Cookie Policy
Last Updated: 05 July 2026
1. Introduction
This Cookie Policy explains how Regulus ("we", "our", or "us") uses cookies and similar technologies when you visit our website at regulus.ai (the "Website") and use our services.
This policy should be read together with our Privacy Policy and Terms of Use.
2. What Are Cookies?
Cookies are small text files that are placed on your device (computer, smartphone, tablet) when you visit a website. They are widely used to make websites work more efficiently and provide information to website owners.
Cookies can be "session" cookies (temporary, deleted when you close your browser) or "persistent" cookies (remain on your device for a set period or until you delete them).
3. Cookies We Use
3.1 Strictly Necessary Cookies
These cookies are essential for the operation of our Website and services. Without these cookies, the services you have requested cannot be provided.
| Cookie Name | Purpose | Duration |
|---|---|---|
| XSRF-TOKEN | Security - protects against Cross-Site Request Forgery attacks | 2 hours |
| regulus_session | Maintains your logged-in session | 2 hours |
| remember_web_* | "Remember me" functionality when you choose to stay logged in | 5 years |
| regulus_aff_ref | Records which affiliate link you arrived from so we can attribute any subsequent subscription to the referring affiliate. Set only on first visit via an affiliate link; not overwritten on return visits (first-touch attribution). The IP address used to set this cookie is stored only as a one-way SHA-256 hash and cannot be reversed to identify you. | 30 days |
Legal Basis: These cookies are necessary for the performance of our contract with you (Article 6(1)(b) UK GDPR).
3.2 Browser Storage (Not Cookies)
In addition to cookies, we use browser local storage for certain preferences:
| Storage Item | Purpose | Type |
|---|---|---|
| theme_preference | Remembers your dark/light mode preference | LocalStorage |
Note: LocalStorage is not a cookie and remains on your device until you clear your browser data. Legal Basis: Legitimate interests (Article 6(1)(f) UK GDPR) - improving user experience.
3.3 Third-Party Cookies
We use limited third-party services that may set cookies on our behalf:
| Service | Purpose | Privacy Policy |
|---|---|---|
| Stripe | Payment processing and fraud prevention | View Policy |
Legal Basis: Contract performance for payment processing (Article 6(1)(b) UK GDPR).
4. Analytics & Marketing Cookies
The cookies in this section are written by the analytics and advertising tags we run. Each is gated behind your active consent — none of them fire until you click "Accept analytics" in the cookie banner. Clicking "Reject analytics" prevents every tracker listed below from loading.
Google Analytics 4
Measure how visitors find and use the website so we can improve content, fix friction in signup, and decide where to invest marketing spend.
Data collected:
- Anonymised IP address (the last octet is masked before storage)
- Page URL and referrer URL
- Device type, browser, and operating system (aggregated)
- Engagement events including page_view, sign_up, view_item, begin_checkout and purchase (no payment card data is transmitted)
| Cookie Name | Purpose | Duration |
|---|---|---|
| _ga | Distinguishes unique visitors (random ID — no personal data) | 2 years |
| _ga_XXXXXXXX | Maintains session state for the GA4 property | 2 years |
Third-party recipients:
- Google Ireland Limited — Ireland (EEA). Privacy policy
- Google LLC — United States (transfers under EU-US/UK Data Privacy Framework + SCCs). Privacy policy
Legal Basis: Your consent (Article 6(1)(a) UK GDPR). This tracker is only activated after you click "Accept analytics" in our cookie banner. You can withdraw consent at any time via the link in the footer.
First-party analytics
Measure how visitors discover and use the service so we can decide where to invest marketing effort, detect abuse, and reduce friction in the signup and subscription flow. All data is stored on our own infrastructure; nothing is shared with third parties by this system.
Data collected:
- Event name (e.g. signup, email_verified, subscription_started) — never the message content of any chat
- Anonymous visitor identifier (a random UUID set in the visitor_id cookie)
- UTM parameters present on the URL when you arrive (utm_source, utm_medium, utm_campaign, utm_content, utm_term)
- Referring URL of the page you arrived from (captured once per session, then frozen)
- A one-way SHA-256 hash of your IP address (the salt rotates on each deploy — the hash cannot be reversed to identify you)
- User-Agent string (browser, operating system) — truncated at 500 characters
| Cookie Name | Purpose | Duration |
|---|---|---|
| visitor_id | Anonymous identifier (UUID) for stitching pre- and post-signup actions of the same browser into a single funnel row. Cannot be used to identify you by name or contact details; not shared with any third party. | 1 year |
Legal Basis: Legitimate interests (Article 6(1)(f) UK GDPR).
In addition to the per-tracker cookies listed in this section, we set
cookie_consent_v1 (1 year retention) to remember your accept/reject choice so the banner is not shown on every visit. You can change your decision at any time via the
link in the footer.
5. Cookieless Analytics (Ahrefs Web Analytics)
On our public marketing pages we load Ahrefs Web Analytics, a cookieless analytics service provided by Ahrefs Pte. Ltd. Ahrefs Web Analytics does not set cookies on your device, does not use browser fingerprinting, and does not collect personally identifiable information. It records aggregated information about page URL, referring page, country, and device type so we can understand how visitors find and use the Website.
Legal Basis: Legitimate interests (Article 6(1)(f) UK GDPR) - measuring and improving the Website. Because the service does not store or read information on your device, the consent requirement under regulation 6 of the Privacy and Electronic Communications Regulations (PECR) does not apply.
How to object: You can object to processing under legitimate interests at any time by emailing us (see section 9). You can also block the script using browser content-blocking extensions, or by enabling your browser's "Do Not Track" or "Global Privacy Control" signal. Ahrefs' privacy notice is available at https://ahrefs.com/privacy.
Things we do not use
Regulus does NOT use:
- Behavioural profiling cookies that build psychographic profiles of you
- Adtech cookies from third-party advertising networks beyond the two named platforms (Meta and LinkedIn) listed in section 4
- Session-replay or heatmap recording tools
6. How to Manage Cookies
6.1 Browser Settings
Most web browsers allow you to control cookies through their settings. You can:
- Delete all cookies from your browser
- Block all cookies from being set
- Allow only first-party cookies (blocking third-party cookies)
- Clear cookies when you close your browser
Browser-Specific Instructions:
- • Chrome: Settings → Privacy and Security → Cookies
- • Firefox: Options → Privacy & Security → Cookies and Site Data
- • Safari: Preferences → Privacy → Cookies and website data
- • Edge: Settings → Cookies and site permissions → Cookies
6.2 Impact of Blocking Cookies
⚠️ Important: If you block or delete our strictly necessary cookies, you will not be able to:
- Log in to your account
- Access your conversation history
- Use our AI assistant service
- Manage your subscription
7. Cookie Duration
Session Cookies
Deleted automatically when you close your browser. Used for essential functionality like maintaining your login session.
Persistent Cookies
Remain on your device for a set period. Used for "remember me" functionality and preferences. Maximum duration: 5 years (for "remember me" feature).
8. Updates to This Policy
We may update this Cookie Policy from time to time to reflect changes in technology, legislation, or our practices. We will notify you of significant changes by:
- Updating the "Last Updated" date at the top of this page
- Displaying a notice on our Website
- Sending an email to registered users (for material changes)
9. More Information
About Cookies
For more information about cookies, visit:
Related Policies
- Privacy Policy - How we collect and use your personal data
- Terms of Use - Terms governing your use of our services
10. Contact Us
If you have questions about our use of cookies, please contact:
Ask Regulus Ltd (trading as Regulus)
Registered Address: County House, St. Marys Street, Worcester, WR1 1HB
Company Registration: 16676659
VAT Registration: 500162456
Email: privacy@askregulus.co.uk
The strictly necessary cookies described in section 3.1 (CSRF protection and session management) do not require your consent under PECR, as they are essential for services you have actively requested. Google Analytics 4 cookies (section 4) require and only activate upon your explicit consent.