Cookie Policy
Last updated: 2026-05-30
This Cookie Policy explains what cookies and similar storage technologies we use on ghugi.com, why we use them, and how you can control them. It sits alongside our Privacy Policyand is written for the UK regulatory framework — the Privacy and Electronic Communications Regulations (PECR) 2003, the UK GDPR, and the Data (Use and Access) Act 2025 (in force since 5 February 2026).
What cookies are, in plain English
A cookie is a small text file a website asks your browser to store. The website can read it back on later visits — typically to keep you signed in, remember your preferences, or count page views. Related technologies like browser local storage do the same job with a different mechanism; the same rules apply.
Our approach
Ghugi uses the fewest cookies we can get away with. We do not run third-party advertising cookies, we do not share data with ad networks, and we do not track you across other websites. The analytics we do use are cookieless— Vercel Web Analytics and Speed Insights record page views and loading speed using a short-lived hashed identifier, not a cookie.
Under PECR Regulation 6(4)(b) we do not need your consent for cookies that are strictly necessary to provide a service you have explicitly asked for — for example, the session cookie that keeps you logged in, or the theme cookie we set only when you click the theme toggle. For other cookies and similar technologies, we follow the Data (Use and Access) Act 2025 rules: analytics used solely to collect aggregated statistics about how the site is used may be run without prior opt-in, provided we clearly disclose them (this page) and give you a straightforward way to opt out.
You can opt out of analytics at any time: or use the same link in the page footer.
Cookies and storage we use on ghugi.com
Strictly necessary — always on
| Name | Purpose | Lifetime | Set by |
|---|---|---|---|
| sb-<project>-auth-token | Keeps you signed in. Stores your access + refresh token so you don’t have to log in on every page load. | Session / 1 hour auto-refresh | Ghugi (via Supabase SSR) |
| __cf_bm | Cloudflare bot-management cookie. Distinguishes humans from automated traffic; prevents abusive bots from reaching the app. | 30 minutes | Cloudflare (on Ghugi’s behalf) |
| theme | Remembers whether you chose light or dark mode after you click the theme toggle, so the right palette renders on the first paint without a flash. Only set after you explicitly switch; never set automatically. | 1 year | Ghugi |
| ghugi:cookie-consent (localStorage) | Remembers your analytics opt-out choice so we honour it on every visit. Only written when you save your cookie preferences; never leaves your device. | Until you clear it | Ghugi |
Functional — opt-in
| Name | Purpose | Lifetime | Set by |
|---|---|---|---|
| ghugi:remember-email (localStorage) | Stores your email address on your device so the login form is prefilled on your next visit. Only written when you tick Remember this email on the login form. Never leaves your device until you submit the form. | Until you clear it | Ghugi |
Analytics — can be turned off
| Name | Purpose | Lifetime | Set by |
|---|---|---|---|
| Vercel Web Analytics (cookieless) | Counts page views and distinguishes unique visitors using a hash of your IP and user-agent (no cookie, no cross-site tracking). Tells us which pages people read, which links break. Data is discarded after 24 hours and only aggregated statistics are retained. | 24 hours (visitor hash) | Vercel, Inc. |
| Vercel Speed Insights (cookieless) | Measures real-user Web Vitals (how fast pages load, when content appears). Helps us catch and fix slow pages. No cookie, no identifier persisted on your device. | Per-page beacon | Vercel, Inc. |
Vercel processes this data on our behalf under their Data Processing Addendum and their own analytics privacy notice. Vercel is contractually prohibited from using the data for its own purposes.
Marketing — none
We do not use marketing, advertising, retargeting, or social-media tracking cookies. No Google Analytics, no Meta Pixel, no LinkedIn Insight Tag, no Hotjar, no session replay.
Third-party pages we redirect you to
When you start a subscription, we hand you off to Stripe Checkout(a separate domain owned by Stripe Inc. / Stripe Payments UK Ltd). Stripe will set its own cookies on that page to process your payment and detect fraud — those cookies are governed by the Stripe Cookie Policy. Ghugi does not load Stripe scripts on the landing page or inside the app shell, so Stripe cookies are not set until you actively begin a checkout flow.
Controlling cookies
- On our site: use the button (also in the footer of every page) to opt out of analytics. Your choice is remembered on your device.
- In your browser: every major browser lets you view, block, or delete cookies through its privacy settings. See the guides for Chrome, Firefox, Safari, and Edge. Blocking the strictly-necessary cookies above will break sign-in.
Changes to this policy
If we add, remove, or change how we use a cookie, we will update this page and refresh the “Last updated” date above. Material changes are also covered by the notice mechanism in our Privacy Policy.
Contact and complaints
Questions? Email privacy@ghugi.com or see our Contact page. If you are unhappy with how we handle your data, you have the right to complain to the UK Information Commissioner’s Office at ico.org.uk or on 0303 123 1113.