Legal

Cookies Policy

Last updated: 10 July 2026 · Bildr Labs Pty Ltd · ACN 696 230 350 · ABN 80 696 230 350

1. What This Page Covers

This page is a plain-English companion to section 11 of our Privacy Policy. It documents the browser storage currently used by the application and how you can clear or change it. Browser, hosting, authentication, security, and other providers may also set or change technical storage under their current services and policies.

Bildr uses first-party browser storage for authentication, preferences, temporary form progress, onboarding, tutorial state, and interface dismissals. It also uses Vercel Analytics and Sentry as described below. We do not currently use advertising cookies or third-party advertising pixels.

2. Cookies and Storage Set by Bildr

The following items are set directly by Bildr in your browser. All are first-party.

  • Authentication session: set as Supabase authentication cookies (for example, sb-*-auth-token) when you sign in. These keep you logged in between visits and are essential for the service to work. You can clear them by signing out or deleting cookies for bildr.au in your browser settings.
  • Password-recovery check: bildr_recovery_session is a short-lived, HTTP-only cookie set after a valid password-recovery callback. It expires after 15 minutes and is cleared after a successful password change.
  • Consent choice: stored as bildr-consent in localStorage. Records whether you allowed or declined optional Vercel Analytics. It is set only after you make a choice.
  • Onboarding progress: a user-scoped key beginning bildr_onboarding_progress: in localStorage. Stores the answers and form progress entered during onboarding so an interrupted setup can be resumed. It may contain personal and project information and is removed when onboarding completes or when site storage is cleared.
  • Tutorial state: bildr_tutorial_seen, bildr_tutorial_step, and bildr_tutorial_active in localStorage. Records whether the product tour was seen, its current step, and whether tutorial mode is active.
  • Budget-guide dismissals: bildr_budget_guide_dismissed and keys such as bildr_budget_guide_columns_dismissed and bildr_budget_guide_actions_dismissed in localStorage. Remembers which in-app help panels you dismissed.

Key names can change as the application and provider SDKs change. If you see another item associated with bildr.au, contact support for help identifying it; do not assume it contains no personal data.

3. Third-Party Analytics and Diagnostics

Vercel Analytics is optional and consent-gated. Sentry error, performance, and diagnostic telemetry is separate: the Sentry SDK can load without optional analytics consent so the service can detect and diagnose faults. Sentry Session Replay is disabled for the 1.0 launch.

  • Vercel Analytics: loaded only after optional consent to provide page-view and related traffic analytics. Provider processing and technical request data are governed by the active service configuration and Vercel's current policy. (vercel.com/privacy)
  • Sentry error and performance telemetry: can send error details, stack traces, performance spans, request or browser metadata, and a pseudonymous user identifier without optional analytics consent. We disable default PII collection and apply filtering, but cannot guarantee that every event is free of personal information. (sentry.io/privacy)

We do not use Google Analytics, Facebook Pixel, Hotjar, or any other advertising or behavioural tracker.

4. Changing or Revoking Your Consent

Use the permanent control below to allow or withdraw optional analytics consent at any time. The change is saved in this browser and Vercel Analytics mounts or unmounts immediately.

No optional analytics choice has been saved yet. Saving a new choice takes effect immediately in this browser.

You can also use your browser's site-data controls:

  • Clear all Bildr cookies and storage: In your browser settings, find the site settings for bildr.au and choose “clear data” or “clear cookies”. This will log you out and reset your saved consent and progress.
  • Browser-level controls: Browser settings may let you block or clear cookies and site storage. Blocking essential authentication storage can prevent sign-in or other features from working.

Withdrawing optional consent does not disable Sentry error and performance telemetry. Data already collected is retained according to the active provider plan, account settings, and each provider's current policy.

5. Essential vs Optional

Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, we draw a clear line between storage required to deliver the service and storage that is optional:

  • Required for the requested app functions: Supabase authentication cookies and the browser storage used for the preference, progress, tutorial, and interface functions described above. Clearing or blocking an item can reset or disable the related function.
  • Diagnostic telemetry: Sentry error and performance telemetry is not controlled by the optional analytics choice. It is configured to reduce default PII collection but may still process personal information included in an event.
  • Optional (consent-gated): Vercel Analytics. It loads only after you choose “Accept analytics” on the consent banner or “Allow analytics” above.

6. Do Not Track

The current application does not implement a separate response to the legacy Do Not Track (DNT) signal. Use “Necessary only” in the preference control above or on the consent banner to decline optional Vercel Analytics.

7. Changes to This Page

We will update this page when our documented browser storage or third-party telemetry practices materially change. We will provide additional notice or obtain consent where required by applicable law.

8. Contact

For cookies or tracking questions, email us at support@bildr.au. For the full policy covering all personal information handling, see our Privacy Policy.