TOYORNOT.com Legal

Cookie and Consent Policy

Last updated: August 11, 2026

1. How Consent Works

On first visit, optional categories are disabled by default. You can allow or deny optional processing and change your choice any time via "Cookie Settings" in the app footer.

2. Storage Used by This Site

Name Type Purpose Category Duration
toyornot-consent-v1 Local storage and first-party cookie Stores the same bounded, timestamped consent declaration in the browser and sends it with relevant same-origin API requests so optional browser and server analytics can verify your current choice. Necessary Up to 365 days from your latest choice, until changed, or until cleared in browser
toyornot-daily-judgement-cap-v1 Local storage Stores the current local-day guest judgement count so the app can enforce the 2-judgements-per-day guest limit. Necessary Until the next local day or storage is cleared
toyornot-initial-crop-guide-seen-v1 Local storage Stores whether the first-upload crop guide has already been shown so the app does not interrupt later uploads with the same instruction. Necessary Until storage is cleared
toyornot-initial-lesson-intro-guide-seen-v1 Local storage Stores whether the first-open Duolingo for Graffiti guide has already been dismissed so the app does not interrupt later lesson-map visits with the same instruction. Necessary Until storage is cleared
toyornot-account-display-status-v1, toyornot-authenticated-account-tier-v1 Local storage Stores the last known guest/free/premium display status and, for signed-in users, the user id tied to that tier so the app can avoid briefly showing stale account-tier UI while server entitlements refresh. Necessary Until updated or storage is cleared
toyornot-guest-id-v1 Local storage Stores a necessary browser guest identifier so anonymous result flows, guest rating history, guest-history merge after sign-in, abuse controls, and first-party retention-funnel measurement can recognize the same browser. Necessary Until storage is cleared
toyornot-pending-scanner-auth-resume-v1 Session storage Temporarily stores only a version, rating request id, creation timestamp, and bounded source label when a scanner action needs to resume after Google sign-in, including the save-result flow, so the app can reopen the matching server-side history entry. It does not store the image, filename, prompt, critique, feedback, email address, or rating-result content. Necessary for the requested scanner sign-in/resume flow Usable for up to 30 minutes; cleared after a successful, failed, invalid, or expired callback, when replaced, when storage is cleared, or when the browser tab/session ends
toyornot-loading-survey-prompt-v2 Local storage Stores up to three recent prompt timestamps and bounded per-question display counts so the fixed-choice loading survey rotates questions and appears at most three times in a rolling seven-day window. It does not store survey answers. Necessary first-party product measurement and interruption control Until replaced by the application or browser storage is cleared; prompt timestamps are used for a rolling seven-day window
toyornot-loading-survey-session-prompted-v2 Session storage Stores only whether the fixed-choice loading survey has already appeared in the current browser session so it cannot appear twice in that session. Necessary interruption control Until the browser tab or session ends
toyornot-contextual-feedback-state-v1 Local storage Stores a pseudonymous feedback key, bounded completed-rating and active-day counters, prompt outcome/cooldown timestamps, and guest or a pseudonymous account_<16hex> scheduling marker derived locally from the signed-in user id. The marker partitions milestones and moment history across account changes and is never sent to the feedback API. Subject-scoped counters and history reset when the subject changes, while browser-wide interruption timestamps and the pseudonymous feedback key remain. It stores no written answer, image, filename, prompt, critique, email, payment detail, or token. Necessary first-party product measurement and interruption control Until replaced by the application or browser storage is cleared; cooldown timestamps are used for up to 180 days
toyornot-contextual-feedback-queue-v1 Local storage Temporarily queues a bounded feedback moment, placement, allow-listed trigger-source code, local de-duplication key, timestamp, optional rating-attempt id, and the local pseudonymous scheduling subject so a requested latch can wait until blocking product screens close without surfacing another account's queued trigger. The bounded source code may be sent with the feedback event, but the raw de-duplication key and scheduling subject are never sent. The queue contains no payment, checkout-session, auth-session, or other session token. Necessary first-party product measurement Two hours for rating inaccuracy/recovery; 48 hours for paywall, checkout, cap, save-auth, and practice; three days for cancellation; seven days for value milestones; earlier when evaluated, answered, dismissed, or storage is cleared
toyornot-feedback-prompt-session-v1 Session storage Records which optional interruption claimed the current browser session so contextual feedback, loading survey, site feedback, install, and push-reminder prompts cannot stack or cascade. Feedback arbitration priority is contextual feedback, then loading survey, then site feedback. Necessary interruption control Until the browser tab or session ends
toyornot-retention-session-key-v1 Session storage Stores the current scanner home-session identifier so necessary first-party retention-funnel events can be grouped into one session/pageview cohort and later return visits can be measured correctly. Necessary Until the browser tab or session ends
toyornot-email-lifecycle-consent-pending-v1 Session storage Temporarily stores the checked optional email-consent choice across the Google sign-in redirect so the app can attach consent to the authenticated Google account email. It does not store the email address. Necessary for requested email opt-in Until submitted, rejected, or the browser tab/session ends
toyornot-experiment-exposures-v2 Local storage Stores a bounded first-party experiment exposure marker containing the experiment and variant, guest subject, source request id, de-duplication key, and timestamp so exposure is not sent repeatedly and a later rating can be attributed to the measured rollout. Necessary Active for up to eight days after exposure, then removed on the next application access; earlier if browser storage is cleared
toyornot-next-practice-target-v1 Local storage Stores bounded primitive context for the visible next-practice target, including account type, score bucket, submission type, target category/source, UI locale, source request id when available, clicked state, result-overlay or home-return placement, and created/expiry days, so a later completed scan can be attributed to that target. It stores no image, filename, prompt, critique, feedback, email address, account id, or exact score. Necessary first-party product measurement; optional PostHog delivery remains consent-gated Active for up to eight days after the target is shown or selected; earlier if replaced, consumed by a later completed rating, expired on next access, or browser storage is cleared
First-party experiment event records Server-side database records Stores bounded exposure and outcome records for product experiments and measured rollouts, including experiment key, variant, stable subject key, route/source labels, UI locale, visitor country, and primitive metadata. Raw uploads, prompts, free-text feedback, emails, and unbounded payloads are not stored in these records. Necessary Until deleted from the application database
First-party contextual-feedback event records Server-side database records Stores only allow-listed view, answer, or dismissal events with bounded moment, question, trigger-source code, complete answer order, answer or dismissal reason, placement, route/locale/release context, optional rating-attempt attribution, timestamp, tier/auth mode, and one pseudonymous guest or account owner. The trigger source is compatible with its moment and is never the raw local de-duplication key or a payment/session token. A prompt retains one context and owner and can have a view plus at most one answer-or-dismissal outcome. Internal reports expose only bounded per-day, per-moment, answer, dismissal, question, placement, and trigger-source aggregates, not prompt, owner, rating-attempt, or other identifiers. No free text, image, filename, prompt, critique, email, payment detail, token, or arbitrary metadata is accepted. Necessary first-party product measurement; optional PostHog mirror requires analytics consent No more than 180 days; earlier for a valid erasure request where applicable
Share-bonus attempt and visit records Server-side database records Stores signed-in share-bonus attempts and shared-link visits, including user id, day key, share token, status, timestamps, landing path, referrer host, and user-agent string so bonus unlocks can be verified and abuse can be limited. Necessary Until deleted from the application database
Optional browser reminder records Server-side database records and browser push subscriptions Stores account or guest lesson reminder preferences separately from rating reminder preferences, including enabled state, local time zone, UI locale, limited day key, next scheduled timestamp, last-sent day key, push endpoint, cryptographic subscription keys, expiration time, user-agent string, and delivery success/failure metadata. Raw images, prompts, lesson uploads, filenames, feedback text, emails, and arbitrary payloads are not stored in reminder metadata. Necessary for requested reminder delivery Until disabled, expired, deleted, or no longer needed for operational records
Optional email lifecycle consent records Server-side database records Stores explicit opt-in preference and audit records for lifecycle emails, including signed-in Google account email, opt-in status, source, UI locale, legal-version identifiers, request id, user-agent string, and timestamps. Necessary for requested email opt-in Until withdrawn, deleted, or no longer needed for consent/legal records
Third-party analytics identifiers Cookie/storage (provider-dependent) Optional product analytics events, including server-side rating, contextual-feedback, site-feedback, and AI-provider diagnostics, plus client-side error diagnostics and session replay via PostHog only in verified production when analytics is configured and you consent. Browser events use anonymous analytics identifiers; consented server events may use a stable pseudonymous signed-in user id or feedback user key. Analytics (optional) Provider-defined
Affiliate optimizer event records Server-side database records Stores optional waiting-overlay affiliate offer selections, viewable impressions, click events, and hashed anonymous session identifiers so sponsored content can measure CTR and improve offer ranking after consent. Sponsored content (optional) Until deleted from the application database
toyornot-analytics-visitor-id-v1, toyornot-analytics-first-seen-v1, toyornot-analytics-session-count-v1 Local storage Stores an anonymous analytics identifier and return-visit counters so optional analytics can measure repeat usage after consent. Analytics (optional) Until consent is withdrawn or storage is cleared
toyornot-analytics-session-id-v1, toyornot-analytics-session-index-v1, toyornot-analytics-rating-attempt-v1 Session storage Stores the current anonymous analytics session and in-session attempt counters. Analytics (optional) Until consent is withdrawn, the browser tab or session ends, or storage is cleared
toyornot-resend-email-attribution-v1 Session storage Stores allow-listed Resend email campaign and link-placement labels from tagged email links so optional analytics can attribute a consented session without storing recipient emails or unsubscribe tokens. Analytics (optional) Until the browser tab or session ends
Amazon affiliate destination cookies/storage Cookie/storage (provider-dependent) May be set by Amazon after you click an optional sponsored Amazon affiliate link for your visitor market. The in-app sponsored cards are static and do not load Amazon scripts before click-through. Sponsored content (optional) Provider-defined after click-through

3. Optional Technologies

4. Manage or Withdraw Consent

Use the in-app "Cookie Settings" control to update your preferences. Changes apply to future processing. Withdrawing analytics consent disables browser PostHog capture, resets its browser analytics identity, and removes ToyOrNot's optional analytics visitor and session identifiers from browser storage. Enabling analytics again creates new browser visitor and session identities. Withdrawal stops future optional server capture until you consent again, but it does not delete previously captured PostHog events or rotate necessary account and feedback identifiers. Consented server events may therefore be associated with the same pseudonymous identifier after later consent. You can also clear browser storage to remove saved preferences. Email lifecycle consent can be withdrawn through the unsubscribe mechanism in lifecycle emails when configured, or by contacting the operator.

5. Contact

Questions about cookies or consent: toyornot.com@gmail.com