Aletheiaby Lonia AI

Legal

Cookies and tracking

The Aletheia marketing site sets no tracking cookies and loads no third-party trackers. This statement explains that posture, how it was verified, and the narrow set of strictly necessary cookies that the signed-in product may use, none of which apply to browsing this site.

Version 1.1. Published: July 14, 2026. Last updated: July 23, 2026.

Introduction

This statement covers the Aletheia marketing site at aletheia.lonia.ai. It is published under the ePrivacy Directive 2002/58/EC (as amended), which applies alongside the General Data Protection Regulation for services directed at users in the European Union. Under that Directive, any cookie or similar storage that is not strictly necessary to deliver a service the user has requested requires the user's consent before it is set. Cookies that are strictly necessary, such as those needed for session management, security, or authentication, are exempt from the consent requirement but are still documented here.

The Aletheia marketing site relies on none of these mechanisms. It sets no cookies at all, stores nothing in your browser, and contacts no third-party host when you load a page.

How this was verified

The zero-cookie claim is not a promise made from reading the code. It is the result of a runtime audit. Every public route on this site was loaded in a fresh, isolated browser session, and after each page finished loading we enumerated every place a tracker could hide: cookies (including those a server can set that scripts cannot read), localStorage, sessionStorage, IndexedDB databases, Service Worker registrations, and every network request the page made, separating our own domain from any third party.

Across all 25 audited routes, the audit observed zero cookies, zero localStorage and sessionStorage entries, zero IndexedDB databases, no Service Worker, and zero requests to any third-party host. The only host contacted was our own origin, serving the page, its stylesheet, and its images. The audit was most recently re-run on July 23, 2026, covering every public route in the current build, and it is re-run whenever the site changes materially.

What we do not do

On the marketing site, we do not load any of the following:

  • Analytics cookies of any kind (Google Analytics, Plausible, Fathom, or any equivalent).
  • Advertising or retargeting cookies.
  • Social media pixels or share-button trackers (Meta, LinkedIn, X, or others).
  • Session replay or heatmap tools.
  • Third-party fonts, scripts, or tag managers loaded from an external content delivery network.
  • Consent-management or cookie-banner scripts, which are unnecessary because there are no non-essential cookies to consent to.

Strictly necessary cookies in the signed-in product

The pages on this marketing site do not require you to sign in, so they set no session or authentication cookies. Those cookies exist only inside the signed-in Aletheia product, on its own application subdomain, and only after you choose to sign in.

When you sign in to the product with Google or Microsoft, the authentication provider maintains a session so that you stay signed in between page loads. That session storage is strictly necessary: without it, you could not use a feature you explicitly asked for, which is to be signed in. Under the ePrivacy Directive, strictly necessary session and authentication storage of this kind is exempt from the consent requirement. It is first-party, it is not used for cross-site tracking, and it does not apply to anyone who is only browsing this marketing site.

Third-party services

Some Lonia AI infrastructure is capable of setting a strictly necessary cookie in narrow circumstances, but none of it runs on this marketing site, and the runtime audit above confirms that.

  • Cloudflare bot protection (Turnstile). Where a bot-protection challenge is presented, for example to guard a sign-in or a form submission inside the product, the challenge may briefly set a first-party session cookie to complete and remember the result of that specific challenge. That cookie is a strictly necessary security cookie under the ePrivacy exemption: it exists to protect the service against automated abuse, not to track you, and it carries no advertising or analytics function. No such challenge runs when you browse this marketing site, so no such cookie is set here.
  • Everything else. The services that operate Aletheia, such as authentication, database, hosting, and payments, are documented in the Sub-processor list. None of them place a cookie or run a script on this marketing site.

Your controls

Because this site sets no cookies, there is nothing for you to clear here. For the strictly necessary cookies that the signed-in product may use, and for cookies from any other site you visit, every major browser lets you view and delete stored cookies and site data, block cookies, and browse in a private or incognito window. These controls are found in your browser's privacy or site-data settings. Clearing a strictly necessary product cookie simply signs you out of the product; it does not affect your ability to read this marketing site.

Change history

Change history for this cookies and tracking statement.
Date Version Change
July 23, 2026 1.1 Re-ran the runtime audit against the current build, covering all 25 public routes, including the six added since initial publication. Result unchanged: zero cookies, zero client-side storage, and zero third-party requests on every route.
July 14, 2026 1.0 Initial publication, backed by a runtime cookie audit confirming a zero-cookie, zero-tracker posture across the 19 public routes then published.

Review cadence

Last review date: July 23, 2026. Next review: annually, or on any material change to the site's storage or network behavior, whichever comes first. A material change includes adding any script, embed, font, or service that loads from a third-party host, or introducing any cookie or client-side storage. On each review the runtime audit is re-run and this statement is updated to match what the audit observes.

Contact

Questions about this statement, or about cookies and tracking generally, can be sent to legal@lonia.ai.

Related documents

Reviewing Aletheia's privacy posture?