Cookie Policy
We use cookies and similar technologies (localStorage / sessionStorage). Under the EU ePrivacy Directive and GDPR, non-essential cookies require your consent. Manage choices anytime via .
1. What are cookies?
Cookies are small text files stored on your device. We also use browser storage for preferences and session tokens. Some are set by us; others by third parties when you load embeds.
2. Categories we use
Necessary (always on)
- Authentication / session tokens for signed-in use.
- Security, CSRF-style protections, and rate-limit keys.
- Practice-share unlock cookies (HttpOnly where applicable).
- Cookie-consent record itself (so we remember your choice).
Preferences (optional)
- Theme (light/dark/system), song-plan language, UI layout flags.
Media embeds (optional)
- YouTube privacy-enhanced embeds (
youtube-nocookie.com) and live radio stream players. - These providers may set their own cookies once loaded. We only load them after you consent to Media.
Analytics (optional, currently unused)
- Reserved for privacy-friendly analytics if we enable them later. Default is off.
3. Third-party cookies
- Supabase Auth — account session (necessary when signed in).
- hCaptcha — bot checks on authentication when enabled.
- YouTube / stream hosts — only after Media consent.
- Google Fonts — font files may be requested from Google; we minimize third-party trackers on legal pages.
4. How long they last
- Session cookies — until you close the browser or sign out.
- Consent preferences — up to 12 months (or until you clear storage / change settings).
- Practice unlock — until the share expires or you clear cookies.
5. How to control cookies
- Use our .
- Use browser controls to block or delete cookies. Blocking necessary cookies will break sign-in.
6. Updates
We will update this Cookie Policy when our technologies change. See the effective date above.