CrateCore

LEGAL DOCUMENT

CrateCore — Cookie & Local Storage Policy

Effective date: August 11, 2026 (previous versions: August 10, August 7, August 6, August 4, and July 17, 2026)

Operator: the individual developer of the CrateCore service

Contact: legal@cratecore.app

1. What this policy covers

This policy describes cookies, localStorage, and similar technologies on https://cratecore.app (including the web feed, story pages, and the sign-in page).

The mobile app is governed by the Privacy Policy: https://cratecore.app/privacy/en/. Firebase Analytics/Crashlytics in the app are not browser cookies and are disclosed there.

2. The main point

The CrateCore website shows no advertising, uses no advertising pixels, and does not track you across sites. Fonts and other page resources are served from our own domain. There are no third-party scripts on our pages other than those named in section 4.

We measure traffic with two tools, and we treat them differently:
- Cloudflare Web Analytics — a cookieless page-view counter. It stores nothing in your browser, reads no identifiers from it, and never "fingerprints" your device, so it needs no consent (section 4.2).
- Google Analytics — it sets cookies, so its script loads ONLY after you press "Accept" in the consent banner yourself. Until you do — including if you press "Decline" or simply keep reading — not a single request goes from the page to Google and not a single Google cookie appears (section 4.1). If Google Analytics is not switched on for the site yet, you will not see a banner either: there is nothing to ask about, and in that case no analytics cookies exist at all.

The site has two of its own cookies, and both are technical: your colour theme (cc_theme) and your answer to the consent banner (cc_consent). Both appear only after an action of yours, hold no identifier, and are never sent to anyone else (section 3.1).

"Accept" and "Decline" are equal: one press each, nothing hidden behind a "settings" screen, and continuing to browse is never treated as consent. We remember a refusal exactly as we remember consent, and we do not nag you in the meantime (section 7).

3. What the site stores in your browser

3.1 Cookies

Our own technical (functional) cookies. They serve what you chose yourself, so they need no separate consent:
Key | What it stores | Why | Lifetime
cc_theme | your chosen colour theme (light or dark) | opening pages straight in the theme you picked, with no flash of the wrong background | 1 year; removed when you clear the site's data in your browser
cc_consent | your answer to the consent banner: yes (accepted) or no (declined) | remembering your choice instead of asking on every page; while the value is no, Google Analytics is not loaded | 180 days; after that the banner asks again

Both are our own (first-party) cookies: only the cratecore.app server can see them, they hold no identifier, and they are not used for analytics or profiling. Until you touch the theme switch and answer the banner they do not exist at all — the site opens in its default dark theme and analytics does not run. Your system's own colour setting is neither requested nor received by us.

Google Analytics cookies. These appear ONLY after you press "Accept":
Key | What it stores | Why | Lifetime
_ga | a random browser identifier | telling a returning visit from a new visitor | up to 2 years; your browser may shorten this by itself (Safari, for example, caps such cookies at a week)
_ga_<our property identifier> | session state and session counter | counting sessions and page views | up to 2 years; same browser cap

These cookies are set on our own domain by the Google Analytics 4 script (gtag.js, loaded from googletagmanager.com). We do not enable Google Analytics advertising features (Google Signals, a Google Ads link, remarketing), so the site sets no advertising cookies such as _gcl_*. Before your "Accept" the script does not load at all — so these cookies do not exist either.

3.2 Local storage (localStorage)

localStorage is the browser's local storage; unlike cookies, its contents are not automatically sent to the server with every request. The site uses it only for features you start yourself:

Key | What it stores | Why | Lifetime
cc_web_session | sign-in session (Supabase tokens, your e-mail) | signing in on the site with an e-mail code; syncing interests with the app | until sign-out or browser data clearing
cc_reads | count of read stories (a number) | showing the "Sign in" banner once after three reads | until browser data clearing
cc_nudge_off | "banner dismissed" flag | never showing the "Sign in" banner again | until browser data clearing

Genres and eras picked on the site are not kept in the browser: before you sign in the site does not remember your interests at all, and after sign-in they go into your account's settings. This choice used to live in a cc_web_tags key; as of August 6, 2026 there is no such storage, and any value early visitors still have is removed from the browser when a page opens.

The internal admin panel (not intended for users) keeps its own sign-in session in localStorage (cc_admin_session).

4. Site analytics

The site's legal pages (including this one) are static: there is no consent banner and no Google Analytics on them. The cookieless counter from section 4.2 may count their views — it stores nothing in your browser.

4.1 Google Analytics 4 — only with your consent

What it is. Google's statistics service. It shows us aggregate reports: how many people read, which stories, where they came from, on a phone or on a computer.
When it runs. Only if you pressed "Accept" in the banner. Our banner is not an "information notice": before that press Google's script is not loaded at all, so until then your browser does not contact Google's servers and the _ga/_ga_… cookies do not exist.
What Google receives. The address of the page viewed and the referring address, information about your browser, device, and language, an approximate location (country/city) derived from your IP address, the random identifier from the _ga cookie, and page-view events. Google Analytics 4 does not log or store the IP address itself: it is used to derive the approximate location and then discarded. Your e-mail, your CrateCore account identifier, and the contents of your notes and collection are never sent to analytics.
Legal basis. Your consent: Art. 6(1)(a) GDPR for the processing and Art. 5(3) of the ePrivacy Directive for the cookies themselves. You can withdraw consent at any time (section 7); withdrawal does not affect the lawfulness of processing before it.
Who processes it and where. Google Ireland Limited as our processor; data may be transferred to Google LLC in the United States. Google bases such transfers on the EU-U.S. Data Privacy Framework (Google LLC is certified under it) and on the Standard Contractual Clauses included in Google's data processing terms. Service list: https://cratecore.app/subprocessors/en/.
How long it is kept. Cookies — per the lifetimes in section 3.1; user- and event-level data inside Google Analytics — per our property's setting, no longer than 14 months (the limit Google sets for GA4); aggregated reports — longer.

4.2 Cloudflare Web Analytics — no cookies

We count page views with Cloudflare Web Analytics, a cookieless counter. It sets no cookies, stores nothing in localStorage, and does not "fingerprint" your device. For each view Cloudflare receives the page address, the referring address, information about your browser and device, the response status code, and page-load performance metrics; the country is derived from the IP address, and the IP address itself is not stored. No individual visitor is singled out, and this counter cannot tie your page views together into a profile.
It needs no consent because it writes nothing to your device and reads no identifiers from it; the legal basis for the processing is our legitimate interest (Art. 6(1)(f) GDPR): knowing how much our own site is read, without tracking readers. You can object to this processing at legal@cratecore.app. Cloudflare is not a new recipient of data here: the site already runs on its infrastructure (section 5).

4.3 Cloudflare Turnstile — bot protection on the sign-in page

On the sign-in page (/login and /ru/login) — and ONLY there — the site loads the Cloudflare Turnstile script (challenges.cloudflare.com). Its purpose is to protect registration and the sending of sign-in codes from bots and automated abuse; the feed, story, and legal pages carry no such script.
During the check the script contacts Cloudflare's servers: they see the IP address and technical signals of the browser environment that tell a person from a bot. Turnstile sets no advertising cookies, builds no visitor profile, and does not track you across sites.
It is a strictly necessary security measure, so it needs no consent and is not placed behind the consent banner. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR): protecting the service and accounts from abuse. You can object to this processing at legal@cratecore.app. Cloudflare is not a new recipient of data here: the site already runs on its infrastructure (section 5).

5. Hosting technical data

The site runs on Cloudflare infrastructure. Like any hosting, Cloudflare processes the technical data needed to deliver pages and protect against attacks (IP address, request headers). Apart from the cookieless counter in section 4.2, we have not configured any additional cookies or analytics features of Cloudflare for this site.

Story images and covers may load directly from Wikimedia and Cover Art Archive / Internet Archive servers — those servers see your IP address when the image loads, as with any image on the internet.

6. Google News, Publisher Center, and Subscribe with Google

The CrateCore publication is registered in Google Publisher Center — a publisher console on Google's side. The registration by itself adds nothing to the site's pages and stores nothing in your browser. Pages of the site may appear in Google Search, Google News, and Discover — that is ordinary indexing of an open website, in which we send Google no data about you.

Google offers publishers a script to embed into article pages: Subscribe with Google / Reader Revenue Manager (the file swg-basic.js from the news.google.com domain). Per Google's documentation its purpose is to show paid offers, registration prompts, and surveys. CrateCore has no paid features and all content is free, so this script is not present on the site's pages.

We write this down deliberately, so that the promise in section 2 ("no third-party scripts other than those named in section 4") can be checked. If such a script ever appears, it will load only after your explicit consent and never by default. The reason: on load it contacts Google's servers, sending them the address of the page you are reading along with whatever Google cookies your browser already holds, and it writes service data into local storage. That goes beyond what is technically necessary to show you a story.

7. How to withdraw consent and manage storage

Withdrawing consent to Google Analytics is as easy as giving it — either of two ways works:
- click "Cookies" in the footer of a page;
- or open the "Appearance" menu in the header and choose "Withdraw analytics consent".
Both do the same thing: we forget your choice, delete the Google Analytics cookies from your browser and reload the page; the banner asks again, and until a new "Accept" Google Analytics is not loaded. The legal pages (including this one) are static and carry no scripts, so the "Cookies" link in their footer simply leads to this policy; to withdraw consent, open any other page of the site — the home page, for example — and use either of the ways above.

You can do the same manually in your browser settings (the section for cookies and site data for cratecore.app):
- delete the cc_consent cookie — or all cratecore.app site data. We then forget your answer, the banner asks again the next time you open a page, and until a new "Accept" Google Analytics is not loaded;
- in the same place, delete the _ga and _ga_… cookies — that erases the identifiers Google Analytics has created in your browser;
- or block cookies for cratecore.app altogether — then Google Analytics cannot set its cookies at all.

Important: if you delete only _ga but leave cc_consent=yes, analytics will start again on your next page view and create a new identifier. That is why withdrawal starts with cc_consent.

We remember your choice for 180 days — both "Accept" and "Decline". While cc_consent=no is in force, analytics is not loaded and the banner does not bother you; when the period expires (or if you delete the cookie) the banner asks again.

Besides that, you can:
- sign out on the sign-in page (removes cc_web_session);
- clear the site's data in your browser settings (this removes cc_theme as well);
- block the site from storing data in your browser settings.

If local storage is blocked, sign-in will not work; reading stories will keep working. If cookies are blocked, the site opens in its default dark theme and your choice of theme is not remembered; the consent banner will also ask on every page — there is nowhere to remember your answer.

8. Changes

We will update this policy if advertising tools, new third-party scripts, A/B tests, personalization, or new storage mechanisms are added — before they are enabled, not after.

9. Contact

Questions about this policy: legal@cratecore.app.