Metropolygonia Open app
Cookie Policy

Cookies and browser storage, without surprises.

The current source audit found necessary account and preference storage plus consent-based Microsoft Clarity analytics. It found no advertising pixel or behavioural marketing tracker.

Version 1.0.0 · Published: 26 July 2026 · Effective: 26 July 2026 · Audit date: 26 July 2026

Technical draft — production scan requiredRun and reconcile a Cookiebot scan on the production domain before launch and after adding any external service.
01

Necessary technologies

Supabase Auth stores the authentication session in browser storage so the application can keep you signed in, refresh tokens and protect access to account data. Cookiebot records the cookie decision.

Metropolygonia also uses:

  • metropolygonia-language in localStorage for the selected language;
  • archiform-realistic-textures-v1 in localStorage for local texture choices and scale settings;
  • archiform-city-project-v1 in localStorage for a local city-project draft;
  • metropolygonia-oauth-acceptance in sessionStorage for short-lived legal-acceptance state during an OAuth redirect.

These mechanisms are not used for behavioural advertising. Clearing them may sign you out or remove local preferences and unsaved local city data.

02

Analytics only after consent

Microsoft Clarity can produce aggregate usage statistics, heatmaps and interaction recordings. The application uses Cookiebot in manual consent mode and dynamically loads Clarity only after the user grants the Statistics category.

Rejecting or withdrawing Statistics consent prevents further analytics loading and does not restrict the generator, account, project editing or exports. Advertising storage remains denied because the application does not use an advertising tracker.

03

Marketing technologies

The source audit found no advertising pixel, tag manager or behavioural-advertising tracker. Email marketing consent and in-app promotional consent are account records, not browser trackers. Resend operates server-side only when an email is sent and does not load a browser script or tracker.

04

Choose, reject and change

The Cookiebot banner must present equally visible options to accept or reject non-essential technologies and must allow a category-level choice. You can reopen it at any time with the Cookie settings button below. Withdrawing consent does not affect earlier lawful processing.

05

Current inventory and dynamic declaration

The implementation-level inventory is maintained in docs/TRACKING_INVENTORY.md. The declaration below is generated from the Cookiebot domain scan and lists detected cookie names, providers, purposes and durations.