MAMA Request Access
← Back to MAMA

Cookie Policy

Last updated: 2026-08-05

Cookie Policy (Draft for legal review)

Controller: OliWoods LLC (“MAMA”, “we”, “us”)

Site: https://mama.oliwoods.ai

Contact: privacy@oliwoods.ai

Last updated: August 5, 2026

Status: Rough draft for counsel review. Not legal advice. Replace bracketed notes, confirm retention periods with counsel, and re-scan production cookies before publish.

1. What this policy covers

This Cookie Policy explains how MAMA and our service providers use cookies, local storage, session storage, and similar technologies on mama.oliwoods.ai and related product surfaces (dashboard, login, marketplace, Slack-linked flows).

It should be read with our Privacy Policy, Terms of Service, and Data Processing Agreement.

We treat localStorage / sessionStorage / IndexedDB access similarly to cookies for transparency purposes under the ePrivacy Directive and GDPR transparency principles.

2. Who we are

Field Detail
Legal name OliWoods LLC
Product MAMA (Master Autonomous Management Agent)
Primary domain mama.oliwoods.ai
Privacy contact privacy@oliwoods.ai
General contact matt@oliwoods.ai

3. What are cookies and similar technologies?

A cookie is a small text file stored on your device. Local storage and related web storage APIs keep data in the browser until cleared. Some are first-party (set by MAMA); some may be set by processors we use (for example authentication).

4. Categories we use

Category Consent (EEA/UK baseline) Examples on MAMA
Strictly necessary Not required Auth/session, CSRF, security
Functional / preferences Generally required for non-essential prefs Theme preference boot, privacy-mode prefs, onboarding UI flags
Analytics / performance Required if non-essential See §6 — currently no third-party ad/analytics SDKs on the public marketing site
Marketing / advertising Required Not used on mama.oliwoods.ai at last inventory
Social / pixels Required Not used (Slack “Add to Slack” image is a static deep-link asset, not a tracking pixel we control)

5. Strictly necessary (always on when you use the feature)

These are needed to provide a service you request (sign-in, stay signed in, protect forms).

Name / key Type Set by Purpose Typical duration
Supabase Auth session cookies (sb-*-auth-token and related) Cookie (httpOnly where configured) MAMA / Supabase Auth Maintain authenticated session for dashboard & APIs Session / refresh cycle per provider config
access_token / auth_token Cookie (legacy / transition) MAMA Bearer forward for API auth during transition Session / short-lived
csrf_token Cookie MAMA dashboard CSRF protection Session
mfa_device_trust Cookie (signed) MAMA Remember MFA step-up on trusted device Up to ~24h (config-dependent)
Device / geo security signals (server-side) Server logs / DB MAMA Unusual login location checks Per security retention
Waitlist / referral attribution cookies (e.g. campaign correlation) Cookie MAMA Correlate waitlist signup with referral click Short-lived (campaign-dependent)

6. Analytics and product telemetry (current posture)

Public marketing site (mama.oliwoods.ai landing HTML):

At last engineering inventory (August 5, 2026), we do not load Google Analytics, Meta Pixel, Segment, Mixpanel, Plausible, PostHog, or similar third-party marketing analytics SDKs on the public landing pages.

First-party product analytics (authenticated product only):

When you are signed in, MAMA may record first-party operational metrics needed to run the product—for example API usage, cost/usage tracking, command analytics, error digests, and admin control-tower summaries. These are processed as part of providing the service (and, where personal data is involved, under our Privacy Policy / DPA). They are not sold to data brokers and are not used as advertising cookies on the public site.

If we add non-essential analytics later:

We will (1) update this policy with named cookies/providers, (2) obtain consent where required before setting them, and (3) provide an easy way to refuse or withdraw consent. Until then, claims of “we use Google Analytics” would be inaccurate.

7. Functional / preference storage (browser localStorage)

These keys are stored in your browser (not always as HTTP cookies). Clearing site data removes them.

Key Purpose Category
mama_email Remember email for login / soft beta flows Functional / necessary for continuity
mama_token Client-held access token for legacy landing API calls (prefer httpOnly cookies where available) Strictly necessary for those flows
mama_signup_email Prefill waitlist / Stripe payment link correlation Functional
mama_privacy_level Privacy mode preference (standard / local / private) Functional
mama_zk_mode, mama_retention_days, mama_memory_retention_days, mama_llm_source Privacy & LLM routing preferences Functional
mama_llm_keys, mama_ollama_url, mama_ollama_model User-supplied LLM endpoint settings (local) Functional — do not store secrets you are unwilling to keep in browser storage
mama_branding, mama_voice_*, mama_imap UI / integration preferences Functional
mama_onboard_*, mama_onboarding_complete, checklist/tooltip flags Onboarding UX state Functional
mama_pack_submissions, mama_creator_apps Draft submissions in browser Functional
Theme boot System color-scheme preference (we avoid forcing a persisted theme override by default) Functional / necessary for accessible rendering

8. Third parties

Party Role Notes
Supabase Auth, database Session cookies / JWTs per Supabase Auth
Stripe Payments Checkout may set Stripe cookies on stripe.com / checkout domains when you pay
Slack Workspace install OAuth / Slack-hosted flows under Slack’s policies
Anthropic / other LLM providers Model inference Prompt routing per your privacy mode; see Privacy Policy & DPA
Fonts (e.g. Google Fonts) Typography May involve network requests to font CDNs; review network tab in production

Third-party domains they control are governed by their own policies. We link processors in the DPA where applicable.

9. Legal bases (GDPR — EEA/UK users)

Processing Typical legal basis
Strictly necessary cookies Legitimate interests / necessity for contract (service delivery); ePrivacy Art. 5(3) exemption for strictly necessary storage
Functional preferences you set Consent and/or legitimate interests for UI continuity — counsel to confirm
Authenticated product telemetry Contract performance / legitimate interests in operating and securing the service
Future non-essential analytics/marketing Consent before storage

10. Your choices

  1. Browser controls — Block or delete cookies/site data in Chrome, Safari, Firefox, Edge, etc. Blocking strictly necessary cookies may break login and installs.
  2. Sign out — Ends session cookies for authenticated areas.
  3. Privacy settings — Use /privacy-settings for product privacy modes where available.
  4. Do Not Track — We do not currently change behavior solely based on DNT headers; counsel may advise a future CMP.
  5. EEA/UK consent banner — If we introduce non-essential cookies, we will ship a consent mechanism before they fire.

11. Children

MAMA is not directed to children under 16 (or higher age required locally). We do not knowingly set marketing cookies for children.

12. International transfers

Auth and hosting may process data in the United States and other regions. See the Privacy Policy and DPA for transfer mechanisms.

13. Retention

Cookie lifetimes appear in the tables above. Server logs and security events follow operational retention (typically shorter for raw logs; longer for security incidents — counsel to set exact periods). Browser storage lasts until you clear it or we document a shorter TTL.

14. Changes

We will update the “Last updated” date when this policy changes. Material changes (new trackers, new processors) should be called out clearly. Admins may publish updates from the MAMA admin Legal settings; published text is what the live site serves.

15. Contact / complaints

Email privacy@oliwoods.ai.

EEA/UK users may also contact their local supervisory authority. US state privacy requests: see Privacy Policy.

---

Counsel checklist (do not publish as customer-facing)

  • [ ] Confirm OliWoods LLC entity, address, and DPO (if any)
  • [ ] Re-scan production Set-Cookie headers + third-party scripts after next deploy
  • [ ] Decide CMP / consent banner for EEA if any non-essential cookie is added
  • [ ] Align retention numbers with Privacy Policy
  • [ ] Confirm Stripe/Slack/Supabase cookie names from live Network panel
  • [ ] California “share/sell” language if applicable (currently: we do not sell personal information)
About Security Terms Privacy Cookies DPA