Cookie Policy

ypai.ai

Effective: September 27, 2026 • Last Updated: September 28, 2026

1. Summary

  • Google Ads, Google Analytics and PostHog do not load on ypai.ai until you click Accept in the cookie banner. If you click Reject, or make no choice, none of them loads, no request is sent to them, and they store nothing on your device.
  • A few things run for every visitor because the site needs them or to keep it working: your cookie choice, Cloudflare's delivery and form protection, and error monitoring with Sentry. Section 3 lists them.
  • You can change or withdraw your choice at any time with the Cookie settings button in the site footer.

2. What This Policy Covers

This policy is about cookies and similar technologies on ypai.ai: small files and entries that a website stores in your browser (cookies, local storage and session storage), and scripts from other companies that a page loads. Local storage stays until it is removed; session storage is deleted when you close the browser tab.

How we handle personal data more broadly, including the enquiries you send us, is described in the Privacy Policy.

3. What Runs for Every Visitor

On an ordinary page view ypai.ai sets no cookies. The entries below are stored or loaded whatever you choose in the banner.

3.1 Stored in your browser

3.2 Cloudflare: delivery, security and form protection

Cloudflare delivers every page of ypai.ai and protects it against attacks, so it processes your IP address and the details of each request. If Cloudflare's security checks challenge your browser, Cloudflare may set a security cookie (such as cf_clearance) to remember that you passed.

Pages with a protected enquiry form load Cloudflare Turnstile from challenges.cloudflare.com when the page opens. It checks that the form is used by a person rather than a bot. When you send the form, the result of the check and your IP address go to Cloudflare to verify it. Turnstile sets no cookies on ypai.ai.

The document-signing pages (addresses starting with /sign/) load their handwriting fonts from Google Fonts, which gives Google your IP address and the page address. They have no site footer; use Cookie settings on any other page to change your choice.

3.3 Sentry: error monitoring

Sentry, run by Functional Software, Inc., receives reports of errors that happen in the page, with the page address, the page you came from, your browser, language and screen size. It also receives performance timings for about 2 of every 100 page loads. The script starts at your first interaction with the page or after a few seconds. To show what led to an error, it keeps a short recording of the page in your browser's memory, for that page only, and sends it with 1 in 4 errors. In that recording all text on the page and everything you type is masked, and images and media are blocked. Sentry stores this data in its EU region (Germany). We use it to keep the site working and secure.

3.4 Only when you use a feature

  • Blog search stores your last five searches in local storage (ypai-search-recent) so you can repeat them. They stay until you clear your browser's site data.
  • Booking a meeting on the scheduling page stores the booking reference in session storage (bookingReference) until you close the tab.
  • In-browser AI demos download their model files when you start them (from ypai.ai and, on some pages, the transformers.js library from cdn.jsdelivr.net) and keep them in your browser's cache storage so the demo starts faster next time. Clearing your browser's site data removes them.

4. What Runs Only If You Accept

Clicking Accept loads the tools below on that page and on later visits for as long as your choice is valid. Clicking Reject, or making no choice, loads none of them.

4.1 Google Ads conversion measurement

Google Ads tells us which of our ad campaigns lead to visits and enquiries. If you arrived by clicking one of our Google ads, the tag stores the click identifier. On the annotation service pages, when you send the short enquiry form, your email address is passed to the Google tag, which hashes it before sending it to Google Ads to match the enquiry to the ad click (Google calls this enhanced conversions).

We do not use Google Ads for remarketing or personalised advertising. The tag tells Google that ad personalisation is not allowed, so your visits to ypai.ai are not used to personalise the ads you see.

4.2 Google Analytics 4

Google Analytics counts visits and pages viewed and shows how visitors arrive, for example from a search engine or a campaign link. Google signals, which links activity to signed-in Google accounts, is switched off. Google Analytics 4 does not log or store IP addresses; Google uses the address to derive an approximate location and then discards it.

4.3 PostHog product analytics

PostHog records the pages you view, when you leave a page, and what you click, so we can see which pages and paths work. Session recording is off. We use PostHog's EU Cloud. PostHog is not loaded if your browser sends a Do Not Track signal, even after you accept.

4.4 Where you came from

We remember, for the rest of the browser tab, the site that sent you to ypai.ai, the first page you opened and any campaign tags in the link (utm_ parameters), and send them with an enquiry form you submit, so we know which channel it came from.

4.5 What these tools store

5. Your Choice and How to Change It

5.1 The cookie banner

On your first visit the banner asks for your choice. Accept and Reject are equally easy to click and nothing is pre-selected. Your choice is kept in your browser for 12 months, after which we ask again.

5.2 Changing or withdrawing your choice

Use the Cookie settings button in the site footer to reopen the banner, then click Accept or Reject. If you withdraw by clicking Reject, we switch Google and PostHog off in every open ypai.ai tab, remove the cookies and storage entries in section 4.5 from ypai.ai, and do not load them again. Withdrawal does not affect what was collected while your consent was valid.

5.3 Browser settings and opt-out tools

You can also block or delete cookies and site data in your browser. Blocking everything can stop parts of the site, such as the enquiry forms, from working.

6. Providers

These companies receive data through the technologies above. Each has its own privacy policy. The Privacy Policy explains our legal bases, retention and transfers outside the EEA.

Cloudflare

Delivery, security and Turnstile form protection. Every visitor.

Cloudflare Privacy Policy

Sentry

Error and performance monitoring, EU region. Every visitor.

Sentry Privacy Policy

Google

Google Ads and Google Analytics 4. Only if you accept.

How Google uses data from sites that use its services

PostHog

Product analytics, EU Cloud. Only if you accept.

PostHog Privacy Policy

7. Your Rights

Under the GDPR, as it applies in Norway and the rest of the EEA, you can withdraw your consent at any time (section 5.2) and ask us for access to, correction or deletion of personal data we hold about you. You can object to processing we base on our legitimate interests, such as error monitoring. The Privacy Policy describes these rights in full.

You also have the right to complain to the Norwegian Data Protection Authority (Datatilsynet), or to the supervisory authority where you live or work.

Norwegian Data Protection Authority (Datatilsynet)

Website: datatilsynet.no

8. freelancer.ypai.ai

Our contributor site, freelancer.ypai.ai, follows the same rule: PostHog loads only after you click Accept in its cookie banner. Browsers keep storage separately for each site, so you make the choice there separately. Google Ads and Google Analytics are not used there.

8.1 For every visitor

  • Your cookie choice, in local storage (ypai-cookie-consent and ypai-cookie-consent-date), for 12 months.
  • Sentry error monitoring (EU region): error reports, a session signal for each page load, performance timings for about 5 of every 100 page loads, and with each error a short recording of the page with all text masked and media blocked. It uses ypai.sentry.budget in session storage.
  • The site reports errors, failed requests, form submissions, clicks on links and buttons, page loads and loading speed to our own server. The reports store no identifiers; when you are signed in, the request carries your sign-in cookie, which the server uses only to note that you are signed in.

8.2 When you use the site

  • Signing in sets fl_session, which keeps you signed in until 30 days after your last visit. Signing in with Google also sets fl_oauth_state for 10 minutes. If no contributor account matches your Google account, fl_google_apply_handoff carries that Google email address to the application form for 5 minutes.
  • Application and profile forms keep unsaved drafts in local storage so you do not lose your work.

8.3 Only if you accept

PostHog records the pages you view, when you leave a page, what you click, clicks that do nothing, and errors in the page, and stores the same entries as in section 4.5 (ph_<project key>_…). Session recording is off.

Where you came from: the site that sent you, the first page you opened and any campaign tags in the link are kept in session storage (yp_fl_first_touch) until you close the tab, and are sent with a job application.

Withdraw with Cookie settings in the site's footer or, when signed in, under Settings. Withdrawing stops PostHog and removes its entries and yp_fl_first_touch.

9. Contact Us

Data controller: Your Personal AI AS (YPAI), organisation number 933 915 778, Lysaker torg 5, 1366 Lysaker, Norway

Contact: contact@ypai.ai or the contact form

Data protection requests: submit a data request

When the cookies or tools we use change, we update this policy and the date at the top of this page.