Cookie and storage policy
Transparency notice: This page reflects the locally audited technical state. Provider dashboard settings and exact token or log retention periods must be confirmed manually before publication.
1. Overview
The audited code does not set Luciago marketing cookies and does not embed Google Analytics, Meta Pixel, TikTok Pixel or a Cloudflare Web Analytics script. Technically required browser storage is used for sign-in and security flows. The app uses comparable local storage through AsyncStorage.
2. Active website storage
| Name / type | Provider | Purpose | Requirement | Duration |
|---|---|---|---|---|
| Supabase Auth storage (library-managed key) | Supabase / browser | Keep the sign-in session and tokens | Technically required for persistent sign-in | Until sign-out, browser storage is cleared or expiry; exact token periods: TODO |
sessionStorage:luciago-password-recovery | Luciago / browser | Recognise a valid password recovery context | Required for this security flow | Until a successful reset or the browser session ends |
sessionStorage:luciago-delete-reauth | Luciago / browser | Associate reauthentication with the correct deletion request | Required for Google reauthentication in this flow | Until return/error or the browser session ends |
sessionStorage:luciago-cal-consent | Luciago / browser | Remember within the current tab that Cal.com was deliberately loaded | Optional | Until the browser session ends |
3. Cal.com
Cal.com is actively used for appointment booking in the organizer and verification process, but it is not loaded automatically. Only after selecting “Enable Cal.com & load booking” does the website load the external Cal.com script. Technical connection data may then be transferred to Cal.com, and Cal.com may use its own storage technologies.
TODO: Verify the Cal.com configuration, exact cookies/storage, recipients, region, contract or data processing agreement, and retention before publication.
4. Local app storage
| Name / type | Purpose | Requirement | Duration |
|---|---|---|---|
| Supabase session in AsyncStorage | Keep a registered or anonymous app session | Required by the current app architecture | Until local sign-out/app data deletion; the app then normally creates another anonymous session |
@luciago/language-v1 | Store the selected language | Functional preference | Until changed or app data is deleted |
@luciago/saved-city-v1 | Store the city selected for event filters | Optional | Until changed or app data is deleted |
@luciago/expo-push-token-v1 | Register and unregister the push device | Optional | Until push is disabled or the account is deleted |
5. Storage not found to be active
The generic file components/ui/sidebar.tsx, which is not imported by the current product pages, contains code for a sidebar_state cookie. As no active usage path was found, it is not listed as active processing.
6. Cloudflare
No Cloudflare Web Analytics beacon was found in the repository. Whether Web Analytics is enabled or regionally restricted in the Cloudflare dashboard cannot be verified locally and must be checked manually. Technically required hosting and security logs must be distinguished from optional audience measurement.
7. Controls and withdrawal
Cal.com is loaded only after a deliberate choice for the current browser session. App push can be disabled in notification settings; location, camera, media library and calendar access are controlled through the relevant operating-system permissions. Browser and app storage can also be cleared in device settings.
Last updated: 12 September 2026