Cookie Policy
How this website uses cookies and other storage, what you can control, and what still needs to be verified.
Website draft updated · Version 2026-10-06
1. Scope and what these technologies mean
This draft Cookie Policy covers the Brave Tales website, not the native mobile token cache. Read it alongside the Privacy Policy for current account and child-data processing. Brave Tales is a product name; the operator’s legal identity, business location and monitored privacy contact are not confirmed.
Cookies are small values a browser stores and may send with matching requests. Similar technologies include sessionStorage (storage associated with a browser tab’s page session), localStorage (browser storage that can persist across sessions), browser asset caches and temporary application memory. Mentioning a technology here does not mean Brave Tales actively uses every kind of storage.
2. Authentication: Clerk and optional Google sign-in
Clerk manages adult account authentication, session cookies and associated authentication storage so the website can recognise a signed-in account and restrict access to its family bookshelf. The shared website provider loads Clerk on public pages too, including these policies, before you choose to sign in. Reading a public page is not consent to optional tracking.
The website’s family API requests use same-origin browser requests, with applicable session cookies attached by the browser. They do not use the native mobile SecureStore token cache. Application authentication and ownership checks protect access but do not guarantee absolute security.
If you choose Google sign-in, Google also participates in the sign-in flow. That is separate from Google Fonts delivery. The exact Clerk and Google cookie/storage names, domains, expiry values, full independent uses and environment-specific differences have not been audited. No specific provider-cookie lifetime or provider-wide no-tracking guarantee is made here.
3. Signup session flag: bt-adult-18
On the signup screen, continuing after checking “I confirm that I am 18 or older” writes bt-adult-18 with the value 1 in browser sessionStorage. The screen reads it to remember that step during the signup flow. This is a signup convenience flag, not an authentication cookie, server-saved consent record, verified age or verified parental authority.
Its scope is the site origin and browser tab’s page session. It survives refreshes; sessionStorage normally ends when that tab/window’s page session ends, although browser restore or duplication features can preserve or copy it. The application sets no timed expiry and does not explicitly remove this flag on sign-out. Clearing it may make the signup screen ask again. A signup continuation hash can also resume the flow without that flag.
Server-saved adult confirmations and mock-preview guardian-confirmation timestamps are separate records. Clearing this flag does not withdraw consent, erase those records or establish legally sufficient parental consent.
4. Temporary application memory and browser caches
The website uses React Query caches in application memory to load story information and, on signed-in family screens, account records, child profiles and saved text previews. The current website does not configure these query caches to persist in localStorage or sessionStorage. Memory is temporary while the application runs, not a fixed retention period for saved family data.
The application clears query caches on account changes and as part of its sign-out action. This is not deletion of database records, provider sessions, browser asset caches or the signup flag. Family profiles, saved snapshots, logs and backups have separate, unresolved retention practices. Signing out does not delete stored data.
Browsers may also cache website scripts, styles, images and downloaded fonts. Such asset caching is different from the application’s family-data query cache. Actual browser, hosting and provider cache lifetimes have not been verified; this draft does not promise removal of every cached copy.
5. Fonts, hosting and current tracking limits
The active website stylesheet requests Fraunces and Nunito from Google Fonts. Google’s stylesheet and font services receive external browser requests that can include IP addresses and request metadata. Font delivery is a presentation purpose, not Google account sign-in. Provider processing and cache durations remain unverified; loading fonts is not proof that Google sets a particular cookie here.
Replit provides hosting and PostgreSQL infrastructure. The application API records operational request information to run and troubleshoot the service. Request logs and server database records are not browser cookies. Hosting-level storage, logs and independent uses still need verification.
No application advertising tracker or customer analytics integration was found in the active website code reviewed for this draft. This finding does not certify that every hosting or sign-in provider avoids tracking, sale or sharing under every law. Unused UI components and installed packages are not evidence of active website storage.
Photos, live AI personalisation, payments and subscriptions are not enabled. They are not current cookie purposes or active customer-processing providers in this policy.
6. Browser controls and sign-in consequences
In your browser’s privacy or site-data settings, you can inspect and delete site cookies and storage, block cookies, limit third-party cookies or clear cached files. Controls and labels vary by browser. Use its help pages for the exact steps. Clearing only cookies may not clear sessionStorage or cached files; inspect each category separately.
Blocking or deleting authentication storage can sign you out, prevent sign-in or interrupt signup and Google sign-in. Public Privacy Policy and Cookie Policy content does not require an account and is included in the exported pages. Blocking scripts or external resources can limit interactive navigation, account controls or font appearance.
You can use Sign out to end the current website session through Clerk, but that is not account deletion or a promise that all browser/provider storage is erased. Browser controls affect your device; they do not delete saved child profiles, text previews or server records and are not a working privacy-rights request process.
7. Inventory and consent questions still unresolved
This inventory is based on active website code reviewed on 6 October 2026, not an exhaustive inspection of every signed-out, signed-in, restored-session, production-domain or provider flow. Only the application signup flag’s name and session-storage behaviour are confirmed here. Provider names, exact cookie/storage identifiers, domains, durations and purpose-by-purpose necessity classifications require a browser and provider review.
Authentication supports an adult-requested service, but this policy does not declare all provider storage strictly necessary or exempt from consent. Regional requirements, provider independent uses and any consent controls for current processing must be assessed. The website has no cookie-preference manager or Accept/Reject control; reading these drafts or checking a guardian box is not blanket consent.
Before any optional analytics, advertising or other non-essential storage is introduced, the operator must assess applicable requirements, establish effective controls where needed and update these notices. No such feature is enabled by this draft.
8. Updates and contact status
Draft website version 2026-10-06, updated 6 October 2026. This policy has not been reviewed by qualified legal counsel and is not a compliance certification. Material changes need an updated inventory and notice and, where required, advance notice or valid fresh consent.
No monitored privacy or support contact or working rights-request process is confirmed. The Contact status page is not a form and cannot submit requests. Do not send family details or identity documents to an unconfirmed address. Operator identity, location, provider arrangements, retention and a staffed rights-request channel remain publication blockers for data already collected.