Cookies
Cookie policy
Two technical cookies, analytics and an advertising pixel, switched off together in one click.
Two cookies are strictly necessary for this site to work and are exempt from consent on that basis. Four more are not: two for audience measurement, two for advertising. Those four start the moment you arrive — a choice we own rather than a banner that blocks the page — and one link, at the foot of every page, stops all four and deletes them.
Each is described by name, purpose, content and duration, so you can check in your own browser that nothing else is set. A cookie policy that does not name the cookies allows no verification at all.
Language cookie
Name: NEXT_LOCALE. Purpose: to remember which language you are reading, so the site root sends you back to it on your next visit.
Content: one of three public values — fr, ar or en. Nothing identifying. Duration: one year.
Deleting it breaks nothing: the site root will simply show French, and the small message under the language switcher will remind you that the other languages exist.
One key, aa.language-hint, is kept in your browser’s local storage. It is not a cookie: nothing is sent with your requests. It records only that this message has been shown to you and that you closed or followed it, so that it is not shown again. It holds nothing but a yes, and stays until you clear the site’s data.
Technical anti-spam token
Name: audit_rt. Purpose: to timestamp the page load so a human submission can be distinguished from an instant automated one.
Content: a signed timestamp, with no personal data. Duration: thirty minutes.
Without it, form submissions may be rejected.
Analytics: Google Analytics
We measure the site with Google Analytics 4: how many visits it gets and which pages are actually read. Measurement starts the moment you arrive — that is a choice we are making, and you can undo it in one click. It exists to tell us which pages genuinely answer a question; it does not exist to identify you.
Two cookies are set: _ga and _ga_ followed by the property identifier, each lasting two years. They exist to tell visitors and sessions apart. The IP address is anonymised by Google, none of this data is used for advertising, and none of it is joined to anything you send through the forms.
Two keys are kept in your browser's local storage. They are not cookies: nothing is sent with your requests. aa.analytics-consent exists only if you have turned measurement off, or turned it back on after turning it off — leave it alone and the key is absent. aa.analytics-notice records that you closed the strip announcing the measurement, so it is not shown to you again. Both stay until you clear the site's data.
You can stop the measurement at any time through the "Turn off audience measurement" link at the foot of every page. It acts immediately: measurement stops on the page you are reading, with no reload, the two cookies above are deleted, and Google is told that storage is no longer permitted. The same link reads "Turn on audience measurement" if you change your mind.
Advertising measurement: the Meta pixel
We have installed the Meta pixel on this site — the measurement code behind Facebook and Instagram. It does not do the same job as Google Analytics, and that is worth saying sharply: Analytics tells us which pages get read, the pixel tells Meta which advertisement produced an audit request. It is what lets us buy advertising without wasting it, and it is also what makes it an advertising tracker in the full sense of the term.
Two cookies are set. _fbp, lasting three months: a random identifier assigned to your browser. _fbc, lasting the same, written only if you arrived here by clicking one of our advertisements, in which case it records which one. Meta receives the pages you view on this site, and the moments when you send a form, request an appointment or open a conversation with us. If you have a Facebook or Instagram account, Meta can join all of that to that account: this is precisely what the pixel is for, and we have no way of preventing it.
What Meta does not receive from us: the content of your messages, your name, your telephone number or your email address. The pixel reports that a form was sent, not what was in it.
The same "Turn off audience measurement" link, at the foot of every page, stops the pixel at the same time as Google Analytics and deletes its two cookies. There are deliberately not two separate settings: a button that switched off one tool and left the other working would be a lie told in the interface.
Client portal: guides kept for offline reading
Name: algeria-agency-help-v1, in the browser cache storage. It is not a cookie: nothing from it is sent with your requests, and it only exists if you sign in to your portal and open at least one help guide.
Contents: the guide pages you have opened, exactly as they were served to you, so they stay readable with no connection. No invoice, no message and no document is written to it. Duration: until you clear the site data, or a new version of the guides replaces the old one.
Deleting it breaks nothing: the guides reload the next time you sign in.
The sign-in cookie
It only exists if you have access to your client area or to our internal console. A visitor reading the blog does not have one.
Name: it starts with sb- and ends with -auth-token; it is issued and read by Supabase, our authentication provider, and is not written by us. Content: the token proving you are signed in. Duration: the length of your session, renewed while you stay active, deleted when you sign out.
Until August 2026 two separate sign-in cookies were confined to the /admin and /dashboard addresses, so they never accompanied a public page. This one applies to the whole site: if you are signed in and you read an article, it goes with the request. It does nothing but identify you, and it is never used for analytics.
Deleting it signs you out. That is all it does.
Sahbi: the conversation identifier
Name: aa.sahbi-thread, in your browser’s session storage. It is not a cookie: nothing is sent automatically with your requests, and the key only exists if you open the assistant.
Contents: a random identifier, unconnected to your identity. It ties the questions in one conversation together and counts your messages for the rate limit. Duration: the life of the tab — closing the tab deletes it.
A second key, aa.sahbi-nudged, records only that the assistant’s greeting has already been shown to you, so that it is not shown again on every page. It holds nothing but a yes, and it too disappears when the tab closes.
A third, aa.sahbi-nudged-dash, does exactly the same inside your client area and inside the team console: the message there is different, so it is counted separately. It holds nothing but a yes, and disappears when the tab closes.
A fourth, aa.mfa-nudge, records that you dismissed the offer to turn on two-factor authentication for your account. It holds nothing but a yes, and stays until you clear the site’s data — longer than the ones above, because an offer that returns every time the browser reopens is an offer that ends up ignored. It disappears by itself if you turn two-factor on.
A fifth, aa.demo-nudged, does the same on the demonstration pages: it records that the demonstration assistant’s greeting has already been shown to you. One key for every demonstration, holding nothing but a yes, and it disappears when the tab closes.
Deleting it breaks nothing: the assistant makes another one and starts an empty conversation. Sahbi is never required to use the site: every page it cites can be read directly.
What we do not use
This page long denied carrying any social-network tracker of this kind. That denial stopped being true in September 2026, and the section above describes what replaced it: the Meta pixel is an advertising tracker, it sets two cookies, and we would rather write that plainly than file it behind a form of words.
What remains true: no sale and no sharing of your browsing data with anybody else, no cookie set by a third-party advertiser, and two measurement tools in total — Google Analytics and the Meta pixel — which the same link switches off together. Other providers do receive data in specific cases — sending the email that notifies us of your message, the Sahbi assistant, and WhatsApp if you choose that channel — but none of them sets a cookie or follows you from page to page; they are described in the privacy policy.
If another tool were ever added, this page would be updated before anything was set, and it would appear in the list above with its duration and its purpose. We do not treat this policy as a document that is written once.
Deleting or blocking these cookies
For analytics, the "Turn off audience measurement" link at the foot of the page is enough. For everything else, browsers let you inspect, delete and block the cookies a site sets from their privacy settings, and we provide no separate tool for it: the browser does it better, and you do not have to trust us to carry it out.
What that changes in practice: deleting the language cookie sends you back to automatic detection, and blocking the anti-spam token can cause form submissions to be rejected. No other function of the site depends on either.
Updates to this policy
This page describes the real state of the site as of its last modification. It is updated whenever a cookie is added or removed, not on a schedule.
A cookie that is not strictly necessary is named here, with its purpose and its duration, before it goes into service, and it can be refused in one click from the foot of any page. This sentence said until September 2026 that such a cookie was only set after explicit consent; it had become false in August 2026, when audience measurement moved to starting immediately with a one-click refusal, and we would rather correct the sentence than leave it describing a site that no longer exists.