DEEN
Back to LuciagoDeutsch
Legal

Cookie and storage policy

Transparency notice: This page reflects the locally audited technical state. Provider dashboard settings and exact token or log retention periods must be confirmed manually before publication.

1. Overview

The audited code does not set Luciago marketing cookies and does not embed Google Analytics, Meta Pixel, TikTok Pixel or a Cloudflare Web Analytics script. Technically required browser storage is used for sign-in and security flows. The app uses comparable local storage through AsyncStorage.

2. Active website storage

Name / typeProviderPurposeRequirementDuration
Supabase Auth storage
(library-managed key)
Supabase / browserKeep the sign-in session and tokensTechnically required for persistent sign-inUntil sign-out, browser storage is cleared or expiry; exact token periods: TODO
sessionStorage:luciago-password-recoveryLuciago / browserRecognise a valid password recovery contextRequired for this security flowUntil a successful reset or the browser session ends
sessionStorage:luciago-delete-reauthLuciago / browserAssociate reauthentication with the correct deletion requestRequired for Google reauthentication in this flowUntil return/error or the browser session ends
sessionStorage:luciago-cal-consentLuciago / browserRemember within the current tab that Cal.com was deliberately loadedOptionalUntil the browser session ends

3. Cal.com

Cal.com is actively used for appointment booking in the organizer and verification process, but it is not loaded automatically. Only after selecting “Enable Cal.com & load booking” does the website load the external Cal.com script. Technical connection data may then be transferred to Cal.com, and Cal.com may use its own storage technologies.

TODO: Verify the Cal.com configuration, exact cookies/storage, recipients, region, contract or data processing agreement, and retention before publication.

4. Local app storage

Name / typePurposeRequirementDuration
Supabase session in AsyncStorageKeep a registered or anonymous app sessionRequired by the current app architectureUntil local sign-out/app data deletion; the app then normally creates another anonymous session
@luciago/language-v1Store the selected languageFunctional preferenceUntil changed or app data is deleted
@luciago/saved-city-v1Store the city selected for event filtersOptionalUntil changed or app data is deleted
@luciago/expo-push-token-v1Register and unregister the push deviceOptionalUntil push is disabled or the account is deleted

5. Storage not found to be active

The generic file components/ui/sidebar.tsx, which is not imported by the current product pages, contains code for a sidebar_state cookie. As no active usage path was found, it is not listed as active processing.

6. Cloudflare

No Cloudflare Web Analytics beacon was found in the repository. Whether Web Analytics is enabled or regionally restricted in the Cloudflare dashboard cannot be verified locally and must be checked manually. Technically required hosting and security logs must be distinguished from optional audience measurement.

7. Controls and withdrawal

Cal.com is loaded only after a deliberate choice for the current browser session. App push can be disabled in notification settings; location, camera, media library and calendar access are controlled through the relevant operating-system permissions. Browser and app storage can also be cleared in device settings.

Last updated: 12 September 2026