TOYORNOT.com Legal
Cookie and Consent Policy
Last updated: August 11, 2026
1. How Consent Works
On first visit, optional categories are disabled by default. You can allow or deny optional processing and change your choice any time via "Cookie Settings" in the app footer.
2. Storage Used by This Site
| Name | Type | Purpose | Category | Duration |
|---|---|---|---|---|
toyornot-consent-v1 |
Local storage and first-party cookie | Stores the same bounded, timestamped consent declaration in the browser and sends it with relevant same-origin API requests so optional browser and server analytics can verify your current choice. | Necessary | Up to 365 days from your latest choice, until changed, or until cleared in browser |
toyornot-daily-judgement-cap-v1 |
Local storage | Stores the current local-day guest judgement count so the app can enforce the 2-judgements-per-day guest limit. | Necessary | Until the next local day or storage is cleared |
toyornot-initial-crop-guide-seen-v1 |
Local storage | Stores whether the first-upload crop guide has already been shown so the app does not interrupt later uploads with the same instruction. | Necessary | Until storage is cleared |
toyornot-initial-lesson-intro-guide-seen-v1 |
Local storage | Stores whether the first-open Duolingo for Graffiti guide has already been dismissed so the app does not interrupt later lesson-map visits with the same instruction. | Necessary | Until storage is cleared |
toyornot-account-display-status-v1, toyornot-authenticated-account-tier-v1 |
Local storage | Stores the last known guest/free/premium display status and, for signed-in users, the user id tied to that tier so the app can avoid briefly showing stale account-tier UI while server entitlements refresh. | Necessary | Until updated or storage is cleared |
toyornot-guest-id-v1 |
Local storage | Stores a necessary browser guest identifier so anonymous result flows, guest rating history, guest-history merge after sign-in, abuse controls, and first-party retention-funnel measurement can recognize the same browser. | Necessary | Until storage is cleared |
toyornot-pending-scanner-auth-resume-v1 |
Session storage | Temporarily stores only a version, rating request id, creation timestamp, and bounded source label when a scanner action needs to resume after Google sign-in, including the save-result flow, so the app can reopen the matching server-side history entry. It does not store the image, filename, prompt, critique, feedback, email address, or rating-result content. | Necessary for the requested scanner sign-in/resume flow | Usable for up to 30 minutes; cleared after a successful, failed, invalid, or expired callback, when replaced, when storage is cleared, or when the browser tab/session ends |
toyornot-loading-survey-prompt-v2 |
Local storage | Stores up to three recent prompt timestamps and bounded per-question display counts so the fixed-choice loading survey rotates questions and appears at most three times in a rolling seven-day window. It does not store survey answers. | Necessary first-party product measurement and interruption control | Until replaced by the application or browser storage is cleared; prompt timestamps are used for a rolling seven-day window |
toyornot-loading-survey-session-prompted-v2 |
Session storage | Stores only whether the fixed-choice loading survey has already appeared in the current browser session so it cannot appear twice in that session. | Necessary interruption control | Until the browser tab or session ends |
toyornot-contextual-feedback-state-v1 |
Local storage | Stores a pseudonymous feedback key, bounded completed-rating and active-day counters, prompt outcome/cooldown timestamps, and guest or a pseudonymous account_<16hex> scheduling marker derived locally from the signed-in user id. The marker partitions milestones and moment history across account changes and is never sent to the feedback API. Subject-scoped counters and history reset when the subject changes, while browser-wide interruption timestamps and the pseudonymous feedback key remain. It stores no written answer, image, filename, prompt, critique, email, payment detail, or token. |
Necessary first-party product measurement and interruption control | Until replaced by the application or browser storage is cleared; cooldown timestamps are used for up to 180 days |
toyornot-contextual-feedback-queue-v1 |
Local storage | Temporarily queues a bounded feedback moment, placement, allow-listed trigger-source code, local de-duplication key, timestamp, optional rating-attempt id, and the local pseudonymous scheduling subject so a requested latch can wait until blocking product screens close without surfacing another account's queued trigger. The bounded source code may be sent with the feedback event, but the raw de-duplication key and scheduling subject are never sent. The queue contains no payment, checkout-session, auth-session, or other session token. | Necessary first-party product measurement | Two hours for rating inaccuracy/recovery; 48 hours for paywall, checkout, cap, save-auth, and practice; three days for cancellation; seven days for value milestones; earlier when evaluated, answered, dismissed, or storage is cleared |
toyornot-feedback-prompt-session-v1 |
Session storage | Records which optional interruption claimed the current browser session so contextual feedback, loading survey, site feedback, install, and push-reminder prompts cannot stack or cascade. Feedback arbitration priority is contextual feedback, then loading survey, then site feedback. | Necessary interruption control | Until the browser tab or session ends |
toyornot-retention-session-key-v1 |
Session storage | Stores the current scanner home-session identifier so necessary first-party retention-funnel events can be grouped into one session/pageview cohort and later return visits can be measured correctly. | Necessary | Until the browser tab or session ends |
toyornot-email-lifecycle-consent-pending-v1 |
Session storage | Temporarily stores the checked optional email-consent choice across the Google sign-in redirect so the app can attach consent to the authenticated Google account email. It does not store the email address. | Necessary for requested email opt-in | Until submitted, rejected, or the browser tab/session ends |
toyornot-experiment-exposures-v2 |
Local storage | Stores a bounded first-party experiment exposure marker containing the experiment and variant, guest subject, source request id, de-duplication key, and timestamp so exposure is not sent repeatedly and a later rating can be attributed to the measured rollout. | Necessary | Active for up to eight days after exposure, then removed on the next application access; earlier if browser storage is cleared |
toyornot-next-practice-target-v1 |
Local storage | Stores bounded primitive context for the visible next-practice target, including account type, score bucket, submission type, target category/source, UI locale, source request id when available, clicked state, result-overlay or home-return placement, and created/expiry days, so a later completed scan can be attributed to that target. It stores no image, filename, prompt, critique, feedback, email address, account id, or exact score. | Necessary first-party product measurement; optional PostHog delivery remains consent-gated | Active for up to eight days after the target is shown or selected; earlier if replaced, consumed by a later completed rating, expired on next access, or browser storage is cleared |
| First-party experiment event records | Server-side database records | Stores bounded exposure and outcome records for product experiments and measured rollouts, including experiment key, variant, stable subject key, route/source labels, UI locale, visitor country, and primitive metadata. Raw uploads, prompts, free-text feedback, emails, and unbounded payloads are not stored in these records. | Necessary | Until deleted from the application database |
| First-party contextual-feedback event records | Server-side database records | Stores only allow-listed view, answer, or dismissal events with bounded moment, question, trigger-source code, complete answer order, answer or dismissal reason, placement, route/locale/release context, optional rating-attempt attribution, timestamp, tier/auth mode, and one pseudonymous guest or account owner. The trigger source is compatible with its moment and is never the raw local de-duplication key or a payment/session token. A prompt retains one context and owner and can have a view plus at most one answer-or-dismissal outcome. Internal reports expose only bounded per-day, per-moment, answer, dismissal, question, placement, and trigger-source aggregates, not prompt, owner, rating-attempt, or other identifiers. No free text, image, filename, prompt, critique, email, payment detail, token, or arbitrary metadata is accepted. | Necessary first-party product measurement; optional PostHog mirror requires analytics consent | No more than 180 days; earlier for a valid erasure request where applicable |
| Share-bonus attempt and visit records | Server-side database records | Stores signed-in share-bonus attempts and shared-link visits, including user id, day key, share token, status, timestamps, landing path, referrer host, and user-agent string so bonus unlocks can be verified and abuse can be limited. | Necessary | Until deleted from the application database |
| Optional browser reminder records | Server-side database records and browser push subscriptions | Stores account or guest lesson reminder preferences separately from rating reminder preferences, including enabled state, local time zone, UI locale, limited day key, next scheduled timestamp, last-sent day key, push endpoint, cryptographic subscription keys, expiration time, user-agent string, and delivery success/failure metadata. Raw images, prompts, lesson uploads, filenames, feedback text, emails, and arbitrary payloads are not stored in reminder metadata. | Necessary for requested reminder delivery | Until disabled, expired, deleted, or no longer needed for operational records |
| Optional email lifecycle consent records | Server-side database records | Stores explicit opt-in preference and audit records for lifecycle emails, including signed-in Google account email, opt-in status, source, UI locale, legal-version identifiers, request id, user-agent string, and timestamps. | Necessary for requested email opt-in | Until withdrawn, deleted, or no longer needed for consent/legal records |
| Third-party analytics identifiers | Cookie/storage (provider-dependent) | Optional product analytics events, including server-side rating, contextual-feedback, site-feedback, and AI-provider diagnostics, plus client-side error diagnostics and session replay via PostHog only in verified production when analytics is configured and you consent. Browser events use anonymous analytics identifiers; consented server events may use a stable pseudonymous signed-in user id or feedback user key. | Analytics (optional) | Provider-defined |
| Affiliate optimizer event records | Server-side database records | Stores optional waiting-overlay affiliate offer selections, viewable impressions, click events, and hashed anonymous session identifiers so sponsored content can measure CTR and improve offer ranking after consent. | Sponsored content (optional) | Until deleted from the application database |
toyornot-analytics-visitor-id-v1, toyornot-analytics-first-seen-v1, toyornot-analytics-session-count-v1 |
Local storage | Stores an anonymous analytics identifier and return-visit counters so optional analytics can measure repeat usage after consent. | Analytics (optional) | Until consent is withdrawn or storage is cleared |
toyornot-analytics-session-id-v1, toyornot-analytics-session-index-v1, toyornot-analytics-rating-attempt-v1 |
Session storage | Stores the current anonymous analytics session and in-session attempt counters. | Analytics (optional) | Until consent is withdrawn, the browser tab or session ends, or storage is cleared |
toyornot-resend-email-attribution-v1 |
Session storage | Stores allow-listed Resend email campaign and link-placement labels from tagged email links so optional analytics can attribute a consented session without storing recipient emails or unsubscribe tokens. | Analytics (optional) | Until the browser tab or session ends |
| Amazon affiliate destination cookies/storage | Cookie/storage (provider-dependent) | May be set by Amazon after you click an optional sponsored Amazon affiliate link for your visitor market. The in-app sponsored cards are static and do not load Amazon scripts before click-through. | Sponsored content (optional) | Provider-defined after click-through |
3. Optional Technologies
- Necessary first-party retention-funnel telemetry for scanner home sessions uses the browser guest identifier and session-scoped retention key above. This telemetry is separate from optional PostHog analytics and does not change the consent-banner behavior.
- Necessary first-party experiment telemetry uses the browser guest identifier or signed-in user id, depending on the experiment's assignment unit. Compatible experiment properties are mirrored to PostHog only through the existing consent-gated analytics path.
- Optional browser push reminders use browser notification permission. Lesson limit reminders are independent from rating limit reminders and can be enabled or disabled separately.
- Optional lifecycle email consent uses the Google account email returned after sign-in only when you check the email opt-in box. This is separate from cookie analytics consent and browser push reminder consent.
- Optional PostHog event capture, including server-side rating, contextual-feedback, site-feedback, and AI-provider diagnostics, plus client-side exception diagnostics and session replay, is enabled only after you consent to analytics and sponsored content, only in verified production, and only when PostHog is configured.
- Relevant same-origin API requests carry the bounded consent declaration in a first-party cookie and request header. Missing, withdrawn, mismatched, malformed, older-than-365-day, or materially future-dated declarations do not authorize server analytics.
- Optional static Amazon affiliate cards may be shown only after you consent to analytics and sponsored content. They do not load Amazon script on this site before you click through.
- Optional analytics storage is used only after that consent and supports anonymous visitor/session measurement.
4. Manage or Withdraw Consent
Use the in-app "Cookie Settings" control to update your preferences. Changes apply to future processing. Withdrawing analytics consent disables browser PostHog capture, resets its browser analytics identity, and removes ToyOrNot's optional analytics visitor and session identifiers from browser storage. Enabling analytics again creates new browser visitor and session identities. Withdrawal stops future optional server capture until you consent again, but it does not delete previously captured PostHog events or rotate necessary account and feedback identifiers. Consented server events may therefore be associated with the same pseudonymous identifier after later consent. You can also clear browser storage to remove saved preferences. Email lifecycle consent can be withdrawn through the unsubscribe mechanism in lifecycle emails when configured, or by contacting the operator.
5. Contact
Questions about cookies or consent: toyornot.com@gmail.com