Cookie Policy
Effective: September 20, 2026
Version: 1.4
This Policy explains how Eveli, Inc. uses cookies, local storage, pixels, SDKs and similar device technologies on eveli.ai and related services.
1. Categories
Strictly necessary
Limited to technologies objectively necessary for a user-requested service or secure operation. Authentication, security, load balancing and consent storage may qualify; payment, anti-abuse and other technologies must be assessed individually rather than labeled necessary by provider or purpose alone. Necessary technologies cannot be switched off through the cookie tool.
Preferences
Remember optional interface, language or personalization choices. These remain off until consent where law requires.
Analytics
Measure use, errors and product performance. These remain off for EU/EEA and UK users until consent.
EVELI's active-time measurement falls in this category. It is analytics, not strictly necessary: EVELI can deliver the Service without it. It is described in full in Section 2A of the Privacy Notice. Unusually for this category, it uses no device technology at all — no cookie, no local storage, no IndexedDB, no pixel, no SDK and no device identifier — so there is nothing on your device to block or clear. It is switched off in the product configuration until every condition in Section 2 below is met, and acceptance of the Terms of Service never switches it on.
Marketing
Measure campaigns, create advertising audiences or track activity across services. These remain off until consent. EVELI does not condition Service access on marketing-cookie consent.
2. Your choices
The customer application uses product storage needed for sign-in, device identity, casting work and security. It also loads optional technologies that stay off until you consent. Google Analytics (Google Ireland Limited) sets _ga for up to two years, _gid for twenty-four hours and _gat. On the marketing site only, the Meta Pixel (Meta Platforms Ireland Limited) sets _fbp and _fbc for up to ninety days. Also on the marketing site only, Framer Analytics (Framer B.V.) is cookieless: it stores nothing on your device and sets no identifier, so there is nothing to block or clear. You make that choice in the consent banner, and you can change or withdraw it at any time through Cookie settings in the footer.
Active-time measurement. This is the one optional analytics purpose EVELI has introduced. It is disabled in the shipped product and will not run for any account until all of the following are true: a server-side feature switch, controlled only by EVELI operators and off unless explicitly turned on, is enabled; the account is a signed-in paid account; a valid analytics permission has been recorded separately from Terms acceptance and has not been withdrawn; the published legal package discloses the measurement, which it does from version 1.3; and the account's jurisdiction and configuration permit it. If any one of these is missing, unreadable or unknown, no time is measured. Acceptance of the Terms of Service is not, and cannot be, that permission.
If EVELI enables a further optional technology, it will update the table below and, before activation where consent is required, provide equally accessible Reject non-essential, Manage choices and Accept all controls. Optional categories will remain off until the user chooses them. Browser blocking or clearing local storage may sign a user out or remove device-local casting work, but does not affect active-time measurement, which stores nothing on the device.
3. Live technology table
| Technology | Provider | Purpose | Category/legal basis | First/third party | Data | Duration |
|---|---|---|---|---|---|---|
\eveli_beta_session\ local storage | EVELI/Supabase authentication | Maintain the signed-in session and refresh it securely | Strictly necessary; requested service and security | First party | Access token, refresh token, account email and expiry | Until sign-out, token expiry or browser storage is cleared |
\eveli_casting_v2\ and legacy casting local storage | EVELI | Save device-local casting work and migrate earlier drafts | Strictly necessary for the requested save function | First party | Casting brief, choices, local project state and asset references | Until the user deletes/overwrites the work or clears browser storage |
\eveli_principal\ and \eveli_device_id\ local storage | EVELI | Maintain a stable device-scoped owner when verified production persistence is unavailable | Strictly necessary for record separation and continuity | First party | Random device identifier and cached principal state | Until browser storage is cleared or replaced by verified production identity |
| Cloudflare security technologies, only when a security challenge is triggered | Cloudflare, Inc. | Deliver the site, prevent abuse and protect requests | Strictly necessary security | Third party | IP address, request/device and security signals | Provider-configured, risk-based duration |
| Stripe Checkout and Billing Portal technologies, after the user chooses to purchase or manage a plan | Stripe | Secure payment, fraud prevention and subscription management on Stripe-hosted pages | Strictly necessary for the requested transaction | Third party | Transaction, browser/device and fraud-prevention data | Under Stripe's published policy and legal retention duties |
| Active-time measurement, only while enabled and permitted | EVELI | Estimate meaningful authenticated product use for internal product measurement, reliability, support, capacity planning and aggregate business reporting | Analytics; NOT strictly necessary. Consent where required, recorded separately from Terms acceptance | First party, no third-party SDK | Pseudonymous account identifier, UTC date, environment, active seconds, first/last activity timestamps, short-lived idempotency receipt. No prompts, entered text, generated content, route history, pointer coordinates, IP address, user agent, referrer, device identifier, fingerprint or cross-site activity | Nothing stored on the device. Receipts no longer than 7 days; per-account daily totals for the life of the paid account, then deleted or irreversibly deidentified |
The table must include cookies, local storage, pixels, scripts, SDK identifiers and server-side events that rely on device data. Re-scan after every analytics, payment, authentication, anti-abuse, marketing or hosting change.
4. Consent records
No optional-cookie consent record is created while no optional device technology is offered.
Where consent is required for active-time measurement, EVELI records it as its own record — the policy version, the specific purpose, the timestamp, the region and the interface language — separately from Terms acceptance and separately from any other agreement. Accepting the Terms of Service, authorizing a subscription or acknowledging an earlier legal version does not create that record and is never treated as though it did. Acknowledging version 1.2 is not acknowledgement of version 1.3. Withdrawal is as easy as acceptance, and a policy update will not revive withdrawn consent.
5. Contact
Questions: legal@eveli.ai