LEGAL · KINAVELA
Cookie and browser-storage policy
Kinavela uses the Meta Pixel only after explicit marketing consent. Before that choice, the pixel, Meta requests and Meta cookies are not loaded or set. The table describes the cookies and browser storage used by the deployed application.
| Name / technology | Purpose | Duration | Consent |
|---|---|---|---|
| Supabase Auth cookie family sb-lchpxzbjawqpirqlhqlh-auth-token | Authentication and session continuity. | Until logout or Supabase Auth session/refresh expiry. | Strictly necessary. |
| kinavela:metrics-consent in localStorage | Stores the choice to enable first-party product metrics. | Until changed or cleared. | Consent memory; metrics require opt-in. |
| kinavela:marketing-consent in localStorage and kinavela_marketing_consent cookie | Stores and mirrors the separate Meta Pixel marketing choice. | Until changed, cleared or the one-year consent cookie expires. | Necessary consent memory; Meta remains opt-in. |
| Meta _fbp and, after a Meta ad click, _fbc cookies | Browser identifiers for advertising measurement and campaign optimisation. | Typically 90 days under Meta’s Cookies Policy. | Only after marketing consent. |
| kinavela:meta-registration-event in localStorage | Stores only the random, signed conversion claim identifier to prevent duplicate CompleteRegistration events. | Until another confirmed registration, withdrawal/site-data deletion or browser clearing. | Only written after marketing consent. |
| kinavela_post_signup HTTP-only cookie | Short-lived signed routing and one-time confirmation marker after a verified signup email link; not sent to Meta. | 10 minutes or first claim. | Strictly necessary to finish confirmed registration safely. |
| kinavela:app_session_started in sessionStorage | Prevents duplicate opt-in session metric events. | Until browser tab/session ends. | Only written after metrics consent. |
| IndexedDB kinavela-offline-v1 | Optional user-selected offline Passport/Missions snapshots. | 30 days without refresh or until cleared. | User feature action; no banner needed. |
| Cache Storage kinavela-shell-v1 and service worker | Offline shell and static assets; no account content. | Until update, uninstall or browser clear. | Strictly necessary for the enabled PWA shell. |
The production Web Push public key is currently empty, so push subscription storage and delivery are not enabled. Kinavela does not embed a payment widget or store payment details in browser storage; Stripe Checkout and Portal are hosted on Stripe infrastructure. Use the control below or browser site-data controls to change or withdraw product-metrics and marketing consent separately. Withdrawal stops further Meta events; Kinavela remains usable.
General contact: contact@kinavela.com