Skip to main content

Chlorofishy — Cookie Policy

Version: v5

Effective Date: August 17, 2026

Last Updated: August 17, 2026


1. Introduction

This Cookie Policy ("Policy") explains how Chlorofishy ("Operator," "we," "us," "our") — a trade name under which an individual sole proprietor offers the Service, with notice address at 530 W Ojai Ave, Suite 201, Ojai, CA 93023 — uses cookies, web local storage, and similar technologies on the Chlorofishy website at chlorofishy.com, and how the equivalent storage mechanisms work in the Chlorofishy mobile application for iOS and Android (the "Mobile App").

This Policy supplements the Privacy Policy and the Terms of Service. Capitalized terms not defined here have the meanings given in those documents.

The web Service uses a cookie banner to obtain your consent for non-essential cookies in accordance with the EU ePrivacy Directive ("ePD"), GDPR, and the California Consumer Privacy Act / California Privacy Rights Act ("CCPA/CPRA"). The Mobile App uses an in-app consent gate with the same effect.


2. What Are Cookies and Similar Technologies?

Cookies are small text files placed on your device by a website that record information about your visit. They allow the site to remember your preferences, keep you signed in, and (with your consent) gather analytics.

Web local storage is similar but persists in your browser's local storage area instead of being sent with every HTTP request. It is typically used for application state and preferences.

Mobile SecureStore (the iOS Keychain and Android Keystore) is the equivalent on-device storage for the Mobile App. Because mobile apps do not use HTTP cookies, the Mobile App stores its session, consent, and preferences in SecureStore on your device.

This Policy treats all three (cookies, web local storage, mobile SecureStore) under the same consent rules.


3. Categories of Cookies and Storage

We use four categories. Essential storage is set without your consent because the Service cannot function without it. Functional and Analytics storage require your active opt-in via the cookie banner (web) or in-app consent gate (mobile). Marketing / Advertising storage requires your active opt-in if you are in the European Economic Area, the United Kingdom, or Switzerland; outside those jurisdictions it is enabled by default and you may switch it off at any time using the Marketing / Advertising toggle in the cookie banner, the consent panel accessible from the footer, or a Global Privacy Control signal.

CategoryPurposeConsent required?
EssentialAuthentication, ToS gate, the consent record itselfNo — necessary for the Service
FunctionalUser preferences (selected layers, last camera, default region, units)Yes — opt-in
AnalyticsPostHog product analytics; Vercel AnalyticsYes — opt-in
Marketing / AdvertisingGoogle Ads and Meta advertising services: conversion measurement and, where you have consented, ad personalization, remarketing, and audience building (see Section 4.4).Depends on location — opt-in in the EEA, UK, and Switzerland; on by default elsewhere, with a separate toggle to switch it off

4. Web Cookie Inventory

4.1 Strictly Essential

CookieSet byPurposeLifetime
sb-jpbncxzildmtskmppqdx-auth-token (and similar sb-*-auth-token cookies)Supabase AuthKeeps you signed in. Without this, every request would require re-authentication.Session / refresh-token lifetime (rolling)
cookie_consentOperatorRecords your consent choices (analytics on/off, functional on/off, version, timestamp). The presence and version of this cookie is what suppresses the banner on subsequent visits.365 days
guest_tosOperatorRecords that you accepted the current version of the Terms of Service as a guest (no account). Mirrored in profiles.tos_agreed_version once you create an account.365 days

4.2 Functional (opt-in)

The Service does not currently set any browser cookies in the Functional category. Functional preferences are stored in your browser's web local storage (see Section 5) and only persisted there after you grant Functional consent.

4.3 Analytics (opt-in)

CookieSet byPurposeLifetime
ph_phc_* (e.g., ph_<project-key>_posthog)PostHogDistinguishes anonymous users, persists feature flags, and identifies authenticated users after sign-in.365 days
Vercel Analytics request beaconsVercelAggregate page-view and Web Vitals telemetry. Vercel Analytics does not set persistent cookies; it sends beacons only when a request is in flight.n/a

PostHog cookies are set only after you grant analytics consent. If you reject or have not yet chosen, the PostHog SDK initializes in opt-out mode and does not write cookies, send events, or capture session replays. Withdrawing analytics consent calls the SDK's opt_out_capturing() and clears existing PostHog cookies.

4.4 Marketing / Advertising

The web Service uses Google Ads conversion tracking (gtag.js, loaded via Google Consent Mode v2) to measure whether a visit resulted in a completed subscription checkout and, where you have accepted Marketing cookies, for ad personalization and remarketing. The Consent Mode ad_personalization signal is governed by the Marketing / Advertising consent category and is denied whenever that category is off or a Global Privacy Control signal is present. Where you have accepted Marketing cookies, the Service uses the Meta Pixel and the Meta Conversions API for advertising measurement and remarketing. The Meta Pixel does not load, and no data is transmitted to Meta, if you decline Marketing cookies or send a Global Privacy Control signal. Other than the Google and Meta services described in this Policy, the Service does not use social-media tracking pixels or any other third-party advertising network.

Google Ads storage is governed by the Marketing / Advertising consent category, which is separate from the Analytics category that governs PostHog and Vercel Analytics. The Service issues a region-scoped Consent Mode default: for visitors Google identifies by IP address as located in the European Economic Area, the United Kingdom, or Switzerland, the ad_storage and ad_user_data signals default to denied and are set to granted only if you affirmatively opt in. For visitors outside those jurisdictions, ad_storage and ad_user_data default to granted unless you switch off the Marketing / Advertising category or a Global Privacy Control signal is present (see Section 8.3). In either case, where those signals are granted, Google may set conversion-measurement cookies:

CookieSet byPurposeLifetime
_gcl_* (e.g., _gcl_au, _gcl_aw)Google Ads (gtag.js)Links an ad click to a completed checkout for conversion measurementUp to 90 days
_fbpMeta Platforms, Inc.Distinguishes browsers for advertising measurement and remarketing; set only with Marketing consent90 days
_fbcMeta Platforms, Inc.Stores the Meta advertising click identifier (fbclid) for conversion attribution; set only with Marketing consent90 days
chlorofishy_click_idsChlorofishy (first party)Stores advertising click identifiers (fbclid, gclid, gbraid, wbraid, msclkid, rdt_cid) and campaign parameters (utm_source, utm_medium, utm_campaign, utm_term, utm_content) with click timestamps for conversion attribution; set only with Marketing consent90 days
chlorofishy_lvChlorofishy (first party)Opaque, randomly generated identifier used solely to connect a tagged advertising landing visit to your account if you later sign up, for first-party measurement of which channels produce signups; set only with Marketing consent. Not readable by page scripts (HttpOnly).90 days

The analytics_storage signal defaults to denied for every visitor in every jurisdiction. The ad_personalization signal follows the same region-scoped default as ad_storage and ad_user_data: denied by default for visitors in the EEA, UK, or Switzerland unless you opt in, and granted by default elsewhere unless you switch off the Marketing / Advertising category or a Global Privacy Control signal is present. Where ad_storage and ad_user_data are denied — because you are in the EEA, UK, or Switzerland and have not opted in, because you switched off the Marketing / Advertising category, or because a Global Privacy Control signal is present — no advertising cookie is set, and Google may receive only limited, cookieless conversion signals (conversions are modeled rather than directly measured). Switching off the Marketing / Advertising category at any time returns the ad_storage and ad_user_data signals to denied. Region is determined by Google from your IP address at the time the tag loads; Operator does not control or independently verify that determination. This Section is consistent with, and supplemented by, Privacy Policy Sections 6.4 and 6.5.

Enhanced conversions. When you complete a subscription checkout, the Service supplies the email address associated with your account to Google in hashed form, so that Google can match the conversion to the ad click that preceded it. Hashing is performed in your browser before transmission; Google does not receive your email address in readable form. This occurs only where the Marketing / Advertising category is enabled and no Global Privacy Control signal is present, and only at the moment a checkout completes. Google uses this enhanced-conversions data for conversion measurement; it is separate from the Meta Conversions API data flow described in Section 4.4 and in Privacy Policy Section 6.4.

First-party campaign landing measurement. Separately from the cookies above, when you arrive at the Service from a link carrying a recognized advertising or campaign identifier, Chlorofishy records that visit server-side (landing page, referring page, browser user agent, the campaign identifier, and a timestamp) regardless of your cookie consent choices, since this record involves no browser storage and is used solely for first-party measurement of how many visits a channel produced — never sent to PostHog or any advertising platform, never used to build advertising audiences. The chlorofishy_lv cookie above is what lets that record be connected to your account if you sign up; without Marketing consent, the record is still created (so the visit is counted) but the advertising click identifier is removed before it is stored and no chlorofishy_lv cookie is set, so the visit can never be connected to an account. This record is retained for twelve (12) months and then anonymized, longer than this table's other retention windows — see Privacy Policy Sections 6.6 and 7.6.


5. Web Local Storage

The web Service uses your browser's local storage to remember on-device preferences. These keys are read on page load and written when you change a preference. They do not transmit to the server unless you save preferences to your authenticated profile.

KeyPurposeCategory
chlorofishy_preferencesUnified preferences blob (default region, units, default layer, default source)Functional
chlorofishy_savedCameraLast map camera (zoom, center) for restoration on next loadFunctional
chlorofishy_compareModeCompare-mode state (enabled/disabled, layer pairing)Functional
chlorofishy_pending_signup_methodShort-lived stash (cleared after a successful sign-up event fires) used to attribute the signed_up analytics event to its sign-in method (Google, Apple, magic link, password)Essential — required for accurate analytics attribution; cleared within 60 seconds of account creation

6. Mobile-App On-Device Storage (SecureStore)

The Mobile App does not use browser cookies. Instead, it stores the equivalent values in the device's secure storage (iOS Keychain, Android Keystore). These are accessible only to the Mobile App.

KeyPurposeCategory
sb-* Supabase auth tokenKeeps you signed in to the Mobile AppEssential
chlorofishy_guest_tosRecords that you accepted the current version of the Terms of Service as a guest. Compared against the current ToS version on each launch.Essential
chlorofishy_pending_signup_methodShort-lived stash used to attribute a sign-up event (Google / Apple / email). Cleared after the event fires or after 60 seconds.Essential
chlorofishy_cookie_consentRecords your analytics-consent choice. The Mobile App's PostHog SDK initializes in opt-out mode by default and only flips to opt-in after a positive value here.Essential
Mobile preferences (when locally cached)Default region, units, default layer, last-viewed passFunctional

7. Server-Side Mirror

For authenticated users, your cookie consent record is mirrored to your Supabase profile (profiles.cookie_consent JSONB) so that signing in on a different device honors the same choices. The mirror is best-effort and triggered each time you change consent. The on-device record is the source of truth on a given device until the next mirror reconciliation.


8. Managing Your Consent

8.1 Web

  • First visit: the cookie banner appears at the bottom of the screen with three options:
    • Accept all — opts you into functional, analytics, and marketing storage.
    • Reject non-essential — keeps only essential cookies set; functional, analytics, and marketing are off.
    • Manage preferences — opens per-category toggles (Essential is always on; Functional and Analytics are off by default; Marketing / Advertising is on by default outside the EEA, UK, and Switzerland, and off by default within them). Each toggle shows its current state when the panel opens, so you can see what is enabled before you change anything.
  • Change your mind: open the consent panel from the footer link on any page and toggle categories on or off. Toggling Analytics off triggers posthog.opt_out_capturing() and clears PostHog cookies.
  • Browser controls: you can also delete cookies through your browser's settings; deleting cookie_consent will cause the banner to reappear on next visit. Deleting sb-*-auth-token will sign you out.
  • A "Do Not Sell or Share My Personal Information" link appears in the site footer and in the account menu. Selecting it reopens the consent panel, where you may review or withdraw your Marketing consent at any time. Withdrawal takes effect immediately: advertising scripts stop loading, and advertising cookies set by Operator are deleted. Operator also honors the Global Privacy Control signal as an opt-out of sharing for cross-context behavioral advertising.

8.2 Mobile App

  • First launch: an in-app consent banner appears with the same three options as the web banner.
  • Change your mind: open the in-app consent control (accessible from the app's footer / settings flow) and toggle categories on or off. Toggling Analytics off calls posthog.optOut() and stops further analytics traffic.
  • Reset everything: uninstalling the Mobile App removes all SecureStore values; reinstalling brings you back to a fresh consent state.

8.3 Do Not Track / Global Privacy Control

The web Service treats a Global Privacy Control ("GPC") signal as a valid opt-out request. While a GPC signal is present, the Service treats Analytics — and with it advertising conversion measurement (Section 4.4) — as declined for that browser, regardless of any previously stored consent choice: PostHog, Vercel Analytics, and Google Ads conversion cookies are not set and no data is sent to those vendors. Operator does not sell personal information or share it for cross-context behavioral advertising (see Privacy Policy Sections 6.5 and 11.3). Industry standards for "Do Not Track" remain non-uniform; the Service does not act on DNT signals separately from GPC.


9. Third-Party Cookies

The only third parties that set cookies through the Service are:

  • Supabase — sets sb-*-auth-token cookies for authentication. Strictly essential.
  • Stripe — sets cookies during the Stripe-hosted checkout and billing portal pages. Stripe's cookies are governed by Stripe's Cookie Policy. Operator does not control these cookies; they are set on Stripe domains during checkout flow.
  • PostHog — sets ph_phc_* cookies after analytics opt-in. Governed by PostHog's Privacy Policy.
  • Google (Google Ads) — sets _gcl_* conversion-measurement cookies where the Marketing / Advertising category is enabled, under Google Consent Mode v2, with ad_personalization governed by the Marketing / Advertising consent category (see Section 4.4). Governed by Google's Privacy Policy.
  • Meta Platforms, Inc. — sets the _fbp and _fbc cookies for advertising measurement and remarketing via the Meta Pixel, only where the Marketing / Advertising consent category is enabled and no Global Privacy Control signal is present (see Section 4.4). Meta's use of this data is described in Meta's own privacy policy.
  • Cloudflare — may set short-lived security cookies on Cloudflare domains (e.g., tiles-v2.chlorofishy.com, buoys.chlorofishy.com) for bot protection and rate limiting. Strictly essential for content delivery.
  • Vercel — may set a __vercel_* cookie during the request lifecycle. Used for routing and bot protection. Strictly essential.

The Service does not embed any social media widgets or third-party content that sets advertising cookies, other than the Google Ads conversion-measurement tag described in Section 4.4.


10. Changes to This Policy

We may update this Policy from time to time. We will indicate updates by changing the "Last Updated" date. Material changes (such as adding a new analytics vendor or a new category of storage) trigger the cookie banner to reappear via a version bump on CURRENT_CONSENT_VERSION, prompting you to re-confirm your consent before non-essential storage resumes.


11. Contact

For questions about this Policy:


This Cookie Policy (Version v3) was last updated on August 1, 2026.