Cookie Policy
Last updated: 24 August 2026
This policy explains the cookies and the browser storage that Nucleus HQ uses on the Nucleus HQ website, in the Nucleus HQ app, and on the funnel and course pages we host for our customers. It lists every cookie we set, what each one is for, and how long it lasts. It also explains the storage we use in your browser that is not a cookie, because that storage is easy to miss and you are entitled to know about it.
1. Cookies and similar technologies
A cookie is a small file that a website asks your browser to store and send back on later visits.
Nucleus HQ also uses two kinds of browser storage that are not cookies, localStorage and sessionStorage. These keep small amounts of information inside your browser and are not sent back to us automatically with every request. They are covered in section 5.
2. No advertising or marketing cookies
Nucleus HQ does not set advertising or marketing cookies, and does not use third-party tracking or advertising pixels. The only cookies we set are the ones listed below, and they are needed to sign you in, keep you signed in, remember your language, keep your account secure, and confirm your return to a seller's funnel page from their external payment page.
There are no non-essential cookies to accept or decline, because we do not set any.
The cookies we do set are either strictly necessary or functional, and they are all listed in section 3. Strictly necessary cookies cannot be switched off, because Nucleus HQ cannot sign you in or keep you signed in without them. You can still block or delete any cookie through your browser settings, as described in section 8.
3. Every cookie Nucleus HQ sets
This is the complete list. Nucleus HQ sets no other cookies.
Strictly necessary
| Cookie | Purpose | Lifetime |
|---|---|---|
| __Host-nucleus_session | Authenticated session for the app. | Session, with server-side expiry. |
| nucleus_mfa_pending | Carries a pending multi-factor step between login screens. Scoped to the path /login. | 5 minutes. |
| __Host-nucleus_learner | Course learner login session. | 30 days, server-side session. |
| __Host-nucleus_off_platform | Confirms your return to a seller's funnel page from the seller's own external payment page. Set on the seller's funnel domain only. | Up to 2 hours. Deleted when you return. |
| nucleus_signup_claim | Holds a signup claim through checkout. Scoped to the path /signup. | 1 hour. |
The __Host-nucleus_off_platform cookie only ever appears on a customer's funnel page, and only when that customer has chosen to take payment on their own external page after a form. It is a signed, pseudonymous note that lets the same browser be recognised when you come back, so your earlier form submission can be marked as returned. It is read once, then deleted. It does not verify any payment, it does not follow you to the external page, and it cannot be read by anyone else.
Functional
| Cookie | Purpose | Lifetime |
|---|---|---|
| nucleus_marketing_locale | Remembers the site language you chose. | 1 year. |
| sidebar_state | Remembers whether the app sidebar is collapsed. | 7 days. |
There is no third category. Nucleus HQ sets no marketing cookie, no advertising cookie, no analytics cookie and no third-party cookie of any kind.
4. What Nucleus HQ does NOT set
To be precise about things that other policies sometimes claim and we do not do:
- There is no CSRF cookie. Cross-site request protection in Nucleus HQ uses signed OAuth state together with host and origin checks. No cookie is involved.
- No cookie is used for tenant routing. Working out which workspace or site a request belongs to is done from the host and the request headers. No cookie is involved.
- There is no error-tracking or analytics cookie, and no error-tracking or analytics provider. Nucleus HQ has no such integration and no configuration for one. If that ever changes, this policy and the subprocessor page will be updated before it is switched on.
- There is no advertising, marketing, or referral attribution cookie. Nucleus HQ does not run advertising pixels and does not share your browsing with an advertising network.
5. Browser storage that is not a cookie
| Key | Where | What it holds | Lifetime |
|---|---|---|---|
| Concierge widget store | sessionStorage | An anonymous session identifier, the bot version, and up to 100 recent messages of your own conversation with the concierge widget. Capped at 128,000 bytes. | The lifetime of the browser tab. Removed when the conversation is reset. |
| Paid booking store | sessionStorage | A booking manage token, your chosen slot and the confirmation message, carried across the Stripe redirect so that your booking can be completed and shown to you when you come back. It is read and then deleted. | Minutes. Deleted on your return. |
The concierge widget storage is first party, it is not used for tracking or advertising, and it is not read by anyone else.
Where a customer publishes the concierge widget on their own Nucleus HQ pages, the same first-party sessionStorage behaviour applies on those pages.
The concierge widget on the Nucleus HQ marketing homepage writes its own sessionStorage entry for the current tab. It does not restore an earlier conversation for you as you browse.
6. Lawful basis for browser storage and for widget analytics
Nucleus HQ takes the following position, which is set out here so you can see our reasoning rather than having to guess at it.
- The strictly necessary cookies in section 3 are set on the basis that they are strictly necessary to provide the service you have asked for. No consent is required for them.
- The concierge widget sessionStorage and the paid booking sessionStorage are used only to deliver the conversation or the booking that you have actively started. Nucleus HQ treats them as strictly necessary for a service you have requested, and does not use them for tracking or advertising.
- The functional cookies in section 3 remember a preference you have expressed and are not used for tracking or advertising.
- Nucleus HQ sets no non-essential cookie, so there is no cookie for which consent would be the lawful basis.
- Nucleus HQ records server-side analytics events about concierge widget usage. These are capped at 500 events per session, and they are deleted when the record they relate to is deleted.
The concierge widget stores a small amount of information in your browser's sessionStorage so that a conversation you have started can carry on as you move between pages. We treat this as strictly necessary for a service you have specifically asked for, because it is written only once you open the widget, it exists only to run the conversation you started, and it is cleared when you close the tab.
Separately, we record usage analytics about the widget. Those events are recorded on our servers, not in your browser. They contain no message text, no contact details and no IP address, and they are capped. We rely on our legitimate interest in knowing whether the widget works.
7. Third parties
Nucleus HQ uses these providers, and only these, in ways that can touch your browser:
- Cloudflare, for DNS, TLS, security, routing, and Turnstile bot verification.
- Stripe, for checkout, the billing portal, and commerce payments. You are redirected to Stripe for payment, and Stripe applies its own notices there.
- Google, only where a workspace user chooses to connect their own Google Calendar. That user is redirected to Google to approve access, and Google applies its own notices there. Nucleus HQ sets no cookie as part of that flow.
Transactional email is delivered by Resend, and Nucleus HQ hosts the application and its databases with Contabo. Neither of those places anything in your browser.
Cloudflare and Stripe are Nucleus HQ subprocessors and match the published Nucleus HQ subprocessor page. Google is not a Nucleus HQ subprocessor. It appears above only because a workspace user can choose to connect their own Google account, which redirects that user to Google.
8. Managing cookies in your browser
You can block or delete cookies through your browser settings. Blocking the strictly necessary cookies will stop Nucleus HQ from being able to sign you in or keep you signed in.
Clearing site data for the Nucleus HQ domain removes the cookies listed in section 3 and the browser storage listed in section 5.
9. Customer sites published through Nucleus HQ
Nucleus HQ serves two different kinds of customer-published site. They behave differently, and the difference matters, so they are described separately.
9.1 Hosted funnel pages on funnelsnucleuslive.org
Funnel pages published through Nucleus HQ and served on funnelsnucleuslive.org set no cookies. Tenant-authored content is sanitised. The only scripts on a funnel page are the small functional ones Nucleus HQ supplies for elements the tenant has used: countdown timers, popups and offer bars, embedded forms with bot protection, and product and basket elements. A basket keeps your chosen product ids, options and quantities in your own browser storage, a similar technology under this policy; it holds no identifier, sets no cookie, and sends nothing about you to Nucleus HQ or the business before you check out. None of these scripts identifies you or tracks you.
9.2 Coded sites
Coded sites are a separate surface. A customer supplies their own HTML, and Nucleus HQ serves that HTML verbatim on an isolated origin, under a deliberately permissive content security policy that allows the customer's own external scripts and iframes to run.
Nucleus HQ injects no tracking, no analytics and no other tool of its own into a coded site. Any third-party script, tag, pixel or cookie on a coded site is the customer's own choice and is placed there by the customer. For anything the customer adds in this way, the customer is the controller. The customer is responsible for its own cookie notice, for obtaining any consent the law requires, and for answering the visitor's questions about it.
Nucleus HQ acts as processor for the hosting of that site and for the lead capture that Nucleus HQ operates on it.
The same split applies on a customer's own custom domain. Nucleus HQ lead capture does not set marketing cookies. If a customer connects tracking or capture tools of its own to pages on its own domain, consent and notices on that domain are the customer's responsibility.
10. Changes to this policy
Nucleus HQ will update this policy when the cookies we set, the browser storage we use, our subprocessors, or the legal requirements change. The current version shows its effective date.
11. Contact
Questions about cookies, browser storage, or any other privacy matter can be sent to [email protected]. Commercial and support questions can be sent to [email protected], or raised through the support route shown in the Nucleus HQ app.
The controller for Nucleus HQ is Nucleus HQ Ltd, a company registered in England and Wales, company number 17343317, registered office 71-75 Shelton Street, Covent Garden, London WC2H 9JQ.