Skip to content
RegSignal
  • Product
  • Solutions
  • Developers
  • Resources
  • Pricing
Sign inRequest access
  • Product
    • Detect
    • Understand
    • Act
    • Trust
    • All capabilities
  • Solutions
    • Compliance teams
    • Software vendors
    • Consultancies
    • Industries
  • Developers
    • API reference
    • Webhook signatures
    • TypeScript SDK
    • Python SDK
    • OpenAPI spec
  • Resources
    • Coverage
    • Source registry
    • Changelog
    • Service status
    • Trust and security
  • Pricing
Sign inRequest access

Legal

Cookie notice

RegSignal uses only the cookies needed to sign you in and remember your organization, plus a few interface preferences kept in your browser. No analytics, advertising or tracking cookies.

Last updated 2026-09-14

On this page

  1. In short
  2. Cookies
  3. Local storage
  4. What we do not use
  5. How to control them

Draft pending legal review

This document is a working draft for RegSignal’s beta with design partners. It has not been reviewed by counsel and is not yet a binding offer. Text in [brackets] is a placeholder that will be completed before general availability.

1. In short

  • No analytics, advertising or third-party tracking cookies on the marketing site or in the console.
  • Strictly necessary cookies only: Supabase authentication cookies that keep you signed in, and one cookie that remembers which organization you are working in.
  • Local storage for preferences, such as a collapsed sidebar or table columns. It stays in your browser and is not sent to RegSignal.
  • Because everything we set is strictly necessary or a preference you choose, we do not show a consent banner. [Counsel to confirm this for each target jurisdiction.] If we ever add analytics, we will update this notice first and ask for consent where the law requires.

2. Cookies

Cookies set by RegSignal
NamePurposeSet whenDurationType
sb-<project-ref>-auth-token (may be split into .0, .1 and so on when large)Holds your Supabase Auth session so the console knows you are signed in; refreshed on each requestYou sign in to the consoleUp to 400 days, cleared when you sign out; the session inside it expires and refreshes on a much shorter cycleFirst-party, strictly necessary
sb-<project-ref>-auth-token-code-verifierSecures the sign-in handshake for magic links, Google and single sign-on (PKCE)You start signing inRemoved once sign-in completesFirst-party, strictly necessary
rs_orgRemembers the organization you selected, so API calls go to the right organizationYou choose or switch organization1 year, or until you sign out of that organizationFirst-party, strictly necessary

The marketing pages set no cookies unless you are already signed in to the console on the same domain.

3. Local storage

These values live in your browser's local storage on the RegSignal domain. They are read only by the page, are not sent to our servers, and do not identify you.

Local storage keys
KeyWhat it remembersWhere
rs.landing.announcement.v1That you dismissed the announcement barMarketing site
rs_localeYour chosen interface and translation languageConsole
rs.nav.collapsed, rs.nav.closedSidebar collapsed state and closed navigation groupsConsole
rs.table.<table>.density, rs.table.<table>.columnsRow density, column order and hidden columns per tableConsole
rs.views.<surface>.defaultYour default saved viewConsole
rs.home.window, rs.home.setup-banner.hiddenDashboard time window and dismissed setup bannerConsole
rs.integrations.windowTime window on the integration status pageConsole
rs.inbox.tour.v1That you finished the impact inbox tourConsole
rs.profile.<id>.first-run-banner.hidden, rs.profile.<id>.analysis.doneDismissed banner and checked-off analysis items per product profileConsole
rs.ask.recentThe last few questions you asked from this browser, so you can repeat themConsole

rs.ask.recent contains the text of your recent questions. If you use a shared computer, clear it by signing out and clearing site data for the RegSignal domain.

4. What we do not use

  • No analytics tools (such as Google Analytics or product analytics SDKs), advertising pixels, social media widgets or session recording.
  • Error monitoring through Sentry reports exceptions without setting cookies, with personal data collection off and session replay disabled.
  • Web fonts are bundled and served from RegSignal's own domain, so your browser does not contact a font provider when pages load.

5. How to control them

You can delete cookies and local storage for the RegSignal domain in your browser settings at any time. Blocking the authentication cookies prevents you from signing in to the console; clearing local storage only resets your preferences.

Questions about this notice: [Privacy contact email]. The Privacy Policy explains how we handle personal data more broadly.

Other documents

  • Terms of Service
  • Privacy Policy
  • Data Processing Addendum
  • Acceptable Use Policy
  • Subprocessors
  • Beta program
RegSignal

Product

  • Overview
  • Detect
  • Understand
  • Act
  • Trust
  • All capabilities

Jurisdictions

  • United States
  • European Union
  • United Kingdom
  • India
  • Japan
  • All 21 jurisdictions

Solutions

  • Compliance teams
  • Software vendors
  • Consultancies
  • Industries
  • Pricing

Developers

  • API reference
  • Webhook signatures
  • TypeScript SDK
  • Python SDK
  • OpenAPI spec

Resources

  • Coverage
  • Source registry
  • Changelog
  • Service status
  • Request access

Company

  • About
  • Contact
  • Trust
  • Security contact
  • Enterprise
  • Log in

Legal

  • Terms of Service
  • Privacy Policy
  • DPA
  • Acceptable use
  • Subprocessors
  • Cookie notice
  • Beta program

  • Terms
  • Privacy
  • Cookies
  • Security

© 2026 RegSignal. All rights reserved