1. Scope and terminology
This Policy explains cookies and similar storage or access technologies used on influrs.com. Cookies are small values stored by a browser; localStorage persists until it is cleared; sessionStorage normally lasts for the browser tab or session.
Under UK PECR, we use strictly necessary technologies without consent where the law permits. We use the appearance/functionality preference exception for persistent language and theme storage only with clear information and a simple, free way to object; the necessary preference-storage choice cookie remembers and enforces that objection. We ask before optional product analytics. The feed-experiment assignment and event runtime is disabled. The privacy basis for associated personal data is explained in the Privacy Policy.
2. First-party cookies
| Name | Purpose and category | Typical lifespan |
|---|---|---|
| influrs-session | Authentication and continuity of a secure session. Strictly necessary. | Normally 120 minutes of inactivity; renewed during an active session. |
| XSRF-TOKEN | Protects forms and API requests against cross-site request forgery. Strictly necessary. | Normally aligned with the active session. |
| remember_web_* | Keeps an authenticated account signed in across browser sessions only when the user affirmatively requests persistent login during password sign-in. OAuth sign-in does not create this persistent login cookie. Strictly necessary for the requested remember-me authentication feature. | Up to 400 days under the current authentication configuration; removed or replaced on sign-out, credential/security changes or access revocation. |
| influrs-language | Stores the language explicitly selected or resolved for the interface while persistent display-preference storage is allowed. Appearance/functionality preference; removed and no longer written after an objection. | 365 days, or earlier objection/clearing. |
| influrs-language-source | Records whether language was selected automatically or manually while persistent display-preference storage is allowed. Appearance/functionality preference; removed and no longer written after an objection. | 365 days, or earlier objection/clearing. |
| influrs-theme | Stores the requested light or dark appearance while persistent display-preference storage is allowed. Appearance/functionality preference; removed and no longer written after an objection. | 365 days, or earlier objection/clearing. |
| influrs-display-preference-storage | Records only whether persistent language/theme storage is allowed or denied, so Influrs can enforce a free objection and avoid recreating the preference cookies or local copies. Necessary to remember and respect that storage choice. | 365 days, or until the choice is changed or site data is cleared. |
| influrs-ranking-visitor | Legacy feed-experiment locator. The experiment runtime is disabled: Influrs does not create a new cookie, assignment or event. A feed response or successful withdrawal expires a legacy cookie, and withdrawal deletes linked legacy assignments and events; if that request fails, tracking remains off and the request is retried. | Not newly set. A legacy value is expired on a feed response, successful withdrawal or site-data clearing; associated server records are retained no more than 365 days. |
3. Local and session storage
| Key or group | Purpose and category | Typical lifespan |
|---|---|---|
| influrs-analytics-consent; influrs-analytics-consent-version; influrs-analytics-consent-recorded-at; influrs-analytics-consent-source; influrs-analytics-consent-account | Remembers “allow analytics” or “only necessary”, the notice version, time and control used, and whether the choice belongs to the anonymous browser or the exact signed-in account. These necessary consent records prevent an old-version choice or a choice made by another account in the same browser from enabling optional analytics. | Until you reset the choice, the notice version or signed-in account changes, or site data is cleared. A stale or differently bound grant is changed to denied and its linked cleanup is retried before a new choice is requested. |
| influrs-analytics-visitor | Pseudonymous visitor ID used to associate optional product-analytics events. Optional analytics. After withdrawal, it is retained locally only while needed to identify linked server records for a failed deletion retry; tracking remains off. | Until successful withdrawal cleanup or site data is cleared. Successful cleanup deletes raw events and any legacy experiment records linked to this HMAC visitor identifier; irreversible non-linked daily totals remain for no more than 365 days. |
| influrs-analytics-withdrawal-pending | Stores only whether the pending server-cleanup request came from the banner, Cookie Policy or account control. Strictly necessary to retry a failed withdrawal, keep optional tracking off and complete deletion of linked analytics records. | Until server cleanup succeeds; clearing site data can remove the local marker. Resetting the visible choice does not remove it while cleanup is pending. |
| influrs-analytics-consent-grant-epoch; influrs-analytics-withdrawal-epoch | Two local counter values with no account, visitor or event identifier: the monotonic withdrawal epoch and the exact epoch captured by the current analytics grant. They are strictly necessary to prevent an overlapping or suspended browser tab from using a stale grant after a later withdrawal. | The grant epoch is removed when analytics is denied, withdrawn or reset. The withdrawal epoch remains until site data is cleared and is not removed when a withdrawal completes, because that would re-open the stale-grant race. Neither value is sent as an analytics event. |
| influrs-language and influrs-theme | Client-side copies of interface preferences for a consistent display, used only while persistent display-preference storage is allowed. An objection deletes both copies and prevents future persistent writes until storage is re-enabled. | Until changed, objected to or site data is cleared. |
| influrs:checkout:<plan>:<interval> | One-time idempotency value that prevents duplicate Stripe checkout sessions after a retry. Strictly necessary when checkout is used. | Session storage; normally removed when the page session ends or navigation completes. |
| influrs:payment-method-setup | One-time idempotency value that prevents duplicate payment-method setup requests. Strictly necessary when billing management is used. | Session storage; removed after success or when the page session ends. |
| influrs-sw-cleanup-reload and influrs-sw-browser-cleanup-reload | Prevent a reload loop while the development/update cleanup or ordinary-browser cleanup removes an Influrs service worker and cache. Strictly necessary to complete that cleanup reliably. | Session storage; removed after the applicable cleanup/reload flow. |
| Cache Storage: influrs-shell-v5 | Service-worker cache of the shell manifest, icons, offline page and same-origin `/_nuxt/` assets needed for reliable installed-app delivery and an offline fallback. API responses, dynamic navigation responses, creator/profile data and media are excluded. It is activated only when the browser reports that the site is running as an installed standalone app (including the iOS standalone signal) and is strictly necessary for that expressly requested offline-capable function. A URL query parameter cannot activate it. Ordinary browser visits do not register the worker and remove an older Influrs worker/cache if one remains. | No fixed item expiry in the current worker; entries can be replaced by a newer response, old cache versions including `influrs-shell-v4` are deleted when the new worker activates, and ordinary browser cleanup or clearing site data removes the cache. |
4. Optional product analytics
Optional analytics is off until you choose “Allow analytics” for the current notice version and the current anonymous or signed-in account context. A notice-version change, sign-in, sign-out or account switch invalidates a differently bound grant and asks for a fresh choice after linked cleanup. If enabled, Influrs records a pseudonymous visitor HMAC for a browser and, for a consented signed-in event, the account user ID, plus a client event ID, event type, page/feature context, referenced story or creator, bounded metadata and daily aggregates. Raw IP address and user-agent are not stored in the analytics event. The feed-experiment assignment and event runtime is disabled and creates no new experiment record or cookie.
We use this data to understand feature use and reliability. We do not use it for third-party advertising or cross-site tracking. Events, aggregates and any legacy experiment records are deleted after no more than 365 days.
You can withdraw as easily as you consented using the control below. Withdrawal immediately records a denied choice and stops new optional events. It asks the server to delete raw analytics events and any legacy experiment assignments/events linked to the signed-in user, HMAC visitor identifier or legacy experiment cookie and, on success, removes the local analytics identifier, pending marker and legacy experiment cookie. If server cleanup fails, the original local analytics visitor identifier and source-only pending marker remain solely to identify and retry that deletion while tracking stays off; the visible reset control stays unavailable until cleanup succeeds. Reset first completes the same server withdrawal and cannot discard a deletion locator. Irreversible daily totals that no longer identify or link to a person remain only for the stated maximum 365-day period. To enforce the completed withdrawal against delayed requests carrying a stale grant, the server keeps only a namespaced HMAC subject marker with denial and expiry times, without a raw account, visitor or experiment identifier, for no more than that 365-day period; it is then pruned, and a later valid grant clears the denial for that subject. Withdrawal does not affect the lawfulness of processing before it; resetting shows the choice again and does not itself grant consent.
5. YouTube external links and disabled embedded player
YouTube embedded playback is disabled in the current release. A creator or content presentation does not load a YouTube player, a player thumbnail from a Google/YouTube image host before play, or a `youtube-nocookie.com` iframe. A visible external source link visits YouTube only if you choose to open it; Google/YouTube then receives the ordinary request data under the Google Privacy Policy and YouTube Terms of Service.
Influrs also refuses automatic browser requests for profile, portfolio, workspace-member or content image URLs whose host differs from the Influrs page. It shows a local fallback instead; opening a clearly labelled external source link remains your choice.
The embedded player must remain disabled until Influrs looks up and retains the current Made For Kids status of every proposed video through the documented YouTube API and implements the required no-tracking and applicable-law controls for every Made For Kids player. This Policy will be updated before such storage or access technology is enabled.
6. Stripe checkout and billing
When billing is available and you open an embedded checkout or payment-management interface, Stripe may store or access cookies and similar technologies for secure payment processing, fraud prevention, authentication and remembering the transaction state. These technologies are loaded only on the billing interaction that needs them.
Stripe controls its own payment technologies. See the Stripe Privacy Policy and Stripe Cookie Policy. You cannot complete a card payment without the technologies strictly necessary to secure and process it.
7. Your controls
- Use the analytics control below at any time. “Only necessary” and “Allow analytics” are separate choices.
- Use browser settings to inspect, block or delete cookies and site storage. Blocking essential session or CSRF cookies can stop sign-in, forms or billing from working.
- Use the display-preference storage control below to stop or re-enable persistent language/theme storage at any time. Objecting deletes the language, language-source and theme cookies and local copies and prevents future persistent writes; the necessary choice cookie remembers the objection.
- A YouTube source link sends a request to YouTube only if you choose to open it; no embedded player is currently offered. Avoid loading a Stripe interface if you do not want that provider request, except where the interface is required to complete a transaction you choose.
8. Changes and contact
We update this inventory when technology, purpose, provider or lifespan materially changes. A new non-essential purpose will not be activated under an old consent that did not cover it.
Questions or concerns about cookies can be sent to influrscom@gmail.com.