Cookie policy

Cookie Policy — SENBridge (England)

Last updated: 10 June 2026
Status: Essential cookies and similar storage only. No advertising or analytics.

Website: https://senbridge.uk
Contact: noreply@senbridge.co.uk
Related: Privacy Policy · Terms of Service


1. Who we are

SENBridge (England) is operated by Sam Connor (sole trader). This policy explains cookies and similar browser storage on https://senbridge.uk (or a temporary host URL during private beta).


2. What are cookies and similar technologies?

  • Cookies — small files on your device set by the website
  • Session storage / local storage — browser storage that is not a cookie but can hold data on your device

We use these to run the Service (sign-in, chat in your tab, optional saved-content notices) — not for advertising.


3. Legal basis (UK)

| Type | Basis | |------|--------| | Strictly necessary cookies (sign-in, security, chat consent enforcement) | Exempt from consent under PECR / UK GDPR — required for the service you request | | Chat session storage | Contract (provide chat in session) and legitimate interests (basic UX) — not used for tracking | | Dismissed notice flags (localStorage) | Legitimate interests / contract — remember choices you made in the app |

If we add non-essential cookies (e.g. analytics), we will ask for consent first and update this policy.


4. Cookies we use

4.1 Authentication session

| Name (typical) | Purpose | Duration | |----------------|---------|----------| | __Secure-next-auth.session-token (production) | Signed-in session | Session cookie (browser closed) or up to 30 days with “Keep me signed in” | | next-auth.session-token (non-production) | Same, development | Same | | NextAuth CSRF cookie (during sign-in only) | Prevents forged login | Minutes — sign-in flow only |

Properties: HTTP-only; Secure in production; SameSite=Lax.

4.2 Chat processing consent (server enforcement)

| Name | Purpose | Duration | |------|---------|----------| | sen-chat-processing-consent | Signed HttpOnly cookie so the API can verify you accepted chat processing consent before messages are sent to AI | Session or short-lived (aligned with consent version) |

A matching sessionStorage key (sen-chat-processing-consent-v1) records acceptance in your tab. Clear chat or a new tab requires fresh acceptance.


5. Browser storage (not cookies)

5.1 Chat in your tab

| Key | Type | Purpose | Duration / limits | |-----|------|---------|-------------------| | sen-chat-session-v1 | sessionStorage | Chat messages and draft input on your device only | Same browser tab — survives page refresh and in-app navigation (e.g. chat → favourites → chat); cleared when you close the tab, Clear chat, sign out, or clear site data. Up to 80 messages; draft input up to 2000 characters | | sen-chat-processing-consent-v1 | sessionStorage | Per-tab chat consent acknowledgement | Until tab closed or consent cleared | | Starter / return-path keys | sessionStorage | In-app navigation helpers | Short-lived |

Important: This may contain personal or sensitive information you type. It is not stored as a full conversation in our database unless you explicitly save favourites or letter drafts.

Shared devices: Anyone with access to the device/browser profile may see in-tab chat until the tab is closed or chat is cleared.

5.2 Favourites UX helpers

| Key | Type | Purpose | Duration | |-----|------|---------|----------| | sen-favourites-first-star-dismissed-v1 | localStorage | Remembers you dismissed the first-save storage notice | Until you clear site data | | sen-letters-first-save-dismissed-v1 | localStorage | Remembers you dismissed the first letter-save storage notice | Until you clear site data | | sen-favourite-pending-restore-v1 | sessionStorage | Restores a pending star after guest sign-in | Short-lived; tab scope |

5.3 Tab-scoped sign-in (without “Keep me signed in”)

| Storage key | Type | Purpose | Duration | |-------------|------|---------|----------| | sen-ephemeral-auth | sessionStorage | Marks tab as owning ephemeral session | Until tab closed | | sen-ephemeral-session-id | sessionStorage + localStorage | Matches tab to login session | Until tab closed or sign-out |


6. What we do NOT use

  • Advertising or retargeting cookies
  • Google Analytics or similar
  • Social media pixels
  • Cross-site tracking
  • Marketing tags

7. Third-party cookies

Core sign-in and chat do not set third-party advertising cookies. Links to external sites (e.g. GOV.UK) have their own policies.

Password-reset emails link back to our site — only our essential cookies apply when you land.


8. How to control storage

| Action | Effect | |--------|--------| | Clear chat (in app) | Clears in-tab chat storage for the current session | | Close the browser tab | Clears sessionStorage chat for that tab | | Sign out | Ends session; clears ephemeral markers and chat consent | | Browser clear site data / cookies | Removes cookies and stored chat | | Block all cookies | Sign-in and chat may break |

Guidance: aboutcookies.org


9. Changes

We will update the Last updated date when this policy changes.


10. Contact

noreply@senbridge.co.uk — privacy and cookies questions. UK GDPR rights: see Privacy Policy.


11. Document history

| Version | Date | Changes | |---------|------|---------| | 1.0 | May 2026 | Initial | | 1.1 | May 2026 | PECR basis, storage limits, ephemeral keys | | 1.2 | 10 Jun 2026 | Chat refresh persistence; processing-consent cookie; favourites notice keys; My letters cross-reference |