripeOpenAIAnthropicClerkFirebasePostHogGoogle AnalyticsMeta PixelMixpanelSentryPineconeResendShopifyNetlifyCloudflareReplitWordPress.com
© 2026 Poliogo Inc. All rights reserved.

Poliogo is an automated code analysis and document display tool, not a law firm. Poliogo does not provide legal advice, representation, or guarantees of statutory compliance, ADA/WCAG certification, or legal immunity. Visual banners and generated documents are advisory tools and do not substitute for professional legal review.

Privacy PolicyTerms of ServiceLegal Disclaimer