# Cookie Policy

_Effective 1 September 2026. Last updated 3 September 2026._

This policy explains the cookies and similar technologies used on
`elaichi.ai` and `app.elaichi.ai` by **Yin Yang, Inc.** (dba Elaichi). It
supplements the [Privacy Policy](/privacy/).

## The short version

**Nothing but strictly necessary cookies is set until you accept.** On your
first visit you are asked to choose. Until you do — and permanently if you
reject — no analytics or advertising script runs and none of their cookies is
set. You can change your mind at any time through the **Cookie settings** link
in the footer.

We also honour the **Global Privacy Control** browser signal: if your browser
sends it and you have not made an explicit choice, we treat that as a rejection
and load nothing.

## Categories

| Category | Consent needed? | What it covers |
|---|---|---|
| **Strictly necessary** | No — required for the service | Signing in, remembering your consent choice, and security |
| **Analytics and advertising** | **Yes — opt-in** | Google Tag Manager, Google Analytics 4, Google Ads measurement, and product analytics |

## Strictly necessary cookies

| Name | Where | Purpose | Duration |
|---|---|---|---|
| `cookie_consent` | `elaichi.ai` | Records whether you accepted or rejected non-essential cookies, so you are not asked again. `SameSite=Lax; Secure`. | 180 days |

The application also sets a strictly necessary sign-in cookie, flagged
`HttpOnly`, `Secure` and `SameSite=Lax`, so it is unreadable to JavaScript and
not sent on cross-site requests. It exists solely to keep you signed in.

None of these can be disabled: without them you could not sign in, and we could
not remember your cookie choice.

## Analytics and advertising cookies

**These are set only after you accept.** We load Google Tag Manager
(container `GTM-KXKJ3L3Q`), which in turn loads Google Analytics 4 and Google
Ads measurement.

| Name | Set by | Purpose | Duration |
|---|---|---|---|
| `_ga` | Google Analytics | Distinguishes one visitor from another | 2 years |
| `_ga_<container-id>` | Google Analytics | Maintains analytics session state | 2 years |
| `_gcl_au` | Google Ads | Measures whether an ad led to a signup | 90 days |

**Google acts as our processor for analytics**, under Google's data processing
terms. Analytics data is retained for **14 months**, and we do not enable the
"reset user data on new activity" setting, so data ages out from collection
rather than being extended each time you return.

**We have not enabled Google Signals**, so Google does not build a cross-device
profile of you from our site.

Because our Google Ads measurement discloses identifiers to Google for
advertising purposes, this counts as **"sharing" for cross-context behavioral
advertising** under California law. Rejecting cookies — or sending Global
Privacy Control — stops it. See the [CCPA Notice](/ccpa/).

## Browser storage

Beyond cookies, the application stores two small preferences in your browser's
**local storage**. European regulators treat browser storage the same way as
cookies, so we disclose it here.

| Key | Purpose | Type | Duration |
|---|---|---|---|
| `elaichi:org_id` | Remembers which organization you last had selected, so you return to the same workspace instead of being asked again on every page load. | Strictly necessary | Until you clear site data |
| `elaichi:onboarding_collapsed` | Remembers that you collapsed the onboarding checklist, so it stays collapsed. | Functional preference | Until you clear site data |

Both are set as a direct result of something you did in the app, are read only
by the app itself, and are **never used for advertising, analytics, or
profiling**. Neither is disclosed to any third party.

**The application's session storage is empty** — we store nothing there.

## Cookieless technologies

| Technology | What it does | Sets a cookie? |
|---|---|---|
| **Cloudflare Web Analytics** | Aggregate page-view and performance measurement, served from `static.cloudflareinsights.com`. **Cookieless by design** — no identifier is stored on your device and no cross-site profile is built. We run it alongside Google Analytics. | No |
| **Cloudflare email obfuscation** | Rewrites email addresses in the page to reduce scraping by spam bots. | No |

Cloudflare also operates our network and security layer. In the course of
protecting the site it may set a short-lived bot-management cookie (`__cf_bm`,
roughly 30 minutes) or a challenge cookie (`cf_clearance`) if a security
challenge is triggered. These are strictly necessary security cookies set by
our infrastructure provider and are not used for advertising or profiling.

## What we do not use

- **No cookies at all until you accept**, beyond the two strictly necessary
  ones above.
- **No Google Signals** and so no cross-device advertising profile.
- **No telemetry in the desktop app.** The Elaichi desktop companion contains
  no analytics, crash reporting, or update pings. It talks to exactly one host:
  the Elaichi API URL you enter. Your API token is stored in your operating
  system's keychain.

## Changing your choice

- **Cookie settings** in the site footer reopens the banner on any page. Choose
  "Reject all" to withdraw consent.
- Enable **Global Privacy Control** in your browser and we will treat it as a
  rejection.
- **California residents**: see [Your Privacy Choices](/privacy-choices/).
- Clear cookies in your browser settings. Note that clearing `cookie_consent`
  means you will be asked again on your next visit; clearing site data for
  `app.elaichi.ai` also clears the two local-storage preferences above, so you
  will be asked to pick an organization again.

Browser controls: [Chrome](https://support.google.com/chrome/answer/95647) ·
[Firefox](https://support.mozilla.org/kb/cookies-information-websites-store-on-your-computer) ·
[Safari](https://support.apple.com/guide/safari/manage-cookies-sfri11471/mac) ·
[Edge](https://support.microsoft.com/microsoft-edge)

## Contact

Questions about this policy: **[privacy@elaichi.ai](mailto:privacy@elaichi.ai)**
