Cookie Policy (Draft for legal review)
Controller: OliWoods LLC (“MAMA”, “we”, “us”)
Site: https://mama.oliwoods.ai
Contact: privacy@oliwoods.ai
Last updated: August 5, 2026
Status: Rough draft for counsel review. Not legal advice. Replace bracketed notes, confirm retention periods with counsel, and re-scan production cookies before publish.
1. What this policy covers
This Cookie Policy explains how MAMA and our service providers use cookies, local storage, session storage, and similar technologies on mama.oliwoods.ai and related product surfaces (dashboard, login, marketplace, Slack-linked flows).
It should be read with our Privacy Policy, Terms of Service, and Data Processing Agreement.
We treat localStorage / sessionStorage / IndexedDB access similarly to cookies for transparency purposes under the ePrivacy Directive and GDPR transparency principles.
2. Who we are
| Field | Detail |
|---|---|
| Legal name | OliWoods LLC |
| Product | MAMA (Master Autonomous Management Agent) |
| Primary domain | mama.oliwoods.ai |
| Privacy contact | privacy@oliwoods.ai |
| General contact | matt@oliwoods.ai |
3. What are cookies and similar technologies?
A cookie is a small text file stored on your device. Local storage and related web storage APIs keep data in the browser until cleared. Some are first-party (set by MAMA); some may be set by processors we use (for example authentication).
4. Categories we use
| Category | Consent (EEA/UK baseline) | Examples on MAMA |
|---|---|---|
| Strictly necessary | Not required | Auth/session, CSRF, security |
| Functional / preferences | Generally required for non-essential prefs | Theme preference boot, privacy-mode prefs, onboarding UI flags |
| Analytics / performance | Required if non-essential | See §6 — currently no third-party ad/analytics SDKs on the public marketing site |
| Marketing / advertising | Required | Not used on mama.oliwoods.ai at last inventory |
| Social / pixels | Required | Not used (Slack “Add to Slack” image is a static deep-link asset, not a tracking pixel we control) |
5. Strictly necessary (always on when you use the feature)
These are needed to provide a service you request (sign-in, stay signed in, protect forms).
| Name / key | Type | Set by | Purpose | Typical duration |
|---|---|---|---|---|
Supabase Auth session cookies (sb-*-auth-token and related) |
Cookie (httpOnly where configured) | MAMA / Supabase Auth | Maintain authenticated session for dashboard & APIs | Session / refresh cycle per provider config |
access_token / auth_token |
Cookie (legacy / transition) | MAMA | Bearer forward for API auth during transition | Session / short-lived |
csrf_token |
Cookie | MAMA dashboard | CSRF protection | Session |
mfa_device_trust |
Cookie (signed) | MAMA | Remember MFA step-up on trusted device | Up to ~24h (config-dependent) |
| Device / geo security signals (server-side) | Server logs / DB | MAMA | Unusual login location checks | Per security retention |
| Waitlist / referral attribution cookies (e.g. campaign correlation) | Cookie | MAMA | Correlate waitlist signup with referral click | Short-lived (campaign-dependent) |
6. Analytics and product telemetry (current posture)
Public marketing site (mama.oliwoods.ai landing HTML):
At last engineering inventory (August 5, 2026), we do not load Google Analytics, Meta Pixel, Segment, Mixpanel, Plausible, PostHog, or similar third-party marketing analytics SDKs on the public landing pages.
First-party product analytics (authenticated product only):
When you are signed in, MAMA may record first-party operational metrics needed to run the product—for example API usage, cost/usage tracking, command analytics, error digests, and admin control-tower summaries. These are processed as part of providing the service (and, where personal data is involved, under our Privacy Policy / DPA). They are not sold to data brokers and are not used as advertising cookies on the public site.
If we add non-essential analytics later:
We will (1) update this policy with named cookies/providers, (2) obtain consent where required before setting them, and (3) provide an easy way to refuse or withdraw consent. Until then, claims of “we use Google Analytics” would be inaccurate.
7. Functional / preference storage (browser localStorage)
These keys are stored in your browser (not always as HTTP cookies). Clearing site data removes them.
| Key | Purpose | Category |
|---|---|---|
mama_email |
Remember email for login / soft beta flows | Functional / necessary for continuity |
mama_token |
Client-held access token for legacy landing API calls (prefer httpOnly cookies where available) | Strictly necessary for those flows |
mama_signup_email |
Prefill waitlist / Stripe payment link correlation | Functional |
mama_privacy_level |
Privacy mode preference (standard / local / private) | Functional |
mama_zk_mode, mama_retention_days, mama_memory_retention_days, mama_llm_source |
Privacy & LLM routing preferences | Functional |
mama_llm_keys, mama_ollama_url, mama_ollama_model |
User-supplied LLM endpoint settings (local) | Functional — do not store secrets you are unwilling to keep in browser storage |
mama_branding, mama_voice_*, mama_imap |
UI / integration preferences | Functional |
mama_onboard_*, mama_onboarding_complete, checklist/tooltip flags |
Onboarding UX state | Functional |
mama_pack_submissions, mama_creator_apps |
Draft submissions in browser | Functional |
| Theme boot | System color-scheme preference (we avoid forcing a persisted theme override by default) | Functional / necessary for accessible rendering |
8. Third parties
| Party | Role | Notes |
|---|---|---|
| Supabase | Auth, database | Session cookies / JWTs per Supabase Auth |
| Stripe | Payments | Checkout may set Stripe cookies on stripe.com / checkout domains when you pay |
| Slack | Workspace install | OAuth / Slack-hosted flows under Slack’s policies |
| Anthropic / other LLM providers | Model inference | Prompt routing per your privacy mode; see Privacy Policy & DPA |
| Fonts (e.g. Google Fonts) | Typography | May involve network requests to font CDNs; review network tab in production |
Third-party domains they control are governed by their own policies. We link processors in the DPA where applicable.
9. Legal bases (GDPR — EEA/UK users)
| Processing | Typical legal basis |
|---|---|
| Strictly necessary cookies | Legitimate interests / necessity for contract (service delivery); ePrivacy Art. 5(3) exemption for strictly necessary storage |
| Functional preferences you set | Consent and/or legitimate interests for UI continuity — counsel to confirm |
| Authenticated product telemetry | Contract performance / legitimate interests in operating and securing the service |
| Future non-essential analytics/marketing | Consent before storage |
10. Your choices
- Browser controls — Block or delete cookies/site data in Chrome, Safari, Firefox, Edge, etc. Blocking strictly necessary cookies may break login and installs.
- Sign out — Ends session cookies for authenticated areas.
- Privacy settings — Use /privacy-settings for product privacy modes where available.
- Do Not Track — We do not currently change behavior solely based on DNT headers; counsel may advise a future CMP.
- EEA/UK consent banner — If we introduce non-essential cookies, we will ship a consent mechanism before they fire.
11. Children
MAMA is not directed to children under 16 (or higher age required locally). We do not knowingly set marketing cookies for children.
12. International transfers
Auth and hosting may process data in the United States and other regions. See the Privacy Policy and DPA for transfer mechanisms.
13. Retention
Cookie lifetimes appear in the tables above. Server logs and security events follow operational retention (typically shorter for raw logs; longer for security incidents — counsel to set exact periods). Browser storage lasts until you clear it or we document a shorter TTL.
14. Changes
We will update the “Last updated” date when this policy changes. Material changes (new trackers, new processors) should be called out clearly. Admins may publish updates from the MAMA admin Legal settings; published text is what the live site serves.
15. Contact / complaints
Email privacy@oliwoods.ai.
EEA/UK users may also contact their local supervisory authority. US state privacy requests: see Privacy Policy.
---
Counsel checklist (do not publish as customer-facing)
- [ ] Confirm OliWoods LLC entity, address, and DPO (if any)
- [ ] Re-scan production Set-Cookie headers + third-party scripts after next deploy
- [ ] Decide CMP / consent banner for EEA if any non-essential cookie is added
- [ ] Align retention numbers with Privacy Policy
- [ ] Confirm Stripe/Slack/Supabase cookie names from live Network panel
- [ ] California “share/sell” language if applicable (currently: we do not sell personal information)