Legal
Cookie Policy
Short version: this marketing site sets no cookies. The application sets three, all strictly necessary to keep you signed in and secure. There is no advertising or cross-site tracking anywhere.
Cookie Policy
1. What this covers
This policy explains the cookies and similar storage technologies used oneluvana.com (this marketing site) andapp.eluvana.com (the application). It sits alongside thePrivacy Policy, which covers personal data more broadly.
2. This marketing site sets no cookies
The pages you are reading now are static HTML. They set no cookies, no local storage and no persistent identifiers. There is no consent banner because there is nothing to consent to.
Web fonts are loaded from Google Fonts, which serves the font files and receives your IP address and user agent as part of that request. Google states it does not set cookies for font requests. If you would rather not make that request at all, a content blocker will prevent it and the site falls back to your system fonts.
3. Cookies used in the application
All three are functional and strictly necessary. They are first-party, set by us, and exempt from consent requirements under the ePrivacy Directive and UK PECR because the service cannot work without them. None of them track you across sites.
| Cookie | Set by | Purpose | Type | Expires |
|---|---|---|---|---|
session | app.eluvana.com | Keeps you signed in for the current browsing session. Without it, every page load would sign you out. | Functional — strictly necessary | Session (cleared when the browser closes) |
refresh_token | app.eluvana.com | Lets the app renew your session without asking you to sign in again each time you return. | Functional — strictly necessary | 30 days |
csrf_token | app.eluvana.com | Protects form and API submissions against cross-site request forgery. | Functional — strictly necessary (security) | Session |
All three are set with HttpOnly, Secure andSameSite attributes, so they cannot be read by page scripts and are not sent on cross-site requests.
4. Cookies we do not use
- No advertising cookies. We do not advertise using cookie-based targeting and we run no ad-network pixels.
- No cross-site tracking. No third-party trackers, no fingerprinting, no data brokers.
- No social media pixels. No Meta pixel, no LinkedIn Insight Tag, no TikTok pixel.
- No A/B testing or session-replay cookies.
5. Analytics
Any analytics we run is cookieless. It records aggregate page views and referrers without setting a cookie, without a persistent identifier, and without building a profile that follows you across sites. If we ever adopt an analytics approach that requires a cookie, we will ask for your consent first and update this page before doing so.
6. Payment checkout
Checkout runs on Polar, who act as Merchant of Record. When you are on Polar's checkout you are on Polar's domain, under Polar's cookie policy — including any cookies they need for fraud prevention and payment processing. We do not control those and cannot set or read them.
7. Managing cookies
You can block or delete cookies in your browser settings. Because the application's cookies are strictly necessary, blocking them means you will not be able to stay signed in — the app will not work. Blocking cookies has no effect on this marketing site, since it sets none.
8. Other storage
The application uses localStorage for interface preferences — such as a remembered export size or a collapsed panel. This stays in your browser, is never transmitted to us, and can be cleared through your browser's site-data controls.
9. Changes and contact
If the cookies we use change, this page is updated and the "last updated" date at the top changes with it. Questions go tosupport@eluvana.com.