Last updated: 30 September 2026.
Privacy and cookies
This page explains what data we collect on this site, and why.
Who we are
The controller is Sidenote, Lda., NIF PT514061286, with its registered office at Rua João Saraiva 36, 3.º piso, 1700-350 Lisboa.
What you decide
What we keep on your device falls into three groups. The essential ones are always on, because without them the site stops doing what you asked it to. Analytics and advertising are off until you accept them.
You can change your answer at any time from the “Cookie choices” link at the bottom of every page. Rejecting takes one click, the same as accepting. We keep your answer for 182 days and then ask again.
If you withdraw consent, we delete the cookies the site is able to delete and stop creating new ones. A few are marked so the browser keeps them out of the page’s reach, and those stay until they expire; from then on we stop using them. You can clear them yourself at any time in your browser settings.
Essential Always on.
| What it is | What it does | Kept for |
|---|---|---|
| sn_consent (local storage) | Your choices on this page, so we stop asking. | 182 days |
| theme (local storage) | The light or dark setting you picked. | Until you clear it |
| sn_lang (cookie) | The language you picked, so we stop sending you to the other one. | 1 year |
| sn_capability_session (session storage) | Your assessment answers, notes and progress, so you can continue after changing language or returning to the page. Does not include contact details. | For the tab session; starting again clears the assessment |
| __Secure-next-auth.callback-url (cookie, cal.com) | Set by Cal.com when the calendar opens on the booking page. Without it there is no booking. | Until you close the browser |
| __Secure-next-auth.csrf-token (cookie, cal.com) | Also Cal.com, on the same page, protecting the booking form. | Until you close the browser |
| __cf_bm (cookie, cal.com) | Set by Cal.com to tell automated traffic apart from real visitors on the booking page. | 30 minutes |
| nextauth.message (local storage, cal.com) | Written by the sign-in library the calendar is built on, so Cal.com pages in different tabs stay in step. | Until you clear it |
| timeOption.is24hClock (local storage, cal.com) | Whether the calendar shows times as 12 or 24 hour, so it remembers how you last read them. | Until you clear it |
| reserverUid (local storage, cal.com) | Identifies your browser to Cal.com while it holds a time slot for you during a booking. | Until you clear it |
| cf.turnstile.u (local storage, challenges.cloudflare.com) | Created by Cloudflare Turnstile, which checks that a subscription is coming from a person rather than a script. It appears when you load a page carrying a subscribe form, before you answer this banner, because without the check the form does not work. | Until you clear it |
Analytics Off until you accept.
| What it is | What it does | Kept for |
|---|---|---|
| attribution (session storage) | Which campaign or link brought you here, so a later enquiry can be credited to it. | Until you close the tab |
| _ga (cookie) | Tells your browser apart from other browsers, so we know how many people visit. | 400 days |
| _ga_* (cookie) | The same, per measurement property. What follows the underscore names the property, and it differs between the live site and the preview one. | 400 days |
| FPID (cookie) | The identifier our own server hands out, rather than one created in the browser. It is what analytics uses to tell repeat visits apart. | 400 days |
| FPLC (cookie) | A short-lived companion to the one above, also created by our server. | 20 hours |
Advertising Off until you accept.
| What it is | What it does | Kept for |
|---|---|---|
| _gcl_ls (local storage) | Written by Google Ads. It holds the ad click that brought you here, so a later enquiry can be credited to that ad. | Until you withdraw consent or clear it |
| _fbp (cookie) | Written by Meta, and the same idea as the one above. It tells your browser apart from other browsers so that an enquiry can be credited to the ad that brought you here. | 90 days |
| lastExternalReferrer (local storage) | Also Meta. It records the site you were on immediately before you arrived here. | Until you withdraw consent or clear it |
| lastExternalReferrerTime (local storage) | When that was, kept beside it. | Until you withdraw consent or clear it |
| _fbc (cookie) | Also Meta’s. It holds the ad click that brought you here, so a later enquiry can be credited to that ad. | 90 days |
| sn_assessment_run (session storage) | A random reference number for your current attempt at the assessment. It links the start, the finish, your enquiry and a call booked from the result, so the platform can tell they belong to the same attempt. | Until you close the tab, restart the assessment or withdraw consent |
| _gtmeec (cookie) | Created by our own server when Meta receives an event from us. It keeps the hashed details described under Advertising, so a later visit can be credited to the same enquiry. | 90 days |
Analytics and tag management
Tag management runs on our own domain. The script loads from sidenotehq.com on every page, before you answer, and it is what decides what runs next. While analytics and advertising are switched off, it creates no cookies and no identifiers.
Some of these cookies are created by our server rather than by the browser. Two of them, FPID and _gtmeec, are marked so that the page can neither read them nor delete them. Others are created in the browser itself, such as the language one, and Cal.com sets its own.
With analytics switched off, Google Analytics still records that the page was viewed, without cookies and without an identifier. It counts the visit, but it does not tie it to you or to your other visits.
If you accept analytics, it starts storing cookies and telling repeat visits apart. It tells us which pages get read, which get ignored, and roughly where our readers are. We do not use it to identify anyone individually, and we do not sell what it produces.
Advertising
We advertise, and we would like to know whether it works. If you accept advertising cookies, the platforms we advertise on can tell us that an ad we paid for led to a visit or an enquiry, and can show our ads to people with similar interests on other sites. Today those are Google and Meta.
If you have accepted advertising cookies and you send us your details through a form, we also pass those platforms a hashed version of the name, email address and phone number you gave us, produced with a one-way function, so that only a platform which already holds those details can recognise them and connect your enquiry to the ad that brought you here. They cannot recover your details from it. Our server keeps that hashed version in a cookie for 90 days, so a later visit from the same browser can be credited to the same enquiry.
If you have accepted advertising cookies and you take the assessment, we give that attempt a random reference number and pass it to those platforms, hashed the same way, when you start, when you finish, when you send your details and when you book a call from the result. It is not made from anything about you. It lets them see that those steps belong together and, once you send your details, whose they are.
For measuring our own campaigns, those platforms act on our instructions. For their own advertising business, they act on their own. If you accept nothing, no advertising identifier is set.
While advertising is switched off, the identifier that came with an ad click travels in the page address rather than in a cookie, so that if you accept later we can still tell which ad brought you here. Nothing about it is recorded unless you accept.
Booking a call
The booking page runs Cal.com, which is what shows the calendar and takes the booking. It sets its own cookies to hold that session together, and those count as essential: without them the booking does not complete, which is the one thing you went to that page to do.
Cal.com receives what you type into the booking form. If you accepted analytics, it also receives the campaign parameters from the link you arrived on, so we can tell which channel produced the call.
When you leave your contact details
At the end of the assessment we ask for your contact details, and the result and next step appear once you have sent them. We keep what you typed, your AI use assessment result, and which campaign or link brought you here, so we can follow up on it. That goes into Notion, which runs our contact list.
On the way there it passes through our own tag server, which removes your name, email and phone before anything is passed on to Google Analytics. Google learns that a form was submitted and nothing about who. If you accepted advertising cookies, a hashed form of your name, email address and phone number also reaches the platforms we advertise on, as described under Advertising.
If you submit the form with the newsletter box selected, Buttondown also receives your email address and your name, your AI use assessment result, and whether you asked for yourself or for a team, so what we send you can match where you are. Your IP address goes with it, which is how they tell a genuine signup from an automated one. The lists themselves are described under Newsletter. We keep your details for two years, or until you ask us to delete them.
Newsletter
If you subscribe, we keep your email address to send you the editions. Buttondown runs the lists for us, one in each language. Every edition carries an unsubscribe link, and we do not share the lists with anyone for marketing.
Before a subscription reaches Buttondown it has to pass a check that separates people from scripts. That check is Cloudflare Turnstile, so Cloudflare sees your IP address and some technical details about your browser when you subscribe. We use it on the subscribe forms and nowhere else.
Your IP address is sent to Buttondown with the subscription as well. It is how they judge whether a signup is genuine, and it is kept on your subscriber record.
Your rights
You can ask us for a copy of what we hold about you, have it corrected or deleted, object to us processing it, and withdraw consent you already gave. You can also complain to the CNPD, the Portuguese supervisory authority.
Changes
If we change something that matters, we update the date at the top of this page. If the change affects what you already agreed to, we ask you again rather than assuming.
For anything on this page, write to us and we answer: