LUCERIA

Legal

Cookies and similar technologies

Last updated 5 August 2026 · Version 1.2.0

This policy explains how Luceria uses cookies and similar technologies — small files and data stores that sit in your browser or on your device — and how you can control them. It sits alongside our [Privacy Policy](/privacy), which explains everything else we do with your personal data.

We have written this in plain English because many of the people who use Luceria are 16-to-18-year-old school-leavers, as well as students, graduates and others across the job market. If anything here is unclear, please contact us using the details at the end.

The short version:

  • We use only a small set of cookies and device-local storage, and we try to keep it minimal.
  • The things that are strictly necessary to log you in and keep the service working are always on — without them, sign-in and security would break.
  • Everything that is not strictly necessary (our privacy-conscious analytics: Vercel Analytics, Speed Insights, and PostHog) is OFF by default. Nothing non-essential runs until you choose to allow it.
  • We do not use advertising cookies, cross-site trackers, tracking pixels, device fingerprinting, or tag managers. We do not sell your data or use it to target ads.
  • You can change your choices at any time, and rejecting non-essential technologies is exactly as easy as accepting them.

Who is responsible (the data controller)

The controller for the personal data described in this policy is Luceria (the operator of luceria.careers).

  • General/support and privacy questions: [contact Luceria](/contact)
  • Controller / postal address:
  • Data Protection Officer / EU representative: not appointed (not currently required).

If you are in the UK and think we have not handled your data properly, you can complain to the Information Commissioner's Office (ICO) at ico.org.uk — though we'd appreciate the chance to put things right first.

What cookies and similar technologies are

A cookie is a small text file that a website asks your browser to store. When you come back, your browser sends the cookie back, so the site can recognise your session — for example, to keep you logged in.

Cookies are not the only way a website can store or read information on your device. "Similar technologies" is an umbrella term for things that do a comparable job, including:

  • Local storage and session storage — small key/value stores built into your browser. Local storage stays on your device until it is cleared; session storage is wiped when you close the tab. These never leave your device unless code deliberately sends them somewhere.
  • Tracking pixels (web beacons) — tiny invisible images used to detect that a page or email was opened.
  • Scripts, tags and SDKs — pieces of code that run in your browser or app and can set storage or send signals.
  • Tag managers — tools that load lots of other tags from one place.
  • Device fingerprinting — building a hidden "fingerprint" from your device's characteristics (fonts, screen size, hardware) to recognise you without a cookie.
  • Link decoration — adding tracking identifiers onto the end of links so you can be followed between sites.

UK law treats all of these the same way: under the Privacy and Electronic Communications Regulations (PECR) and the UK GDPR, anything that is not strictly necessary to provide the service you asked for needs your consent before it runs.

Importantly, most of the technologies in that list are things Luceria does NOT use. We say exactly which we do use — and which we deliberately avoid — below. We only ever list something as "in use" if it is genuinely present in the product.

The categories we use

We group what we use into three categories. Only the first two are on by default, and neither of those involves analytics or tracking.

1. Strictly necessary (always on). These are essential to deliver the service you have asked for — signing you in, keeping your session secure, remembering your cookie choice itself, and protecting our free public tools from abuse. You cannot turn these off through a consent banner, because the service would not work without them. They do not require consent under PECR, but we still tell you about them here so you know what they do. They are not used for analytics, advertising or tracking you across other websites.

2. Functional / device-local (your settings, kept on your device). These remember your preferences and your in-progress work — your theme, whether the sidebar is open, your dashboard layout, and drafts you are part-way through (for example a resume draft or a chat you have not sent). On Luceria these are almost entirely browser local/session storage, which means they stay on your device and are not transmitted to us as tracking data. Clearing them resets those preferences and can discard unsaved drafts.

3. Analytics (OFF by default — only with your consent). With your consent we use three privacy-conscious tools to understand, at an aggregate level, which features are used, where things break and how quickly pages respond: Vercel Analytics, Vercel Speed Insights, and PostHog (EU cloud). This category is non-essential, so it is switched off until you allow it — the analytics code is not even downloaded to your browser before you consent. None of these tools receives your resume text, names, emails, free text or job descriptions: events are restricted to a fixed allowlist of coarse product facts, page addresses are stripped of identifiers before they are sent, session recording is off, and automatic click/content capture is disabled.

We use no Marketing category at all — there are no advertising or marketing cookies on Luceria, so you will never be asked to consent to one.

The actual cookies and storage we use

The table below lists what Luceria actually sets, based on a review of our code (last verified 5 August 2026). "First-party" means stored under luceria.careers; "third-party" names the provider that processes the data.

Name / familyPurposeCategoryProviderDurationFirst / third-party
sb-* (Supabase auth/session, e.g. sb-<project>-auth-token)Keeps you securely signed in; stores your authenticated session and access/refresh tokens so you don't have to log in on every page. Without it, login does not work.Strictly necessarySupabase (our EU auth/database processor)For as long as you stay signed in (tokens refresh while you use the site); cleared on sign-out.First-party
luceria_consentRemembers the cookie choice you made (accepted or rejected, the policy version, the date, and an anonymous consent id) so we don't keep asking and so the server respects your choice.Strictly necessaryLuceria12 months, then we ask again.First-party
luc_prcFair-use quota for the public scam/risk checker — lets anyone use the free tool a fair number of times while protecting it from abuse, without requiring an account.Strictly necessaryLuceria30 daysFirst-party
luc_prvSame fair-use quota for the public company verification checker.Strictly necessaryLuceria30 daysFirst-party

| luceria:* localStorage keys (representative: luceria:theme, luceria:sidebar-collapsed, luceria:dashboard:mode, resume-draft and chat-draft keys, luceria:cookie-consent:v1 — the local mirror of your consent choice) — ~20 keys in total | Remember your preferences and your in-progress work so the product behaves the way you left it and you don't lose unsaved drafts. Stored on your device only — not transmitted to us as tracking data. | Functional / device-local | Luceria (device-local) | Until you clear them (or clear browser storage). | First-party, device-local | | luceria:* sessionStorage (e.g. a pending workflow-chat prompt, a once-per-session marker) | Temporarily holds something you're part-way through so it isn't lost mid-flow. | Functional / device-local | Luceria (device-local) | Cleared when you close the tab. | First-party, device-local | | Vercel Analytics and Speed Insights (script + beacon; no long-lived identifier cookie) | Privacy-conscious product analytics and anonymous Core Web Vitals. Analytics receives an allowlist of non-PII events only; Speed Insights receives route, browser, device, network, country and performance measurements. Private in-app and sensitive page addresses are excluded, and query strings are stripped, before anything is sent. | Analytics (OFF until you consent) | Vercel | Per Vercel's retention; no cross-site identifier is set. | Third-party (Vercel) | | ph_* (e.g. ph_<project>_posthog cookie + matching localStorage keys) | PostHog (EU cloud) product analytics: a random device id plus our allowlisted events and one "page viewed" event per page, with identifiers stripped from addresses. Loads only after you consent; requests go through our own domain (/ingest) to PostHog's EU servers; session recording is off and automatic capture is disabled. If you withdraw consent we delete every ph_* cookie and storage key from your browser. | Analytics (OFF until you consent) | PostHog (EU cloud) | Up to 12 months, deleted immediately on withdrawal. | First-party storage; PostHog EU processes the data | | Stripe | We use Stripe's redirect-hosted checkout: when you pay, you go to Stripe's own checkout pages, and any cookies involved are set there by Stripe under Stripe's policy. No Stripe script runs and no Stripe cookie is set on luceria.careers itself today. We never receive or store your full card number. | Payment (on Stripe's own pages) | Stripe | Per Stripe's cookie policy (stripe.com/cookies-policy) | Third-party, on Stripe's domain only |

Note on the `luceria:*` device-local keys: the names above are representative examples rather than an exhaustive list. They are functional and stay on your device. We may add or rename keys as features evolve; the categories and behaviour described here continue to apply.

So that we can evidence consent (which UK GDPR requires of us), we keep a minimal server-side record of each banner decision:

  • an anonymous consent id (a random identifier generated in your browser and stored in the luceria_consent cookie),
  • which categories you allowed or refused (today: analytics yes/no),
  • the policy version you decided against, and the time of the decision,
  • for accept/reject/withdraw decisions: a hashed (never raw) network address and a truncated browser user-agent string, as tamper-evidence,
  • your account id, only if you happened to be signed in when you decided — before signup the record is anonymous.

Withdrawing consent is recorded the same way, so the trail shows the full history of your choice. These records are consent evidence, not analytics — they are never sent to any analytics tool. Separately, when you create an account we record which versions of our Terms, Privacy, Cookie and Acceptable-Use policies you accepted (described in our Privacy Policy).

What we do NOT use

To be completely clear, Luceria does not use any of the following:

  • Google Analytics — not used.
  • Advertising or marketing cookies — none. We do not run ads, and we do not use cookies to build advertising profiles or to target ads at you. This matters especially because some of our users are under-18 minors, and we do not profile or target marketing at minors.
  • Cross-site trackers — none. We do not track you across other websites or apps.
  • Device fingerprinting — not used.
  • Session recording / screen replay — switched off in our analytics tooling (it would capture resume content).
  • Tracking pixels / web beacons — not used (including in our email; our service emails are delivered through Resend, and marketing email is not active).
  • Link decoration — not used.
  • Tag managers (e.g. Google Tag Manager) — not used.

We will not silently add advertising or cross-site tracking technologies. If our use of cookies materially changes, we will update this policy and, where the law requires it, ask for your consent again.

Consent banner — non-essential OFF by default. You will see a consent banner before anything non-essential runs. By design:

  • Non-essential technologies are switched OFF by default. Nothing in the analytics category runs — or is even downloaded — until you actively choose to allow it. There are no pre-ticked boxes.
  • Rejecting is exactly as easy as accepting. The banner offers equally-prominent "Reject non-essential" and "Accept all" buttons — the same number of clicks, the same visual weight. We do not use dark patterns, nag screens, or designs that make rejecting harder.
  • Granular choice. The "Preferences" option lets you decide per category rather than all-or-nothing.

Changing your mind at any time. Use the "Cookie settings" link in the footer of any page (or the same control in your account settings area) — it reopens the preferences panel. Withdrawing consent is as easy as giving it and takes effect immediately: analytics stops, and every ph_* analytics cookie and storage key is deleted from your browser.

Where your preference is stored. Your choice is stored in two first-party places so we don't keep asking: the luceria_consent cookie (12 months) and the luceria:cookie-consent:v1 localStorage key. A minimal server-side evidence record is kept as described above. If we materially change what a category covers, the stored decision is treated as expired and we ask you again.

Controlling cookies through your browser. You can also control or delete cookies and clear local/session storage directly in your browser settings — search your browser's help for "clear cookies and site data".

Bear in mind:

  • Clearing or blocking storage will reset your preferences and may discard unsaved drafts held in luceria:* device-local storage.
  • Strictly-necessary cookies cannot be switched off through our banner. If you block the sb-* Supabase cookies in your browser, you will not be able to log in or stay signed in. Blocking luc_prc/luc_prv may stop the public checkers from working correctly.

"Do Not Track" / Global Privacy Control. We do not currently read the DNT or GPC browser signals. Our default is stronger than acting on them: non-essential technologies are off for everyone until you explicitly opt in, and nothing is sold or shared for advertising in any case.

Younger users (16-18)

Luceria's minimum age is 16, and our audience deliberately includes 16-to-18-year-old school-leavers, so some of our users are minors under 18.

Because of that, we apply high-privacy defaults to everyone: non-essential technologies are off by default, we do not profile users or run targeted advertising or marketing to minors, and we minimise the data we collect. We never use cookies or similar technologies to build advertising profiles of young people. If you are a younger user (or a parent/guardian) and have any questions about how this works, please contact us using the details below.

Changes to this policy, version and contact

Changes. We may update this policy as the product changes — for example, if we add a new tool or activate a feature that uses storage. When we make a material change, we update the version and the "last updated" date, and where the law requires it we will ask for your consent again before any new non-essential technology runs.

Version and last-updated. The version number and last-updated date for this policy are managed centrally (in lib/legal/versions.ts) and rendered onto this page, so they always match the version recorded against your consent.

How to contact us.

  • General/support and privacy questions: [contact Luceria](/contact)
  • Controller identity and postal address: see "Who is responsible" at the top of this policy.

You can also find out more about how we handle personal data in our [Privacy Policy](/privacy).