Cookie Policy for Agenda Application
Last Updated: 22 December 2025 | Application Name: Agenda
1. Introduction
This Cookie Policy explains how the Agenda application ("the Application", "the Service") uses cookies and similar technologies when you access or use the Service.
This policy should be read together with the Privacy Policy, which explains how personal data is processed more broadly.
Cookies are used to ensure the proper functioning of the Application, maintain security, improve usability, and remember user preferences. We do not use cookies for advertising or cross-site tracking purposes.
2. Who We Are
The Application is operated by:
- Data Controller: Prasaath Sastha Kuppan Ravi
- Trading As: AIAgentsAge
- Jurisdiction: United Kingdom
- Contact Email: privacy@aiagentsage.com
3. What Are Cookies?
Cookies are small text files placed on your device (computer, tablet, or mobile device) when you visit a website or use an online application.
Cookies allow the Application to:
- Recognize your device
- Maintain authenticated sessions
- Store preferences
- Ensure secure and reliable operation
Similar technologies such as local storage or session storage may also be used for comparable purposes.
4. Types of Cookies We Use
The Agenda Application uses the following categories of cookies, primarily through our authentication system implemented with NextAuth.js and the Stack framework:
4.1 Strictly Necessary Cookies
These cookies are essential for the operation of the Application and cannot be disabled.
They are used to:
- Authenticate users through NextAuth.js with JWT (JSON Web Token) strategy
- Maintain login sessions using secure JWT tokens stored in cookies
- Store session information with a maximum age of 30 days (2,592,000 seconds)
- Protect against unauthorized access through secure session management
- Enable core security features including tenant isolation in our multi-tenant environment
The Application uses the following strictly necessary cookies:
next-auth.session-token: Stores the JWT session token for authenticated usersnext-auth.state: Temporary state cookie used during OAuth flows- Stack framework authentication cookies for user session management
Without these cookies, the Application cannot function properly.
Legal basis: Legitimate interest and performance of a contract (Article 6(1)(b) and (f) GDPR)
4.2 Authentication and OAuth Cookies
These cookies facilitate authentication through Google OAuth and other providers:
- Used to store temporary OAuth state during Google authentication flows
- Store Google OAuth access and refresh tokens for calendar integration
- Enable single sign-on functionality through Google accounts
- Maintain secure authentication tokens with automatic refresh capabilities
When connecting Google Calendar, additional tokens are stored to maintain calendar synchronization and enable meeting scheduling features.
Legal basis: Legitimate interest and performance of a contract (Article 6(1)(b) and (f) GDPR)
4.3 Functional Cookies
Functional cookies allow the Application to remember choices you make and provide enhanced functionality and personalization.
They may be used to:
- Remember user preferences and UI settings
- Maintain application state between sessions
- Store tenant-specific configurations and branding preferences
- Retain dashboard customization settings
Disabling these cookies may reduce usability but will not prevent access to the core service.
Legal basis: Legitimate interest (Article 6(1)(f) GDPR)
4.4 Security Cookies
Security-related cookies are used to:
- Detect suspicious authentication activity
- Prevent fraudulent access attempts
- Protect user accounts through secure session validation
- Enforce access controls and tenant isolation
- Maintain secure token validation for API requests
These cookies are essential for protecting both users and the Application.
Legal basis: Legitimate interest (Article 6(1)(f) GDPR)
4.5 Analytics and Performance Cookies
At present, the Application does not use advertising cookies or cookies for cross-site behavioral tracking.
If analytics or performance measurement tools are introduced in the future:
- They will be used solely to understand application performance and feature usage
- They will not be used for profiling or advertising
- Users will be informed and, where required, asked for consent before activation
5. Third-Party Cookies
Some cookies may be set by third-party services that are integrated into the Application, such as:
- Google OAuth: During authentication flows, Google sets cookies to manage the OAuth consent and authentication process. These cookies are governed by Google's own privacy policy.
- Infrastructure and hosting providers: Database services (Neon PostgreSQL) and hosting platforms may set operational cookies for system management.
- Authentication framework: NextAuth.js and the Stack framework may set additional cookies for session management and security validation.
These third parties may process limited technical information strictly necessary for their function. They are contractually bound to comply with applicable data protection laws.
6. How You Can Control Cookies
You can manage or delete cookies through your browser settings. Most browsers allow you to:
- View cookies stored on your device
- Delete existing cookies
- Block cookies entirely
- Receive notifications when cookies are set
Please note that disabling cookies may impact the functionality and security of the Application.
7. Consent
Where cookies are strictly necessary, they are used without consent as permitted by law.
If non-essential cookies are introduced in the future:
- You will be informed clearly
- Consent will be obtained where legally required
- You will have the ability to manage your preferences
8. Changes to This Cookie Policy
This Cookie Policy may be updated from time to time to reflect changes in technology, legal requirements, or application functionality.
Any changes will be posted within the Application and reflected in the "Last Updated" date at the top of this policy.
9. Contact Information
If you have any questions about this Cookie Policy or the use of cookies in the Application, please contact:
Email: privacy@aiagentsage.com
Effective Date
This Cookie Policy is effective as of 22 December 2025.