Cookie Policy

Cookie Policy (Draft for legal review)

Controller: OliWoods LLC (“MAMA”, “we”, “us”)

Site: https://mama.oliwoods.ai

Contact: privacy@oliwoods.ai

Last updated: August 5, 2026

Status: Rough draft for counsel review. Not legal advice. Replace bracketed notes, confirm retention periods with counsel, and re-scan production cookies before publish.

1. What this policy covers

This Cookie Policy explains how MAMA and our service providers use cookies, local storage, session storage, and similar technologies on mama.oliwoods.ai and related product surfaces (dashboard, login, marketplace, Slack-linked flows).

It should be read with our Privacy Policy, Terms of Service, and Data Processing Agreement.

We treat localStorage / sessionStorage / IndexedDB access similarly to cookies for transparency purposes under the ePrivacy Directive and GDPR transparency principles.

2. Who we are

3. What are cookies and similar technologies?

A cookie is a small text file stored on your device. Local storage and related web storage APIs keep data in the browser until cleared. Some are first-party (set by MAMA); some may be set by processors we use (for example authentication).

4. Categories we use

5. Strictly necessary (always on when you use the feature)

These are needed to provide a service you request (sign-in, stay signed in, protect forms).

6. Analytics and product telemetry (current posture)

Public marketing site (mama.oliwoods.ai landing HTML):

At last engineering inventory (August 5, 2026), we do not load Google Analytics, Meta Pixel, Segment, Mixpanel, Plausible, PostHog, or similar third-party marketing analytics SDKs on the public landing pages.

First-party product analytics (authenticated product only):

When you are signed in, MAMA may record first-party operational metrics needed to run the product—for example API usage, cost/usage tracking, command analytics, error digests, and admin control-tower summaries. These are processed as part of providing the service (and, where personal data is involved, under our Privacy Policy / DPA). They are not sold to data brokers and are not used as advertising cookies on the public site.

If we add non-essential analytics later:

We will (1) update this policy with named cookies/providers, (2) obtain consent where required before setting them, and (3) provide an easy way to refuse or withdraw consent. Until then, claims of “we use Google Analytics” would be inaccurate.

7. Functional / preference storage (browser localStorage)

These keys are stored in your browser (not always as HTTP cookies). Clearing site data removes them.

8. Third parties

Third-party domains they control are governed by their own policies. We link processors in the DPA where applicable.

9. Legal bases (GDPR — EEA/UK users)

10. Your choices

  1. Browser controls — Block or delete cookies/site data in Chrome, Safari, Firefox, Edge, etc. Blocking strictly necessary cookies may break login and installs.
  2. Sign out — Ends session cookies for authenticated areas.
  3. Privacy settings — Use /privacy-settings for product privacy modes where available.
  4. Do Not Track — We do not currently change behavior solely based on DNT headers; counsel may advise a future CMP.
  5. EEA/UK consent banner — If we introduce non-essential cookies, we will ship a consent mechanism before they fire.

11. Children

MAMA is not directed to children under 16 (or higher age required locally). We do not knowingly set marketing cookies for children.

12. International transfers

Auth and hosting may process data in the United States and other regions. See the Privacy Policy and DPA for transfer mechanisms.

13. Retention

Cookie lifetimes appear in the tables above. Server logs and security events follow operational retention (typically shorter for raw logs; longer for security incidents — counsel to set exact periods). Browser storage lasts until you clear it or we document a shorter TTL.

14. Changes

We will update the “Last updated” date when this policy changes. Material changes (new trackers, new processors) should be called out clearly. Admins may publish updates from the MAMA admin Legal settings; published text is what the live site serves.

15. Contact / complaints

Email privacy@oliwoods.ai.

EEA/UK users may also contact their local supervisory authority. US state privacy requests: see Privacy Policy.

---

Counsel checklist (do not publish as customer-facing)

  • [ ] Confirm OliWoods LLC entity, address, and DPO (if any)
  • [ ] Re-scan production Set-Cookie headers + third-party scripts after next deploy
  • [ ] Decide CMP / consent banner for EEA if any non-essential cookie is added
  • [ ] Align retention numbers with Privacy Policy
  • [ ] Confirm Stripe/Slack/Supabase cookie names from live Network panel
  • [ ] California “share/sell” language if applicable (currently: we do not sell personal information)