Cookie Policy

Last updated: October 8, 2026  ·  Datylux

This Cookie Policy explains how Datylux uses cookies and similar browser storage technologies when you use our platform. We ask for your consent before setting any non-essential cookies. You can manage your choices anytime via the Cookie preferences link at the bottom of every page.

What Are Cookies?

Cookies are small text files stored on your device by your web browser when you visit a website. They allow websites to remember your login status and preferences between visits.

Datylux also uses local storage and session storage — similar browser-based technologies that store data on your device to make the app work smoothly between sessions. We refer to these together as browser storage in this policy.

Cookie Categories

We group browser storage into four categories. Strictly necessary storage is always active because the site cannot function without it. Analytics and marketing cookies are optional and only enabled after you consent.

Strictly Necessary

NameProviderPurposeDuration
sb-...-auth-token
Supabase auth browser storage
Supabase Keep you signed in to your Datylux account. Without this, the app cannot reliably confirm your session. Session / up to 7 days
dl_cookie_consent_v3
dl_cookie_consent_history_v3
Datylux Records your choice, timestamp, policy version, and browser privacy signals on this device. Keeps a limited local history of up to 20 choices; it is not a server-side consent register. 180 days; expired records are removed on a subsequent visit

Functional / App Preferences

NameProviderPurposeDuration
dl_cache Datylux Caches limited saved-campaign summaries locally so the app can load faster. Full saved campaign data is stored server-side only when you choose to save it. Persistent until cleared
dl_theme Datylux Remembers your dark or light mode preference between sessions. Persistent until cleared
dl_tour_seen Datylux Remembers whether you have completed the onboarding tour so it does not repeat. Persistent until cleared

Analytics (Optional)

NameProviderPurposeDuration
_ga Google Analytics 4 Distinguishes unique visitors. Uses a pseudonymous identifier that may be personal data; it does not contain your name or email. Up to 180 days in our configuration
_ga_6D7DB462ZC Google Analytics 4 Persists session state for our specific GA4 property. Used to count pageviews and feature usage in aggregate. Up to 180 days in our configuration

Google Analytics is blocked from loading until you accept analytics cookies. Google advertising signals and advertising personalization are disabled. Rejecting analytics also blocks Google Analytics cookieless requests from the tag because the tag is not loaded. Google’s handling of this data is governed by their Privacy Policy.

Marketing (Optional)

NameProviderPurposeDuration
li_fat_id
bcookie
bscookie
UserMatchHistory
AnalyticsSyncHistory
lidc
LinkedIn Measures Datylux LinkedIn ad performance and website visits. With purpose-specific marketing permission and a server check, a confirmed Pro trial can be measured once. Signup and checkout clicks do not count as trials. Varies by cookie; generally session to 2 years depending on LinkedIn settings and browser controls.

The LinkedIn Insight Tag is only loaded if you accept marketing cookies. LinkedIn’s handling of this data is governed by their Privacy Policy.

First-party campaign and privacy storage

With purpose-specific marketing permission, Datylux keeps only approved first/latest campaign source, medium, campaign and creative codes, plus a 30-day expiry. An account binding prevents mixing attribution between signed-in accounts. Both have a fixed 30-day window; browsing does not renew it. No full URL, email, imported CSV/report contents or advertising click identifier is added to this storage.

Withdrawal clears local campaign codes immediately. A pending-removal receipt contains only the account identifier, random nonce and creation time, with at most 20 accounts and a 30-day logical limit. It exists to retry authenticated account removal and is removed after matching acknowledgment or, once expired, when the site next runs. The account binding is removed after acknowledgment. Expired local entries are physically removed when the site next runs; inactive devices cannot be remotely erased.

Account-linked server measurement is enabled only after automatic cleanup and its monitoring are verified operational. The following retention and cleanup periods apply to records collected while it is enabled. Our existing server stores account-linked campaign codes for 30 days, consented trial/deduplication records for 90 days and minimal consent state until 180 days after its last authenticated consent update. Campaign copies inside trial records also expire at the original 30-day deadline. Routine authenticated consent updates can extend minimal consent-state retention for active accounts. Daily housekeeping removes expired server fields/records within 24 hours. No new measurement trial row is created without valid permission that began by trial start. Account deletion removes these linked records. See our Privacy Policy for recipients and details.

The existing cookie choice/history lasts up to 180 days with at most 20 choices. Earlier generic marketing permission alone does not enable this new account-linked trial purpose in this release. Analytics remains independent.

What We Do Not Use

Datylux does not use:

Managing Cookies

The easiest way is the in-app consent banner. Click Cookie preferences at any time to manage analytics and marketing consent. Your choice is stored on this browser for up to 180 days; simply revisiting the site does not extend it. We request a new choice after expiry or a material consent-policy change. Optional tracking stays off if your browser cannot save the choice.

Browser privacy signals: Global Privacy Control (GPC) and Do Not Track (DNT) disable Marketing, even after an earlier opt-in. You may still choose Analytics separately. Use Cookie preferences as your Do not sell or share / targeted advertising opt-out control.

Withdrawal: Turning a category off clears the matching first-party cookies that Datylux can access. If a tracker is already running, the page refreshes to stop its scripts; save unfinished forms first. Cookies set on Google or LinkedIn domains cannot be erased by Datylux. You can remove those through browser settings or use the provider's privacy controls. Withdrawal stops future tracking through these tags; it cannot retract information already sent.

Account-linked removal: If signed in, withdrawal sends removal to our server. Acknowledgment clears marketing fields and suppresses pending trial conversions. Offline removal is visibly pending and retried when that account reconnects or signs in; another offline/anonymous device keeps its own choice until it updates or signs in. Necessary billing and minimal consented-trial deduplication records are separate from campaign fields. Browser controls cannot retract requests already sent or LinkedIn records already received.

You can also control or delete cookies through your browser settings. Note that disabling strictly necessary cookies (Supabase auth) will prevent you from staying logged in to Datylux.

To delete your saved campaign data, use the delete options within the app or your Account page. To clear all browser-level preferences, clear site data for datylux.com in your browser's developer tools.

For browser-specific instructions:

Changes to This Policy

We may update this Cookie Policy from time to time. Changes will be reflected by the updated date at the top of this page.

Contact

If you have questions about our use of cookies, please contact us at support@datylux.com.