Cookie Policy
Last updated: 2 September 2026
This Cookie Policy explains what cookies and similar technologies Ozvor places on your device, why we use them, and how you can control them. It should be read alongside our Privacy Policy. Ozvor is operated by Ozvor (a company being incorporated in Brazil). Home jurisdiction: Brazil (LGPD); we also comply with the GDPR / ePrivacy Directive (EU/EEA) and CCPA/CPRA (California, US).
1. What are cookies?
Cookies are small text files stored on your device when you visit a website. They allow the site to recognise your device across page loads and sessions. We also use localStorage (a browser storage mechanism) for lightweight UI preferences such as your colour-scheme choice, and sessionStorage (a storage mechanism that lives only as long as the browser tab) for campaign attribution. None of these mechanisms identify you to third parties; they are scoped to our domain only.
2. Cookies we use at launch
By default Ozvor deploys only strictly necessary cookies. The single exception is Google Analytics 4, which loads only if you opt in to analytics via the consent banner — decline (or simply don't answer) and no analytics cookie is ever set. No marketing cookies and no advertising pixels are active. The table below lists every cookie the Service can set today.
| Cookie / key | Purpose | First- or third-party | Retention |
|---|---|---|---|
sb-wdeabrzpgshnouvnfvml-auth-token | Supabase authentication session token. Set only after you log in. Allows the app to verify your identity across page loads without re-entering your email each time. | First-party (ozvor.com) | Session; refreshed on activity (7-day rotation) |
sb-wdeabrzpgshnouvnfvml-refresh-token | Supabase session refresh token. Allows the session to be silently renewed so you are not unexpectedly logged out while actively using the Service. | First-party (ozvor.com) | 7 days; rotated on use |
localStorage: theme | Stores your light/dark colour-scheme preference so it persists across browser sessions. Not a cookie; stored in browser localStorage; never transmitted to our servers. | First-party (ozvor.com) | Persistent until you clear browser storage or change preference |
sessionStorage: ozvor_attribution | Campaign attribution (first-touch). If you arrive from one of our own campaign links (e.g. ?from= or utm_* parameters), the campaign label is kept so we know which campaign brought you if you later run a test or buy. Stores only the campaign identifiers we chose — no click IDs, no device fingerprint, no cross-site identifiers. Not a cookie; never read by third parties. | First-party (ozvor.com) | Tab session only — deleted automatically when you close the browser tab |
The Supabase auth cookies do not track you across websites. They are scoped strictly to ozvor.com and contain only an encrypted session identifier — no personal data in the cookie payload itself.
3. Cookie categories — status at launch
The table below follows the standard ePrivacy Directive / LGPD taxonomy. Categories marked "Not in use" are listed for transparency so you know what we have — and have not — deployed. If any category is introduced in the future, this policy will be updated before deployment and a consent mechanism will be provided as required.
| Category | Description | In use at launch | Consent required? |
|---|---|---|---|
| Strictly necessary | Authentication session cookies that allow you to stay logged in. The Service cannot function without them for authenticated users. | Yes | No — exempt under ePrivacy Directive, LGPD, and CCPA (necessary for service delivery) |
| Functional / preferences | Remembers non-essential user choices (e.g., language, layout preferences). Only localStorage theme preference is used today (non-cookie; no server transmission). | Not in use (cookie) | Would require consent if cookies were used |
| Analytics / performance | Google Analytics 4 (Google LLC) — aggregate usage data (page views, session duration, referrer). Cookies: _ga, _ga_* (persist up to 13 months). Loaded only after you opt in via the consent banner — declining (or never answering) means nothing loads and no analytics cookies are set. Ad-related signals are permanently disabled (Consent Mode: ad_storage denied). | Consent-gated | Opt-in required (EU/BR); opt-out honored (US). Withdraw any time via “Cookie preferences” in the footer. |
| Marketing / advertising | Cross-site tracking for advertising, retargeting, or behavioural profiling (e.g., Meta Pixel, Google Ads, LinkedIn Insight Tag). None deployed. | Not in use | Requires explicit opt-in consent (EU/BR); "Do Not Sell or Share" opt-out (California) |
4. Legal basis for cookies
Brazil (LGPD): Strictly necessary cookies are processed on the basis of contract performance (Art. 7, V LGPD) — they are required to provide the authenticated service you requested. No consent is required for these cookies.
EU/EEA (GDPR + ePrivacy Directive): Strictly necessary cookies fall within the "essential technical purpose" exception to the ePrivacy Directive consent requirement. They are processed under contract performance (Art. 6(1)(b) GDPR). Any non-essential cookie category would require prior, freely given, specific and informed consent (opt-in) from EU users before being set.
California (CCPA/CPRA): Strictly necessary cookies are exempt from the "sale" and "sharing" restrictions because they are used solely to provide the service you requested. No marketing cookies are in use, so no "Do Not Sell or Share" opt-out is triggered. If marketing cookies are introduced in the future, a compliant opt-out mechanism will be provided.
5. Third-party cookies
At launch, no third-party cookies are set on ozvor.com. The Supabase auth cookies are first-party (set and read only by ozvor.com). We do not embed third-party advertising, social, or analytics widgets that set their own cookies.
If a future integration (such as a support chat widget or third-party analytics platform) introduces third-party cookies, it will be disclosed in an update to this policy, and appropriate consent will be obtained before those cookies are set.
6. Your choices and controls
Strictly necessary cookies: These cookies cannot be disabled without breaking the authenticated application. If you do not wish these cookies to be stored, please do not use the logged-in Service.
Browser controls: You can delete or block cookies at any time via your browser settings. Most browsers provide a mechanism to review stored cookies and clear them selectively. Deleting auth cookies will log you out of the Service. Guidance for common browsers:
For a general guide to managing cookies across browsers, see allaboutcookies.org.
Do Not Track (DNT): Some browsers send a "Do Not Track" signal. We honour this signal as a best-effort measure and do not deploy any behavioural tracking that would be affected by it.
7. Changes to this policy
We will update this Cookie Policy before adding any new cookie category or analytics tool. Material changes — such as the introduction of marketing or analytics cookies — will be notified via in-app notification and by email to registered users at least 14 days before the change takes effect.
The "Last updated" date at the top of this page reflects the most recent revision.
8. Contact
For questions about this Cookie Policy or to exercise your data rights, contact our Privacy Team at dpo@ozvor.com. You may also submit a Data Subject Request or review our full Privacy Policy.