Cookie Policy
Last updated: 21 July 2026
1. What we use
Koliva uses a minimal set of strictly-necessary browser storage to keep you signed in and remember your preferences, plus — only if you allow it — one Google cookie that measures whether our ads work. Nothing is set for advertising purposes without your consent.
2. The list
- koliva_access_token (localStorage) — your signed-in session JWT. Required for the app to function. Cleared on logout or account deletion.
- Stripe session cookies (set by Stripe's domain when you check out) — payment fraud prevention.
- Cloudflare may set bot-management cookies on assets served from our CDN. These are strictly necessary for security.
- Google Ads measurement (
_gcl_awand related, pluskoliva_cookie_consentin localStorage remembering your choice) — set only after you press "Allow" on the cookie bar. It tells us which Google ad click led to a signup or subscription. If you decline, the tag runs in cookieless mode (Google Consent Mode) and ad clicks are measured only as anonymous aggregates.
We do not use Google Analytics, Facebook Pixel, or any other tracker. The single Google Ads conversion cookie above is the full list, and it stays off until you opt in.
3. Disabling
You can at any time — the consent bar will re-appear. You can also clear localStorage from your browser dev tools; disabling browser storage entirely will sign you out and prevent the app from running. Stripe and Cloudflare cookies are controlled at their respective domains' privacy pages.
4. Updates
If we add further analytics or marketing cookies, we'll update this page and request consent first.