AI PRÁCEby moadlab
How it worksFeaturesPricingFAQ
Sign inTry for free

Cookie policy

Effective from: 18 September 2026Version: 2.1
← Back to home
Contents
1.What this document covers2.Strictly necessary cookies3.Other data in browser storage4.Analytics cookies: Google Analytics 45.Cookieless measurement and error reporting6.Legal basis7.How to give, change and withdraw consent8.Third parties9.Changes to this policy
Provider: Moadlab s. r. o.Effective from: 18 September 2026Version: 2.1

1.What this document covers

This document explains what AIPráce stores on your device and reads from it when you use www.aiprace.tech.

It is not only about cookies. Under Section 109(8) of Slovak Act No. 452/2021 Coll. on electronic communications, the same rules apply to any storage of data on the user's terminal equipment and to any access to it. The provision is technology neutral, so it also covers the browser's local storage, session storage and the IndexedDB database. That is why we list everything the site keeps in those places, not just classic cookies.

How we handle the personal data these tools produce is described in our privacy policy at www.aiprace.tech/legal/gdpr.

2.Strictly necessary cookies

These cookies are required for the site to work and for you to sign in. We store them without consent, under the exemption for a service you have explicitly requested. They cannot be switched off, only deleted in your browser.

aiprace_locale

  • Purpose: the language of the web interface (sk, cs, en, pl, de). The server sets it on your first visit from the page address or your country, and it changes when you switch language.
  • Validity: 1 year, path /, SameSite=Lax. We keep the same value in the browser's local storage under the same name.

sb-…-auth-token (the ellipsis stands for our Supabase project identifier)

  • Purpose: your sign-in session. It is created only after you log in and holds your account's access and refresh token. If the value is long, the browser splits it into parts with the suffixes .0 and .1.
  • Validity: path /, SameSite=Lax, at most 400 days according to the library's setting. The access token inside is short-lived and refreshes automatically. Signing out deletes the cookie.

CookieConsent

  • Purpose: the state of your cookie consent per category (necessary, statistics, marketing), the date and time of the choice and a consent identifier. It is set on our domain by the Cookiebot consent bar; without it the bar would appear on every visit.
  • Validity: 12 months, path /. When it expires the bar asks again.

aiprace_oauth_consent

  • Purpose: when you sign up with Google, it remembers that you accepted the terms and the privacy policy (document version, language, time), so that the consent can be recorded for the new account when you return from Google.
  • Validity: 30 minutes, path /, SameSite=Lax, server only (HttpOnly). It is deleted once the sign-in is complete.

aiprace_oauth_ref

  • Purpose: when you sign up with Google, it holds the referral code of the friend who invited you, so that the reward goes to the right account. It is only set if you arrived through a referral link.
  • Validity: 30 minutes, path /, SameSite=Lax, server only (HttpOnly). It is deleted once the sign-in is complete.

Without these entries you cannot sign in or use the generator.

3.Other data in browser storage

Besides cookies, the site keeps a few entries directly in your browser. They serve only to make the service work, they are not sent to third parties and they are not used for tracking. The same consent exemption applies to them as to strictly necessary cookies.

  • aiprace_locale (local storage): a copy of the language setting from the cookie of the same name.
  • aiprace_storage (IndexedDB database, entries named thesis_save_…): the working text of your thesis from the editor, so that it survives a page reload. If the browser blocks IndexedDB, the same data goes to local storage.
  • g4_state_v1, g4_school_tpl_v1, g5_state_v1, g5_school_tpl_v1 and g5_panel_w (local storage): the brief you are filling in, the school template you used last and the width of the editor's side panel. The primary copy is stored on our server; this is a backup for connection failures.
  • g3_thesis_versions and g3_gen_… (local storage): text versions in the editor and the identifier of a running generation, so that it can be resumed after you close the tab.
  • source_search_results (local storage): the list of sources found during a search.
  • kontrola.activeReviewId (local storage): the identifier of a thesis check in progress.
  • referral_code (local storage): the referral code from the link you arrived through. It is deleted after registration.

These entries stay in your browser until you delete them. Note that clearing the site data also removes the working text of your thesis that is stored only locally.

4.Analytics cookies: Google Analytics 4

We use Google Analytics 4, provided by Google, to see which parts of the site people use and where they leave. We switch it on only if you allow the statistics category in the consent bar, either with Accept all or in the detailed settings. Google Tag Manager, through which we manage Google's measurement tags, loads under the same category. Until you consent, neither script is loaded and no request leaves this page for Google's servers.

Once you consent, the following cookies are set:

  • _ga: a browser identifier that distinguishes individual visitors. Default validity 2 years; we do not shorten it.
  • _ga_…: the session state for our measurement stream, with its identifier after the underscore. Default validity 2 years.

Advertising features are disabled: when the script loads we pass Google a setting that denies advertising storage and ad personalisation. We do not link measurement to the content of your theses.

If you withdraw consent, measurement stops before the next page load: the Google script is told that analytics storage is no longer permitted, and it is not loaded again. The _ga and _ga_… cookies already in your browser may remain until they expire; you can delete them in your browser settings. Data already sent is retained by Google according to the data-retention setting of our Google Analytics account. Its processing, including transfers outside the European Union, is described in our privacy policy.

5.Cookieless measurement and error reporting

Vercel Analytics, provided by Vercel, which hosts the site for us, counts traffic without cookies. The measurement script is loaded from our own domain, from the path /_vercel/insights/script.js. The code we embed writes nothing to cookies or to browser storage, and according to the provider's documentation the measurement creates no identifier stored on your device. Only what the browser sends with every request is evaluated: the address of the page visited, the referring page, the device type and the country.

Because nothing is stored on or read from your device in the process, Section 109(8) does not apply to this measurement and it runs without consent. The processing of the resulting data is described in our privacy policy.

Sentry is used to capture technical interface errors, for example a script failure in the editor. It sets no cookies, and session replay, which would store data in the browser, is switched off. The error report is sent to the server; nothing is stored on your device. The tool runs only when it is configured for the given environment.

6.Legal basis

We store strictly necessary cookies and functional entries in browser storage under Section 109(8) of Act No. 452/2021 Coll. on electronic communications, which allows an exemption from consent for such data: they are needed to provide the service you explicitly requested, namely signing in, the interface language and saving your work in progress.

Analytics is not strictly necessary. We therefore switch Google Analytics on only after your demonstrable consent, which we request in advance. Consent is voluntary, refusing it has no effect on how the service works, refusing is as easy in the bar as accepting, no option is pre-ticked, and we do not treat silence or continued browsing as consent. The provider of the consent bar keeps a record of your choice on our behalf, because we have to be able to prove consent. Section 7 sets out what that record contains, on what legal basis we process it and how long we keep it.

Compliance with the rules on storing data on terminal equipment is supervised by the Slovak Regulatory Authority for Electronic Communications and Postal Services. Personal data protection is supervised by the Office for Personal Data Protection of the Slovak Republic, Hraničná 12, 820 07 Bratislava.

7.How to give, change and withdraw consent

On your first visit a consent bar appears. It is operated for us by Cookiebot, a service of Usercentrics A/S. The bar offers accepting all categories, refusing everything except the necessary entries, and detailed settings per category. No option is pre-ticked, and until you decide, the analytics scripts are not loaded.

Your choice is stored in two places, and it matters which is which.

In the browser. The bar sets the CookieConsent cookie on our domain; it holds the consent state per category, the date and time of the choice and a consent identifier. That cookie decides whether Google Analytics and Google Tag Manager load. It is tied to this browser and this device: in another browser the bar asks again, and after you clear the site data it reappears. It is valid for at most 12 months, after which the bar asks again.

With the provider of the bar. Cookiebot keeps a record of every choice on our behalf, which serves as proof of consent. The record holds an anonymous consent identifier, the consent state per category, the address of the page on which you decided, the country derived from the IP address, and the date and time. It does not hold the IP address itself or your account identifier. Usercentrics A/S (Denmark, registration number 34624607) processes this data for us as a processor under a data processing agreement and keeps it for 12 months. A refusal is recorded too, because showing that analytics were rightly never switched on is the harder half of the job.

Why we do this: Section 109(8) of Act No. 452/2021 Coll. requires demonstrable consent, and Sections 15(9) and 17(9) of Act No. 108/2024 Coll. place the burden of proof on the trader. A choice that stayed only in your browser would prove nothing. The legal basis for the record is Article 6(1)(c) GDPR, compliance with the legal obligation to prove consent, together with Article 6(1)(f), our legitimate interest in defending legal claims. Deleting the cookie in your browser does not remove this record. The wider context is described in our privacy policy.

You can change your choice at any time. The footer of every page has a Cookie settings button that reopens the bar. If you refuse statistics, Google Analytics and Google Tag Manager stop loading and Google is told that analytics storage is no longer permitted. The new choice is recorded the same way as the previous one.

You can also manage cookies directly in your browser:

  • Google Chrome: Settings → Privacy and security → Cookies
  • Mozilla Firefox: Settings → Privacy & Security
  • Safari: Settings → Safari → Privacy
  • Microsoft Edge: Settings → Cookies and site permissions

Note: deleting the sign-in cookie will log you out, and clearing the site data also removes the work in progress your browser kept locally.

8.Third parties

We use no advertising cookies and no social-media cookies, and we do not sell data about your behaviour to anyone.

  • Google: Google Analytics 4 and Google Tag Manager, only after your consent. The _ga and _ga_… cookies are set on our domain.
  • Usercentrics A/S (Cookiebot): the consent bar and the record of your choice, described in section 7. The script is loaded from consent.cookiebot.com and sets the CookieConsent cookie on our domain.
  • Supabase: sign-in and database. It sets the sign-in cookie described in article 2 on our domain.
  • Sign-in with Google: if you choose to sign in with a Google account, we redirect you to a Google page, which uses its own cookies on its own domain. After you return, only the Supabase sign-in cookie remains on our domain.
  • Stripe: payment takes place on a Stripe payment page we redirect you to. Stripe sets its own cookies on its own domain. We load no Stripe script and no Stripe cookies on www.aiprace.tech.
  • Vercel: hosting and cookieless traffic measurement.

The full list of providers that process data for us is available on request at info@aiprace.tech.

9.Changes to this policy

We may update this policy, for example when a tool is added or removed. We will notify you of material changes by email or an in-app notice. If the change concerns a tool that requires consent, we will ask for it again.

The current version is always available at www.aiprace.tech/legal/cookies.

Provider: Moadlab s. r. o., Konopná ul. 3059/5, 934 01 Levice, Slovakia. Contact: info@aiprace.tech

FacebookInstagramTikTok
Navigation
HomeHow it worksFeaturesPricingFAQ
Product
GeneratorSource searchThesis checkSign inSign up
Content
Thesis sampleBlog
Language
SlovenskyČeskyEnglishPolskiDeutsch
AI PRÁCE
by moadlab

Your first draft in an hour, not weeks.

Moadlab s. r. o. · IČO: 57 704 406 · DIČ: 2122899372

AIPráce is a help tool. The output is a working draft you must review, complete and finalize yourself. You are the sole author and submitter of your thesis.

Payments secured by stripeVisaMastercardApple PayGoogle Pay
TermsComplaints policyPrivacy policyCookiesUse of AI and academic integrity