1. What this policy covers
This Cookie Policy explains how Krolville Stories uses cookies and similar technologies on the website and in the application.
2. What are cookies
Cookies are small text files stored on your device when you visit a website or use a web application. Similar technologies include localStorage and session storage used for similar purposes.
3. Cookies we use
Strictly necessary
These are required for the service to function. They cannot be turned off, and no consent is required for them.
| Purpose | Details |
|---|---|
| Authentication session | Keeps you logged in across page visits |
| Onboarding state | Remembers whether you have completed onboarding (kv_ob, kv_onboarding_flow) |
| Language preference | Remembers the language you selected (locale) |
| Cookie choice | Records whether you accepted or rejected non-essential cookies (kv_cookie_consent) |
| Parent Gate verification | Temporary verification state for protected actions (15-minute session) |
| Security and CSRF protection | Used by the authentication system |
These cookies are set by Krolville Stories itself and by our authentication provider (Auth.js / Supabase).
Analytics and diagnostics
We keep non-essential tracking to a minimum.
| Provider | Purpose | Status |
|---|---|---|
| Sentry — error monitoring | Diagnostic data when an error occurs, so we can find and fix problems. Story text, prompts and child-profile content are excluded from what is sent. | Always on — treated as essential diagnostics |
| Sentry — Session Replay | Optional session recording used to reproduce hard-to-debug issues | Disabled during the beta. When enabled it stays off until you accept analytics cookies — recording never starts before your choice |
We do not run product-analytics tools such as PostHog during the beta, and no advertising or session-tracking SDK is loaded. If this changes, this policy will be updated and any required consent obtained before such tracking is switched on.
Marketing / advertising
We do not currently use advertising or retargeting cookies. If this changes, this policy will be updated before such cookies are introduced.
4. Consent
Strictly necessary cookies do not require consent — they are essential for the service to work.
Error monitoring (Sentry) collects redacted technical diagnostics under our legitimate interest in keeping the service reliable and secure; it does not receive story text, prompts or child-profile data.
Non-essential analytics (Sentry Session Replay) are off by default. During the closed beta they are disabled entirely. When they become available:
- Reject non-essential keeps them off and does not reduce any core functionality.
- Accept records your choice so optional analytics can run; recording only ever starts after your choice, never before.
Your choice is stored in the kv_cookie_consent cookie so we can remember it.
5. Managing your preferences
You can control cookies through your browser settings. Disabling strictly necessary cookies may prevent the service from functioning correctly.
Most browsers allow you to:
- view and delete stored cookies;
- block cookies from specific sites;
- accept or reject cookies before they are set.
6. Third-party services
Some of the tools we use (Sentry) may set their own cookies or identifiers governed by their own privacy policies.
See the Subprocessor List for a full list of our service providers.
7. Updates
This policy will be updated if we introduce new tools, change consent mechanics, or add marketing/advertising features.