Cookie Policy
Last updated: 10 August 2026
This Cookie Policy is issued by Nexus Generated FZ-LLC, a free zone limited liability company licensed by the Ras Al Khaimah Economic Zone (RAKEZ), License No. 5034603, with registered address at VUET1700, Compass Building - Al Hulaila, Al Hulaila Industrial Zone-FZ, Ras Al Khaimah, United Arab Emirates ("Nexus Generated", "we", "us").
It explains what cookies and similar technologies (such as browser local storage) we use, why we use them, and how you can control them. It covers:
- odiseo.ai — our own website and the Odiseo application (the "Platform"), where we act as the data controller; and
- the Odiseo embedded widget — the chat bubble our clients place on their websites. On a client's site, the client is the data controller and we act as their processor. This Policy describes the widget's cookie behavior for transparency; the client's own cookie and privacy notices govern their site.
This Policy should be read together with our Privacy Policy, which explains how we handle personal data more broadly.
1. What cookies are
Cookies are small text files that a website stores on your device. Local storage is a similar browser feature that keeps small pieces of data on your device without sending them with every request. We use both, and this Policy refers to them together as "cookies" unless the distinction matters.
Cookies can be:
- First-party — set by the site you are visiting. All cookies described in this Policy are first-party in this sense: they are set by the Platform or by the widget serving the page you are on.
- Session or persistent — deleted when you close your browser, or kept until they expire or you delete them.
- Strictly necessary, functional, or analytics — depending on their purpose, as described below.
We do not use advertising cookies. We do not use cookies to track you across other websites. We do not sell data derived from cookies.
2. The cookies we use
2.1 Strictly necessary — authentication (Clerk)
If you sign in to the Platform, our authentication provider, Clerk, sets session cookies that keep you signed in and protect your account (for example, against session hijacking and cross-site request forgery). Without these cookies, signing in is not possible.
- Purpose: authentication and account security
- Type: strictly necessary, first-party
- Consent: not required — the Platform cannot function without them
- Duration: session cookies set by our authentication provider; they expire according to your session's lifetime
2.2 Strictly necessary — widget visitor identity
When a visitor on a client's website (or on odiseo.ai) opens the Odiseo chat bubble, the widget sets a single, cryptographically signed identity cookie. Its only job is continuity: it lets the AI employee recognize a returning visitor so the conversation can pick up where it left off, instead of starting from zero every visit.
Key properties, by design:
- It does not exist until you open the bubble. Merely loading a page with the widget on it sets nothing. If you never click the chat bubble, this cookie is never created.
- The identifier is minted by our server and signed. It cannot be chosen or forged by the browser, and a tampered value is rejected.
- It is scoped to the site you are on. It is not shared between different clients' websites and is not used to follow you from one site to another.
- No advertising, no profiling for ads, no cross-site tracking. The cookie carries an opaque identifier only — no name, email, or browsing history.
- Duration: 180 days, renewed on return visits (sliding window)
On a client's website, this cookie is set in the course of providing our service to that client, who is the controller of their visitors' data. For visitors of a client's website, the website owner's privacy policy governs; visitors who want their conversation data deleted should contact the website owner, and deletion requests flow through our Data Processing Agreement (Section 8 of that agreement).
2.3 Functional — language preference
We store a locale preference so the Platform and widget appear in your language without asking on every visit.
- Purpose: remembering your language choice
- Type: functional, first-party
- Content: a language/region code only (e.g. "es", "en")
- Duration: one year
2.4 Analytics — PostHog
We use PostHog to understand how the Platform is used — which pages are visited, where users run into friction — so we can improve the product. PostHog may use cookies or local storage to distinguish visitors and sessions.
- Purpose: product analytics (aggregate usage understanding, not advertising)
- Type: analytics
- What it is not: we do not use PostHog for ad targeting, and we do not share analytics identifiers with advertising networks.
A consent banner for EU visitors is being implemented. Until it ships, analytics may run without a prior consent gate; once live, analytics cookies for EU visitors will only be set after you consent.
3. Cookies we do not use
For clarity — as a statement of our own current practice — on the Platform and in the widget we do not deploy:
- third-party advertising or retargeting cookies;
- social media tracking pixels;
- cross-site or cross-device tracking identifiers;
- fingerprinting techniques as a substitute for the cookies described above.
4. How to control or refuse cookies
Consent choices. Where a consent banner is shown (see Section 2.4), you can accept or refuse non-essential cookies there, and change your choice later through the same mechanism.
Browser settings. Every major browser lets you block or delete cookies, block third-party cookies, or clear local storage. See your browser's help pages (commonly under "Privacy" or "Site settings"). You can also browse in private/incognito mode, which discards cookies when the window closes.
What happens if you refuse or delete them:
- Deleting or blocking the Clerk session cookies signs you out and prevents you from signing back in while they remain blocked.
- Deleting the widget identity cookie means the AI employee will treat you as a new visitor: your previous conversation will not be resumed in the widget. Simply never opening the chat bubble also means the cookie is never set.
- Deleting the locale cookie resets your language preference.
- Refusing analytics cookies has no effect on functionality — the Platform works fully without them.
Do Not Track / Global Privacy Control. We honor Global Privacy Control (GPC) signals for analytics where they apply.
5. Legal bases and your rights
Depending on where you are, the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) and, for visitors in the European Union, the GDPR and ePrivacy rules apply to our use of cookies. Strictly necessary cookies rest on our legitimate need to deliver the service you request; analytics cookies rest on consent where the law requires it.
Your rights over personal data processed via cookies (access, deletion, objection, and others) are described in our Privacy Policy. For conversations held through the widget on a client's website, the website owner is the controller — direct requests to them, and we will support them as their processor.
6. Changes to this Policy
We may update this Policy as the product or the law changes — for example, if we add or remove a cookie. The "Last updated" date at the top reflects the current version. For material changes affecting consent, we will re-request consent where required.
7. Contact
Questions about this Cookie Policy can be sent to:
Nexus Generated FZ-LLC RAKEZ License No. 5034603 VUET1700, Compass Building - Al Hulaila, Al Hulaila Industrial Zone-FZ, Ras Al Khaimah, United Arab Emirates
Email: legal@odiseo.ai