What we store on your device
Cookie Policy
Chimesong uses cookies for sessions, request security, and consent, plus browser storage for preferences and local interaction state. No advertising or cross-site analytics vendor is enabled. Optional analytics stays off unless a valid choice enables it.
Session and request-security cookies
| Name | Purpose | Duration |
|---|---|---|
sb-*-auth-token and possible numbered chunks | Supabase sign-in session and refresh information. | Managed by the Auth client and session configuration; a token's lifetime is not the cookie's lifetime. |
sb-*-auth-token-code-verifier | Temporary verifier during PKCE sign-in or account recovery. | Auth-flow managed; cleared after use where supported. |
cs-csrf | Protect state-changing requests against cross-site request forgery. | Up to 30 days; can be renewed by requests. |
cs_consent_v1 | Your optional analytics choice. | One year from the latest saved choice. |
Clearing session cookies signs you out. Essential authentication and security continue to work when you reject optional analytics.
Saved preferences and local interaction state
These localStorage values persist until cleared by the app or your browser; they have no general automatic expiry:
themeandchimesong:experience-preferences:v1: theme, motion, sound, haptics, Quiet Sky, and performance preferences.- Legacy sensory settings may still be read during migration:
chimesong:sound,cs-sfx-enabled,cs-haptics-enabled,chimesong:quiet-sky, andchimesong:low-performance. cs-onboarding-seen: acknowledgement of onboarding.cs-retro-modeandcs-retro-mode-unlocked: an optional visual preference and its availability.chimesong:momentsPanel:openandchime-cascade-swipe-hint-shown: Moments expansion and Chime Cascade hint preferences.chimesong-daily-YYYY-MM-DD: unfinished daily-game guesses and feedback, cleared on successful completion where possible. This does not make Chimesong an offline app.
A development-only region override, cs-debug-geo, may be present in a manually configured test browser. Normal consent controls do not create it.
Optional analytics
With analytics consent, performance measurements may be sent to Chimesong's own telemetry endpoint. Payloads use coarse route categories, not entry text, post identifiers, URL queries, or an advertising identifier. The current production handlers acknowledge and discard telemetry rather than forwarding it to an analytics provider.
The existing feature-event adapter is also consent-gated; no automatic page-view tracker, Google Analytics, advertising pixel, or marketing subscription is enabled. Marketing consent is not requested for a nonexistent feature.
A regional banner can offer a choice, but its timezone-based region hint is not legal geolocation verification. Analytics stays off everywhere without valid consent, whether or not a banner appears.
Withdraw or change consent
Use Manage cookies here, in the landing footer, or in Settings. Choose Essential only to withdraw analytics consent. Every telemetry send rechecks the current choice. Changes are shared with open tabs where the browser supports BroadcastChannel and rechecked when a tab regains focus.
A browser Global Privacy Control signal forces optional analytics off, including when an older cookie allowed it. An earlier opt-in is not restored automatically after that override. Already-sent requests cannot be recalled.
Security fingerprinting is different from advertising
Chimesong uses hashed IP/browser evidence for consent and browser/region-derived fingerprints for account security. It would be inaccurate to say that no fingerprinting occurs. These security records are described in the Privacy Policy; they are not cross-site advertising profiles.
Clear site data
Your browser can delete cookies and localStorage separately. Clearing only cookies does not necessarily remove your saved theme or local game state. Removing all site data resets these browser preferences, but it does not delete your server-side account or entries; use Settings for account deletion.
Questions: klarkkrampus@gmail.com.