Cookie Policy
AI Management Solutions LLC
Effective date: 5 July 2026
This Cookie Policy explains how AI Management Solutions LLC ("we," "us," or "our") uses cookies and similar browser-storage technologies on our websites:
• cioaim.com (our public website)
• api.cioaim.com (our authenticated member app)
• Our embedded chat experience (aims-chat) within the member app
This policy should be read alongside our Privacy Policy and Terms & Conditions. Our mobile app (CIOAIM Mobile) uses native device secure storage rather than cookies and is covered in our Privacy Policy. AI coaching accessed through supported third-party messaging platforms (WhatsApp, Telegram, and Threema) does not involve cookies, as these are native messaging applications rather than browser-based surfaces. Data processing through these channels is described in our Privacy Policy and Terms and Conditions.
1. What Are Cookies and Similar Technologies
Cookies are small text files placed on your device when you visit a website. We also use two related technologies that are treated equivalently to cookies for consent purposes:
Local Storage: persistent data stored in your browser
Session Storage: temporary data cleared when you close your tab
Throughout this policy, "cookies" refers to all three technologies.
2. How We Categorise Cookies
We use four categories of cookies and similar technologies:
Strictly necessary — required to deliver the service. No consent required.
Functional — remember your preferences. No tracking purpose; treated as first-party functional.
Analytics — help us understand product and site usage. Consent required.
Affiliate / Marketing — track referral and partner attribution. Consent required.
You can manage your consent for analytics and affiliate cookies on our public website via the cookie banner shown on first visit, or at any time by clicking "Manage Consent" in the footer.
3. Strictly Necessary Cookies (No Consent Required)
These cookies are essential to operate our Services and are exempt from consent requirements under the "strictly necessary" exemption in the ePrivacy Directive and PECR.
3.1 Authentication and Security (Member App)
Our authenticated member app uses Auth.js v5 (also known as NextAuth) for sign-in. The following cookies are set on .cioaim.com:
Cookie: Secure-authentication
Purpose: Encrypted login session (JWE)
Flags: HttpOnly, Secure, SameSite=Lax
Duration: ~30 days
Cookie: Protection endpoint
Purpose: CSRF protection on auth endpoints
Flags: HttpOnly, Secure
Duration: Session
Cookie: Secure Re-direct
Purpose: Post-login redirect target
Flags: HttpOnly, Secure
Duration: Session
Cookie: Secure handshake
Purpose: OAuth handshake during third-party sign-in
Flags: HttpOnly, Secure
Duration: Transient (~15 min)
3.2 Payment and Fraud Prevention (Stripe)
When you add or update a payment method in your account settings, our payment provider Stripe loads its JavaScript library within that dialog and sets the following cookies as first-party cookies on our domain:
Cookie: Stripe
Purpose: Stripe fraud prevention — persistent device identifier
Duration: ~1 year
Cookie: Stripe fraud prevention
Purpose: Stripe fraud prevention — session identifier
Duration: ~30 minutes
These cookies are set as first-party cookies on our domain, meaning they appear under cioaim.com rather than stripe.com. However, because Stripe's JavaScript library runs on the page, the underlying data associated with these identifiers is transmitted to and processed by Stripe. Setting location and data destination are separate: the cookie lives on our domain, but Stripe receives the data. These cookies are essential for processing payments securely and preventing fraud. See Section 7 for Stripe's role and transfer mechanism.
Note: When you sign up directly for a Pro or Ultra plan with a free trial (see our Terms and Conditions, Section 6.3), you are redirected to a checkout page hosted entirely by Stripe on their own domain. Any cookies set during that process are governed by Stripe's own privacy and cookie policies, not this Cookie Policy.
4. Functional Cookies (First-Party)
These cookies remember your preferences. They are first-party only and do not track you across sites.
Cookie: Language
Purpose: Remembers UI language (en/de/fr/es)
Surface: Member app + public site
Duration: ~1 year
5. Analytics Cookies (Consent Required)
We use analytics to understand how our Services are used and to improve them. These cookies are only set if you give consent (analytics category).
5.1 PostHog (Member App)
We use PostHog for product analytics on the member app. PostHog is configured with the following privacy settings:
EU-hosted instance — PostHog data is processed in the European Union.
First-party reverse proxy — PostHog requests are routed through our own /ingest endpoint, so no direct browser-to-PostHog connection occurs.
person_profiles: ‘identified_only’ — anonymous visitors are not tracked at the person level; only logged-in users are associated with a stable identifier after login.
Cookie / Storage Details:
Cookie/Storage: ph_<project-key>_posthog (and session variant)
Purpose: PostHog device and event identification
Location: Cookie + local storage on api.cioaim.com
Important note on PostHog consent: PostHog currently runs on the authenticated member app without a separate cookie-consent prompt because the member app is only accessible after you have created an account and accepted our Terms. We are migrating to explicit cookie-consent gating on the member app to align with our public site. Until that migration is complete, you can opt out of PostHog tracking by emailing hello (at) (dot) com.
5.2 Google Analytics 4 (Public Site Only)
We use Google Analytics 4 on the public website (cioaim.com) — not on the member app — only if you give analytics consent.
Cookie: User identification
Purpose: Unique user identification
Duration: 13 months
Cookie: Session
Purpose: Session and campaign data
Duration: 13 months
Cookie: User distinction
Purpose: User and session distinction
Duration: 24 hours
Cookie: Throttling
Purpose: Request throttling
Duration: 1 minute
Google Analytics is configured with anonymize_ip: true to mask the last octet of your IP address before processing. See Section 7 for Google’s role and transfer mechanism.
6. Affiliate Cookies (Consent Required)
We use Partnero on the public website to track referrals from our partner program. These cookies are only set if you give affiliate consent.
Cookie: Partnero attribution cookie(s) (vendor-named)
Purpose: Tracks which partner referred you so attribution can be credited correctly
Duration: Vendor-defined
Partnero also processes server-side webhooks from our member app for attribution events. No cookies are set on your device through that server-side flow.
This policy is reviewed and updated whenever we add a new cookie, tracking technology, or vendor. If you believe a cookie or tracking mechanism is in use that isn't listed here, please contact us at hello (at) (dot) com and we will investigate.
7. Third-Party Service Providers and Cross-Border Transfers
7.1 AI Providers by Selected Region
You can select or change your data processing region at any time under "Compliance" in your account settings, as described in our Terms and Conditions, Section 4.2. Changing your region may affect access to your existing coaching history, as described there. The AI/LLM providers used depend on your selected region:
• EU region: Eden AI SAS (France) and Gladia SAS (France), and other EEA-based providers as applicable.
• US region (default): Anthropic PBC, OpenAI, OpenRouter Inc., and ElevenLabs Inc., and other US-based providers as applicable.
The cookies and analytics tools above involve data being processed by third-party providers. Where these providers are based outside the European Economic Area (EEA), we rely on the following GDPR Chapter V transfer mechanisms:
Provider: Stripe
Role: Payment processing and fraud prevention
Location: United States (with EU/Ireland entity)
Transfer Mechanism: EU-US Data Privacy Framework + Standard Contractual Clauses
Provider: Google LLC
Role: Google Analytics 4
Location: United States
Transfer Mechanism: EU-US Data Privacy Framework
Provider: Partnero
Role: Affiliate / referral attribution
Location: Lithuania (EEA)
Transfer Mechanism: Not required — EEA-based
Provider: PostHog
Role: Product analytics
Location: European Union (EU-hosted instance)
Transfer Mechanism: Not required — EU-based
Provider: Vercel
Role: Hosting and preview deployments
Location: United States
Transfer Mechanism: Standard Contractual Clauses
Provider: Cloudflare
Role: CDN, security, and DDoS protection (does not set cookies in this configuration)
Location: United States
Transfer Mechanism: Standard Contractual Clauses
Server-to-Server API Providers
Where "Standard Contractual Clauses" is listed below, this refers to the EU Standard Contractual Clauses for transfers from the EEA. For transfers from the UK, we rely on the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs, as applicable, alongside adequacy decisions where they apply.
The following providers are accessed exclusively via server-to-server API calls from our infrastructure. They receive no data directly from your browser and set no cookies on your device. They are listed here for transparency:
Provider: Anthropic PBC
Role: AI coaching responses (Claude models)
Location: United States
Transfer Mechanism: Standard Contractual Clauses
Provider: OpenAI
Role: AI coaching responses
Location: United States
Transfer Mechanism: Standard Contractual Clauses
Provider: OpenRouter, Inc.
Role: AI model routing to a range of underlying providers
Location: United States
Transfer Mechanism: SCCs; underlying provider list available on request
Provider: Eden AI SAS
Role: AI provider aggregation
Location: France (EEA)
Transfer Mechanism: Not required for Eden; SCCs apply to non-EEA underlying providers via Eden’s sub-processor agreements
Provider: Gladia SAS
Role: Voice transcription
Location: France (EEA)
Transfer Mechanism: Not required — EEA-based
A current list of Standard Contractual Clauses and sub-processors is available on request by emailing hello@cioaim.com. Where this policy references the EU-US Data Privacy Framework or Standard Contractual Clauses (European Commission Implementing Decision (EU) 2021/914), these mechanisms are subject to ongoing certification and legal status. We review and update this information periodically; the most current status for any provider is available on request.
7.2 Voice Coaching (ElevenLabs)
Voice coaching sessions are routed differently depending on your selected data processing region:
· US region: ElevenLabs Conversational AI SDK establishes a direct WebSocket connection from your browser to ElevenLabs' servers during voice coaching sessions. Your voice data is transmitted directly to ElevenLabs, not through our servers.
· EU region: Voice coaching sessions do not use ElevenLabs. EU-region users are routed to EU-hosted voice providers only, consistent with the region selected under "Compliance" in your account settings.
7.3 Subprocessors of AI Aggregation and Routing Providers
Eden AI SAS and OpenRouter, Inc. operate as aggregation and routing services rather than as AI models themselves. These providers may engage their own subprocessors as needed to operate their services, including:
the specific third-party AI providers we select to be used through their platforms;
infrastructure, hosting, analytics, support, and payment providers.
We select which underlying AI providers are used through Eden AI and OpenRouter, consistent with your selected data processing region (see Section 4.2 of our Terms and Conditions). Information about AI providers available through Eden AI can be found at https://app.edenai.run/models. A current list of subprocessors for Eden AI or OpenRouter is available on request by emailing hello (at) (dot) com.
We are not responsible for the data processing practices of the underlying AI providers accessed through these aggregation services, beyond the obligations described elsewhere in this policy.
8. How We Obtain Your Consent
8.1 Public Site (cioaim.com)
When you first visit our public website, we display a cookie consent banner before any non-essential cookies or scripts are loaded. The banner is designed to meet GDPR, UK GDPR, and PECR requirements:
Pre-consent blocking — analytics and affiliate scripts on the public site (Google Analytics, Partnero) do not load until you give the corresponding consent. PostHog operates as a server-side service on the member app; see Section 5.1 for how it is currently handled.
Equal prominence — "Accept All" and "Reject All" are presented with equivalent visual weight, size, and position.
Granular control — a "Manage Consent" option allows you to consent to or reject each category (analytics, affiliate) individually.
No dark patterns — we do not use design techniques to nudge or pressure you into accepting cookies.
No consent walls — access to our public site is not conditional on accepting non-essential cookies.
Your choices are recorded in cioaim_cookie_consent in your browser’s local storage (this is not a cookie, but is treated as one under the same consent framework).
8.2 Member App (api.cioaim.com)
When you create an account, you accept our Terms & Conditions and Privacy Policy, which describe the data processing necessary to provide the service. Strictly necessary cookies, functional cookies (NEXT_LOCALE), and Stripe payment cookies operate on this basis.
As noted in Section 5.1, PostHog currently runs on the member app without a separate cookie-consent prompt. We are working to add explicit cookie-consent gating to the member app. Until then, you can opt out of PostHog by emailing hello (at) (dot) com.
8.3 Withdrawing or Changing Consent
You can change your consent at any time:
Public site: click "Manage Consent" in the footer
Any surface: email hello (at) (dot) com
Withdrawing consent for non-essential cookies will not affect your access to our Services.
9. Data Retention
There is an important distinction between cookie lifespan (how long the cookie file remains in your browser, listed above) and data retention (how long we keep the underlying data).
Category: Strictly necessary (auth)
Cookie Lifespan: Session — 30 days
Data Retention: Authentication and security logs: 90 days; security audit logs: 12 months
Category: Strictly necessary (Stripe)
Cookie Lifespan: Up to 1 year
Data Retention: Retained by Stripe per their policy; we retain payment records as required by tax and accounting law
Category: Functional
Cookie Lifespan: Up to 1 year
Data Retention: No server-side retention
Category: Analytics (PostHog)
Cookie Lifespan: Cookie + local storage
Data Retention: Personal-level data: while account is active; deleted within 30 days of account closure. Aggregated data: retained for product analytics
Category: Analytics (Google Analytics)
Cookie Lifespan: Up to 13 months
Data Retention: 14 months, as configured in our GA4 property (Google's configurable range is 2–14 months)
Category: Affiliate (Partnero)
Cookie Lifespan: Vendor-defined
Data Retention: Attribution records: retained while program is active or as required for partner payments
When you delete your account, all personal data associated with cookies is deleted within 30 days, subject only to legal retention obligations (e.g., financial records).
10. Your Rights
10.1 European Union and United Kingdom (GDPR / UK GDPR / PECR)
You have the right to access, correct, erase, restrict, port, and object to the processing of your personal data. To exercise these rights, contact hello (at) (dot) com. You also have the right to lodge a complaint with your local data protection authority.
10.2 California (CCPA / CPRA)
California residents have the right to know, the right to delete, the right to correct, and the right to opt out of the "sale" or "sharing" of personal information. We do not sell personal information.
10.2.1 Global Privacy Control (GPC)
We do not sell personal information. To opt out of the sharing of personal information for cross-context behavioural advertising, use the cookie preference centre described in Section 8 to reject the analytics and affiliate categories, or contact us using the methods in Section 10.2.2. We are working to support the Global Privacy Control (GPC) browser signal as an automated opt-out mechanism; this policy will be updated once that capability is live.
10.2.2 Submitting Rights Requests
We provide one designated method:
Email: hello (at) (dot) com with "California Privacy Rights Request" in the subject line
10.3 Other Jurisdictions
Canada (PIPEDA): Canadian users have access and correction rights — contact hello (at) (dot) com.
Australia (Privacy Act 1988): Australian users have rights under the Australian Privacy Principles — contact hello (at) (dot) com.
11. Cookies and AI Processing
The cookies described in this policy support our Services, including AI coaching features. We do not use individual cookie data, session data, or device identifiers to train our own AI models. Where aggregated usage data informs service improvements, it is processed at a statistical level only. Note that the third-party AI and voice providers listed in Section 7 have their own data-use practices, which may include model training depending on the provider; we cannot guarantee third-party practices on your behalf. The retention and consent settings for AI coaching content itself (memory of past conversations, chat transcripts) are managed separately from cookie consent. You can manage these in your member app settings or by contacting us. See our Privacy Policy for details.
12. Children’s Privacy
Our Services are intended for adults aged 16 and over. We do not knowingly collect cookies or tracking data from individuals under 16. If you believe a child has accessed our Services, please contact us at hello (at) (dot) com.
13. Updates to This Policy
We may update this Cookie Policy to reflect changes in our cookie usage, new features, or legal requirements. We will notify you of material changes by updating the effective date, displaying a banner on your next visit, and emailing registered users. For non-material updates (e.g., clarifications, formatting), we will update the effective date only.
When we add a new category of non-essential cookies, we will re-prompt for consent before those cookies are set.
14. Contact Information
AI Management Solutions LLC
General contact: hello (at) (dot) com
Privacy and rights requests: hello (at) (dot) com
You may also contact your local data protection authority with any concerns about our cookie practices.