Cookie Policy

Last updated: 22 August 2026

Cookies, browser storage and similar technologies. Effective: 22 August 2026. This Policy explains the limited information Marklet stores on or reads from a user's device, and the security and analytics technologies used on marklet.io and the Marklet web application.

1. Who we are

Marklet is operated by Levered AI Ltd (company number 17149630), of 167-169 Great Portland Street, 5th Floor, London, W1W 5PF. Contact: privacy@marklet.io.

2. What these technologies are

A cookie is a small text file stored on a device. Browser local storage and session storage can store information in a similar way. Scripts may also read device or connection information without setting a cookie. The Information Commissioner's Office refers to these collectively as storage and access technologies.

3. Technologies Marklet uses

Authentication

Purpose: Essential authentication cookie and authentication-provider session storage used for one-time codes, magic links, sign-in and account security.

Duration: The Marklet authentication cookie lasts 1 hour and is refreshed while signed in; the authentication provider's session storage can persist for up to 400 days. Both are cleared on sign-out.

Why used without consent: Strictly necessary to provide secure sign-in requested by the user.

Session state

Purpose: First-party browser-storage keys used to preserve the current session, navigation and functions requested within the application.

Duration: Session or until the relevant state is cleared.

Why used without consent: Strictly necessary to provide the requested application function.

Interface preferences

Purpose: A first-party preference cookie and browser-storage keys remember choices the user deliberately makes, such as interface settings.

Duration: The preference cookie lasts 7 days; other preferences last until changed or cleared.

Why used without consent: Used to implement a preference expressly requested by the user.

Installable app and service-worker cache

Purpose: The installable app uses a service worker to pre-cache the application shell and static assets on the device so that the app can load, update and operate reliably. The service worker also keeps a short-lived cache of recently fetched application data, which for a signed-in user can include Workspace data, and holds any changes made while offline until they can be delivered.

Duration: The application shell and assets last until the cache is refreshed by an app update, the app or site data is removed, or the browser evicts it. The data cache and any held offline changes are cleared on sign-out and in any event expire within 24 hours.

Why used without consent: Strictly necessary to provide and maintain the installable application requested by the user and to prevent technical faults. The cache is not used for analytics or tracking.

Push-notification subscription

Purpose: When a user enables push notifications, the browser stores a per-device subscription, including an endpoint and cryptographic keys, so notifications can be routed securely to that device.

Duration: Until the user disables or unsubscribes from notifications, clears the relevant app or site data, or the browser or push provider expires the subscription.

Why used without consent: Used solely to deliver notifications the user has switched on. Storing the subscription is strictly necessary to provide that function, which the user expressly requested; the browser also asks the user for notification permission.

Local Workspace cache

Purpose: The app may store recently viewed Workspace data locally on the device to maintain the requested application state and provide the relevant Workspace functions.

Duration: Until the user signs out; the browser may also remove it if the user clears app or site data.

Why used without consent: Strictly necessary to provide the requested app functions. It is not used for analytics, advertising or tracking and is cleared on sign-out.

Assistant chat history

Purpose: Conversations with the Ask Mark assistant are kept in the browser's local storage on the user's own device (up to 50 messages per building) rather than on Marklet's servers.

Duration: Until cleared from the browser.

Why used without consent: Implements a function expressly requested by the user, and keeps the conversation on the user's device instead of Marklet's servers.

Bot and abuse protection

Purpose: Cloudflare Turnstile on login, signup, public forms and the in-app feedback form processes IP address, browser and connection information to distinguish legitimate users from automated abuse.

Duration: As determined by Cloudflare for the security interaction; it may use necessary storage or access.

Why used without consent: Necessary for security, fraud and abuse prevention.

Cookieless website analytics

Purpose: Marklet's website measurement runs on its own servers. It creates no visitor identifier of any kind. The network and browser information a device sends with each request is used to tell an automated request from a browser and to place the request in a country and a town, and is then discarded; what is recorded is the page, that coarse location and page interactions. It sets no cookie and stores or reads nothing on the device.

Duration: Not applicable to device storage.

Why used without consent: No information is stored on or read from the device for this measurement, and it is not used for advertising or cross-site tracking. The lawful basis for the processing is in the Privacy Policy.

4. Why there is no consent banner

Marklet does not currently use advertising cookies, marketing cookies, cross-site tracking or device-based analytics. Its storage and access technologies are limited to functions that are strictly necessary to provide or secure the service requested by the user, to remember an interface preference the user has expressly selected, or solely to transmit push notifications the user has requested. The website analytics stores and reads nothing on the device.

On the basis of the technologies and purposes described above, Marklet does not presently require consent for its use of storage and access technologies and therefore does not display a cookie consent banner. If Marklet introduces a technology that requires consent, it will obtain consent before using it and update this Policy.

5. Cloudflare Turnstile

Turnstile is a third-party security script supplied by Cloudflare. It assesses technical and connection information to decide whether a request appears human and legitimate. Cloudflare processes information for Marklet in providing that security function and may also use information under its own terms to maintain and improve its services. Marklet uses Turnstile on login, signup, public forms and the in-app feedback form, where bot and abuse protection is needed.

6. Managing device storage

Users can inspect, block or delete cookies, browser storage, service-worker caches and app data through browser or device settings. Blocking authentication, session storage or required app storage may prevent sign-in or cause the Service or installable app to malfunction. Clearing preference storage will reset the selected setting. Users can disable push notifications through the browser, device or app settings. Signing out clears the local Workspace cache; users should sign out on shared or unmanaged devices. Because Marklet does not use non-essential consent-based cookies at present, there is no separate Marklet preference centre.

7. Personal data and lawful bases

Where these technologies involve personal data that Marklet controls, Marklet relies on contract and legitimate interests in providing secure accounts, preventing abuse, remembering requested settings, delivering requested notifications and understanding website performance in a proportionate way. Workspace data held in the local device cache remains customer-controlled Workspace content and is processed under the Marklet DPA. More information about recipients, retention, transfers and rights is in the Marklet Privacy Policy.

8. Changes to this Policy

Marklet may update this Policy when technologies, providers or law change. The updated date will appear above. A new consent-requiring purpose will not be activated for a user before the required consent mechanism is available.

9. Contact

Questions about cookies, browser storage or privacy may be sent to privacy@marklet.io.