Skip to content

Cookie Policy

Last updated: August 21, 2026 · Version 2026-08-21

This Cookie Policy explains how Kaify Ai (https://kaifyai.org) uses cookies, pixels, tags, local storage, session storage, and similar browser technologies. Native mobile SDKs (for example push tokens) are not cookies and are described in the Privacy Policy.

1. Overview and consent

Strictly necessary technologies run to provide the service you request. Non-essential analytics or marketing technologies activate only after you accept them in our cookie banner (Accept All / Reject optional / Manage preferences where offered). Categories are not pre-enabled for optional use. You can change preferences by clearing kaify_cookie_consent or using Cookie Preferences links. Global Privacy Control will be honored where legally required and technically supported.

2. Strictly necessary

  • Supabase auth cookies — session / signed-in state (first-party; duration per auth SDK)
  • kaify_csrf — CSRF protection for sensitive actions (first-party cookie)
  • kaify_stepup — step-up MFA window (first-party cookie)
  • kaify_admin_hub — admin hub session when applicable (first-party cookie)
  • kaify-lang — locale preference (cookie and/or localStorage)
  • kaify_cookie_consent — stores your cookie choice, version, and timestamp (localStorage)
  • kaify_legal_pending — temporary pre-auth Terms/Privacy acceptance sync (localStorage)
  • Paddle Checkout technologies — necessary to open and secure a checkout you request (third-party; vendor-controlled)

3. Functional (product preferences)

These improve UX and are generally first-party localStorage (not advertising). Examples: kaify-theme, kaify-unit, sound preferences, streak/gamification client state, referral codes, OTP resume (sessionStorage), analytics cache bundle (sessionStorage). They are not used to sell your data.

4. Analytics (optional — consent required where applicable)

  • Vercel Analytics / Speed Insights — anonymous or pseudonymous usage and performance metrics (loaded only after optional cookie acceptance; skipped on native app shell)
  • First-party product analytics (workout/meal aggregates stored in Kaify Ai databases) are not browser advertising cookies; see Privacy Policy

5. Marketing / third-party (optional or contextual)

  • Sender.net — waitlist/marketing email tooling when the optional analytics/marketing path is accepted (may set third-party cookies/scripts)
  • Google reCAPTCHA — bot protection on waitlist forms (may set cookies; necessary for that form's abuse protection)

Termly embeds are not the canonical Privacy Policy host; if a Termly script is enabled via environment configuration it may set cookies on legal pages. Prefer the in-repo Privacy Policy at /privacy.

6. Error monitoring

Sentry error monitoring initializes for reliability and security. It is treated as an operational necessity for running the service; payloads are scrubbed of obvious PII where configured. If counsel classifies Sentry as non-essential in a specific jurisdiction, loading must be gated behind consent — tracked in LEGAL_IMPLEMENTATION_CHECKLIST.

7. Managing preferences

Use the cookie banner controls, clear site data, or delete kaify_cookie_consent from local storage to reset. Browser settings alone are not the only withdrawal method. See also /privacy. Version: 2026-08-21.

Cookie Policy — Kaify Ai