Cookie Statement
brainattic uses strictly necessary cookies and security technologies. With your consent, we also use optional first-party browser storage to remember the first campaign source and supported advertising click identifiers during the current public-site and registration journey. We set no Meta Pixel, LinkedIn Insight Tag code, third-party advertising cookie, analytics cookie, or behavioural-tracking cookie. Google reCAPTCHA protects the public contact and self-registration forms against spam, fraud, and abuse. Advertising-conversion delivery is server-side and does not cause Meta or LinkedIn code to run or set advertising cookies in your browser.
The cookies and security technologies we use
The brainattic.ai website and public registration surface use the technologies below to keep sessions and public forms secure. Optional acquisition-attribution storage is set only if you choose it. Fonts and ordinary site assets are served from our own infrastructure. Google reCAPTCHA is the only third-party browser runtime used on these public forms.
| Cookie or technology | Purpose | Duration | Type |
|---|---|---|---|
brainattic-session (session cookie) | Maintains your session so the site works and stays secure | About 2 hours; renewed while you browse | Strictly necessary |
| Optional first-party acquisition-attribution storage | Carries a signed first-source value derived only from the allowed campaign fields: UTM source, medium, campaign, content and term; query-stripped landing path; referring origin limited to scheme and host; and, after consent, supported platform click identifiers derived from fbclid or li_fat_id where present. No unrestricted query string is stored. LinkedIn Campaign Manager may be configured to append li_fat_id to a paid-ad landing URL, but LinkedIn Insight Tag code is not installed on this site. | Current browsing and registration session, approximately 2 hours and renewed while you browse. The resulting server-side record has the separate retention periods stated in the Privacy Policy. | Optional — consent required |
ba-cookie-choice (first-party cookie) | Records whether you accepted or declined the optional acquisition-attribution storage above, so that your answer is honoured and you are not asked again. It is set only when you choose Accept or Decline in the cookie banner or at the site's cookie controls, it holds nothing but that choice, and it is encrypted, Secure, HttpOnly, SameSite=Lax and readable only by this site. | 6 months from the choice; changing or clearing it at the site's cookie controls replaces or removes it sooner | Consent preference — set only by your choice |
XSRF-TOKEN | Protects contact, registration, and application forms against cross-site request forgery | Same as the session | Strictly necessary |
_GRECAPTCHA (set by Google reCAPTCHA) | Supports spam, fraud, and abuse detection on protected public contact and registration forms | Persistent; managed by the reCAPTCHA service | Strictly necessary security |
The brainattic application uses the same kinds of strictly necessary cookies — a session cookie and a CSRF token — to keep you signed in and your session secure. Optional acquisition-attribution storage is not required to contact us, register, sign in, or use the Service. None of these technologies stores your documents or personal profile.
Google reCAPTCHA
The public contact form and, where shown, the self-registration form are protected by Google reCAPTCHA. It loads a Google script, may set the _GRECAPTCHA cookie, and processes information such as your IP address, device/browser or application signals, and interaction signals to assess whether a submission is automated.
Finite Software Systems Ltd. is the controller for this website and account-security processing. Google Cloud EMEA Limited acts as our processor under the Google Cloud Terms and Cloud Data Processing Addendum. We use reCAPTCHA only for form security and prevention of spam, fraud, and abuse — not for analytics, advertising, profiling, or eligibility decisions. Because this is FSS's own security processing, it falls outside the customer DPA and its Annex III.
The reCAPTCHA verification token and Google's raw verification response are processed transiently and are not logged or stored by FSS. We may retain limited operational metadata — such as the time, outcome, score if returned, action, hostname, and a request/correlation identifier — for up to 30 days as part of our security logs.
Consent and your choices
Under the ePrivacy rules, storage or access that is strictly necessary to provide a service requested by the user or to protect that service may be exempt from prior consent. We classify the first-party session and CSRF cookies and the reCAPTCHA security cookie as strictly necessary for the secure operation of the relevant site functions.
Optional acquisition-attribution storage is set only after you opt in. Declining it does not affect contact, registration, sign-in, or use of brainattic; the journey is simply not attributed through that storage. Sending the limited server-side conversion events described in the Privacy Policy to Meta or LinkedIn also requires consent. You can withdraw that choice at any time; withdrawal stops future platform delivery but does not reverse processing already completed by a recipient.
Managing cookies
You can review or change the optional choices through the site's cookie controls and can also block or delete browser storage in your browser settings. Blocking session or CSRF cookies may prevent a form from submitting or the application from keeping you signed in. Blocking Google reCAPTCHA may prevent a protected contact or registration form from being verified; you can still contact us through brainattic.ai/support or at hello@brainattic.ai. Deleting optional acquisition-attribution storage clears the source carried in the current browser journey. Any server-side record already created is retained only for the periods in the Privacy Policy, and withdrawal prevents future Meta and LinkedIn conversion delivery.
Changes & contact
We may update this statement; the "last updated" date will change accordingly. Questions: privacy@brainattic.ai. See also our Privacy Policy.