Legal
Cookie Policy
Last updated 7 September 2026
Corollary uses a small number of cookies and browser storage keys. The ones needed to sign you in are set without asking; analytics and session replay are not set at all unless you accept them.
Strictly necessary — set without consent
These are required to deliver the service you asked for, and the law does not require consent for them. Refusing them is not offered because the site cannot work without them.
- Supabase authentication cookies (sb-…-auth-token and related) — keep you signed in and carry the refresh token. First-party. Duration: the session, and up to one year for the refresh token. Cleared when you sign out.
- corollary-theme (local storage) — remembers light or dark mode. First-party, no expiry, never leaves your browser.
- corollary_ref (cookie) — holds a referral code between following an invitation link and creating an account. First-party, short-lived.
- corollary-analytics-consent (local storage) — records the choice you made about analytics, so we do not ask again and so a refusal is honoured. First-party, no expiry.
- Job history and run outputs (local storage) — your work when signed out, and large structure files at all times. First-party, never transmitted to us.
Analytics and session replay — only with your consent
We use PostHog, acting as our processor, to understand how the demonstration is used and to find what is broken. Nothing below is created unless you accept.
- ph_<token>_posthog (cookie) — distinguishes one browser from another so a sequence of page views can be read as one visit. First-party, set through our own /ingest path. Duration: up to one year.
- PostHog local storage and session storage keys — hold the queue of events waiting to be sent and the current session's replay state. Duration: the session, or until cleared.
- Session replay — a reconstruction of what happened on screen during your visit, together with browser console output and network timings, so a failed run can be diagnosed from what occurred rather than from a guess. Every form field and input is masked before it leaves your browser: replays show that you typed, never what you typed. Sequences, structures, questions to the agent and API keys are never captured.
If your browser sends Global Privacy Control or Do Not Track we treat that as a refusal and never ask. If you reject, or have not answered, PostHog is not loaded or initialised at all — this is not a case of starting and then opting out.
Your choice
You can change your mind at any time, and withdrawing is as easy as giving consent. Withdrawing stops capture and deletes the PostHog cookies already on this device.
Third-party content
Some pages embed or fetch content from public scientific services and CDNs to render structures, molecules and figures. Those requests reveal your IP address to the service concerned, as any web request does. We do not permit third-party advertising or tracking scripts on this site, and there are none.
Blocking cookies yourself
Every major browser lets you block or delete cookies and site data through its settings. Blocking strictly necessary cookies will sign you out and prevent sign-in; blocking the rest has no effect on how the platform works.
Questions about anything on this page: privacy@corollary-labs.com.
Operator and contact
Kernel Science SRL
Via dei Salici 9/09
34151, Trieste (TS)
Italy
Company register: R.E.A.: TS-213649
VAT: P.IVA / C.F.: 01411320326