Skip to main content
No third-party tracking

Cookie Policy

Last updated: August 31, 2026

Plain-English Summary

  • Cookies that keep you logged in, plus the ones behind the dashboard PIN gate. Those are the required ones.
  • Anonymous traffic analytics (no personal data). No cross-site tracking.
  • No advertising pixels, no Facebook tracker, no Google Ads tags. Ever.
  • You can clear cookies anytime from your browser. You’ll just need to log in again.

1. What is a cookie?

A cookie is a small text file a website asks your browser to store. Sites use them for things like keeping you logged in, remembering preferences, and (in the bad cases) tracking you across the internet to serve ads. Briveli only uses cookies for the boring, necessary things.

2. Cookies Briveli uses

Strictly necessary

  • Supabase auth session cookies (essential): store a signed token so you stay logged in across page navigations. Without these cookies, the site can’t tell who you are. They expire when your session ends or when you log out.
  • Dashboard PIN cookies (security): if you set a parent PIN, a signed cookie records that you entered it, so you are not asked again on every dashboard page for the next four hours. If you have not set a PIN, a signed ten-minute marker saves us re-checking that on every page. Both are readable only by our server, never by scripts in the page, and neither one identifies a child.
  • Cloudflare Turnstile (security, free-worksheet forms only): our worksheet pages load Cloudflare’s anti-spam check so bots cannot harvest the download. If that check stores anything in your browser, it belongs to Cloudflare and is used only to confirm a person filled the form in. It is not used to track you and never runs inside the app itself.

Anonymous analytics

  • Vercel Web Analytics and Speed Insights (analytics): record aggregate page performance and broad traffic patterns (country, device type, referrer). Vercel’s analytics products are designed to be privacy-friendly. They do not set cross-site tracking cookies and do not follow you across other websites. These measurements are not tied to your account or to a child profile.

Error monitoring

  • No cookie. When the app hits an unexpected error we send a report to our error-monitoring service, and we strip child first names, parent emails, and other personal details from it before it leaves the browser. That report does not set or read a cookie.

What we don’t use

  • No advertising or retargeting pixels (no Facebook Pixel, Google Ads tag, TikTok pixel, etc.)
  • No cross-site tracking cookies
  • No third-party social-share trackers
  • No always-on session-replay or heatmap tools that record what you click on (Sentry replay only arms on error and masks all on-screen text).

3. Children and cookies

Children do not create accounts on Briveli, so children never log in and never receive an authentication cookie. The auth and dashboard PIN cookies above are only set on a parent device, and only after a parent signs in. See our Privacy Policy for the full COPPA breakdown.

4. Managing cookies

You can clear cookies at any time from your browser settings. If you clear the Briveli auth cookie, you’ll be logged out and will need to sign in again. If you block cookies entirely for briveli.com, the app will still load public marketing pages, but you won’t be able to log in.

We don’t need to show a cookie banner under most jurisdictions because we don’t set non-essential or tracking cookies. If that ever changes, you’ll see a clear opt-in prompt before any new cookie is set.

5. Changes to this policy

If we add new cookie categories (for example, if we ever introduce a preference cookie), we’ll update this page and call out the change at the top. Material changes that affect how we collect data will also be announced by email to active account holders.

6. Contact

Questions about cookies or tracking? Email privacy@briveli.com.