Updated August 21, 2026
This Cookie Policy explains how Rikyū, an AI design service (the "Service"), uses cookies, local storage, session storage, and similar technologies (collectively, "Cookies").
1. About Cookies
A cookie is a small piece of information sent by a website to your browser and stored on your device. Local storage and session storage similarly let a browser store settings and temporary data.
Some Cookies are set on the Service's domain, while others are set through external providers such as Google and Cloudflare.
2. How We Use Cookies
- Essential: to keep you signed in, protect the Service, remember display settings, support editing, and provide features you request
- Analytics: to understand browsing and feature usage and improve the Service's performance, usability, and features. Analytics start automatically in Japan and the United States and start with your permission in other regions.
- Advertising: the Service does not use Cookies for behavioral advertising, ad personalization, Google Signals, or integration with Google Ads.
3. Essential Cookies
The following Cookies are used to provide the Service, remember settings you choose, or maintain security. They are not covered by the Decline option in the cookie consent prompt.
sb-[project-identifier]-auth-token (numbered suffixes are added when split)
- Provider
- Rikyū / Supabase
- Purpose
- To keep you signed in after Google authentication and securely refresh your session
- Duration
- Up to 400 days. Refreshed when your session renews and deleted when you log out.
sidebar_state, canvas_chat_sidebar_state
- Provider
- Rikyū
- Purpose
- To remember whether the app sidebar and canvas chat sidebar are open or closed
- Duration
- 7 days
NEXT_LOCALE
- Provider
- Rikyū
- Purpose
- To remember the display language you choose
- Duration
- Until you close your browser
theme, rikyu:chat-model, and project tab settings
- Provider
- Rikyū (local storage)
- Purpose
- To remember display settings you choose, including theme, AI model, and open project tabs
- Duration
- Until you clear your browser data or the Service removes the data
rikyu:canvas-node-clipboard and messages awaiting submission
- Provider
- Rikyū (local or session storage)
- Purpose
- To support copy actions on the canvas and submit messages during navigation
- Duration
- Until you clear the data, the message is sent, or you close the browser tab
rikyu:analytics-consent:v1
- Provider
- Rikyū (local storage)
- Purpose
- To remember whether you allowed or declined Google Analytics
- Duration
- Allow lasts 180 days. Decline lasts until you change the setting or clear your browser data.
__cf_bm, cf_clearance, and others (when Cloudflare security features are triggered)
- Provider
- Cloudflare
- Purpose
- To detect automated abuse, remember successful security challenges, and protect the Service
- Duration
- __cf_bm lasts 30 minutes after your last activity. Other durations depend on the Cloudflare feature and security settings.
4. Analytics with Google Analytics
Based on the country code Vercel derives from your IP address, we load Google Analytics automatically in Japan and the United States. In other regions, or when we cannot determine the country, we load it only after you select Allow in the cookie consent prompt. Google Analytics cookies are set on the Service's domain, but the information they collect is sent to Google.
Google Analytics 4
- Cookie or storage key
- _ga, _ga_[measurement-ID]
- Information sent
- Cookie identifiers; IP address and network information; browser, device, operating system, and language; access times; pages viewed with identifiers removed; feature usage; and approximate location. We do not send a user ID, name, email address, prompts, User Content, URL query strings, or project identifiers.
- Recipient
- Google LLC and its affiliates
- Purpose
- To analyze browsing trends, usage, and Service performance and improve the Service
- Duration
- _ga and _ga_[measurement-ID] expire after two years by default. User-level and event-level Google Analytics data is retained for 14 months.
For details on how Google handles information, see the Google Privacy Policy
5. Declining and Changing Your Choice
You can disable Google Analytics from the cookie consent prompt or Cookie settings. We also treat an enabled browser Global Privacy Control signal as a decline. Declining does not change how Rikyū works.
You can change your choice at any time from Cookie settings in the footer or account menu. If you decline, we stop loading Google Analytics and delete _ga cookies on the Service's domain.
You can also disable or delete all cookies in your browser settings. If you do, sign-in, saved preferences, and some other Service features may not work correctly.
6. Changes to This Policy
We may update this Policy to reflect changes in law, the services we use, or how we use Cookies. We will provide a clear in-product notice of any material change.
7. Contact
Questions about our use of Cookies can be sent to hello@rikyu.ai.
End of Policy