1. Scope
This Cookie Policy explains how Spek, operated by RELOAD TECHNOLOGIES - FZCO in Dubai, United Arab Emirates, uses cookies and similar browser storage on its websites and applications (the "Service"). It should be read with the Privacy Policy.
2. Storage technologies
A cookie is a small value a website asks a browser to store and send with later requests. Local storage is browser storage that remains on a device and is read by client-side code; unlike a cookie, it is not automatically sent with each network request.
Spek uses these technologies to keep users signed in, complete an requested subscription purchase, remember the active workspace, retain a requested theme, and preserve browser-side copies of agent workflow and rule settings.
3. Authentication storage
Authentication cookies maintain sessions, refresh access, and complete supported sign-in callbacks. They commonly use an sb- prefix with an auth-token identifier and may include related verifier or numbered chunk cookies.
Their names and lifetimes vary with the relevant authentication session and sign-in flow. These cookies use Secure and SameSite=Lax attributes.
4. Billing intent cookie
The spek_billing_intent cookie, named __Host-spek_billing_intent in production, temporarily carries an opaque purchase capability between Spek's subscription review and Stripe Checkout. The cookie does not contain a card number, price, workspace name, or Stripe secret. The server revalidates its user, plan, cycle, expiry, and active-workspace relationship before creating Checkout.
This strictly necessary first-party cookie is HttpOnly, uses SameSite=Lax and Path=/, uses Secure in production, and expires after one hour unless it is replaced or cleared earlier.
5. Active workspace cookie
The aso_active_workspace cookie records the workspace selected by an authenticated user so the Service can resolve subsequent requests in the correct authorized workspace. It is an essential or functional first-party cookie, is HttpOnly, and expires after one year unless it is replaced or cleared earlier.
The cookie contains a workspace identifier, not the workspace's store credential. Selecting a workspace is also subject to an authenticated membership check. The cookie uses Secure and SameSite=Lax attributes.
6. Local storage
Spek uses the following local-storage values:
- Theme preference (aso-theme):remembers a user's light or dark theme preference. Choosing the system setting removes the stored preference;
- Agent workflow preferences (aso-agent-flows-v12): preserves a browser-side copy of the authored agent workflow library and its active workflow; and
- Agent rule preferences (aso-agent-rules-v6): preserves a browser-side copy of authored agent rules used by the rule editor.
These settings remain until you clear them or reset the relevant feature. Clearing browser storage removes the browser copy but does not delete your account or server-side data.
7. Duration
A session cookie generally ends with the browser session, while a persistent cookie or local-storage value remains until its configured expiry or until it is replaced or cleared. The billing-intent and aso_active_workspace durations are stated above. Authentication cookies remain for the applicable session and refresh period.
Related server-side retention is addressed separately in the Privacy Policy.
8. Third-party services
When a user follows a link to, signs in through, or otherwise interacts with a third-party service, that provider may set its own cookies under its own domain and policies. Spek does not control storage placed by Apple, Google, Stripe, Supabase, or another provider on the provider's own website.
9. Consent
Spek uses essential cookies to provide authentication, requested subscription checkout, workspace, and security functionality, and uses local storage for settings or features requested by the user. Where applicable law requires consent for a technology, Spek obtains it before activation.
10. Your controls
Most browsers allow users to inspect, delete, or block cookies and local storage for a site. Users can also sign out of Spek and clear site data through their browser settings. The exact controls depend on the browser and device.
Blocking or deleting essential storage may prevent sign-in, interrupt a requested checkout, lose the selected workspace, or reset theme, workflow, and rule preferences. Controls for storage on a third-party domain must be exercised with that provider or through the browser.
11. Contact
Questions about this Cookie Policy may be sent to RELOAD TECHNOLOGIES - FZCO, Dubai, United Arab Emirates, at hello@spek.app. You can also use our contact page.
We may update this policy when browser storage, the Service, or legal requirements change. We will provide any additional notice or choice required by applicable law.