Cookie Policy
What we store on your device, and why.
Last updated: 2026-08-18
This Cookie Policy explains the cookies and similar technologies that Auraverse LLC (“Auraverse,” “we,” “us”) uses on the Auraverse website and services (the “Service”). It is part of our Privacy Policy, which explains what we do with the information involved.
1. What these technologies are
A cookie is a small file a site stores in your browser and reads back on later visits. Browsers offer other storage for the same job — local storage is the one we use — and this Policy covers both. Storage set by auraverse.fm is “first-party”; storage set by another company whose code runs on the page (our payment processor, and our advertising and consent partners once advertising is enabled) is “third-party.”
2. What we store today
These are used on every plan, including free and signed-out browsing. Most of them are needed to run the Service; the entries set by or for our analytics provider measure how the Service itself is used. All of them are first-party — none of them are cross-site tracking technologies.
| Name | Type | Set by | Purpose | Lifetime |
|---|---|---|---|---|
Sign-in cookies (for example __session, __client_uat) | Cookie | Clerk (our authentication provider) | Keeps you signed in and keeps your session secure. | Session-based; durations are set by Clerk. |
__return_to | Cookie | Auraverse | Returns you to the page you were viewing after you sign in. | 45 minutes. |
share_ref | Cookie | Auraverse | Credits a sign-up to the shared link you followed. | 30 minutes. |
aura-ad-session | Browser local storage | Auraverse | A random, opaque identifier with no personal information in it, used to limit how often the same ad is shown to this browser — including when you are signed out. First-party only; not used to track you across other sites. | Until you clear your browser's site data. |
aura-ad-opt-out | Browser local storage | Auraverse | Records that you used the “Do Not Sell or Share My Personal Information” control, so this browser keeps applying your opt-out — including when you are signed out. Set only if you use that control; it holds nothing but that one choice. | Until you clear your browser's site data. |
Payment cookies (for example __stripe_mid, __stripe_sid) | Cookie | Stripe (our payment processor) | Runs checkout and subscription management and helps Stripe detect payment fraud. | Up to one year, as set by Stripe. |
ph_[our project key]_posthog | Cookie and browser local storage | PostHog (our analytics provider) | A random identifier used to measure how the Service itself is used — pages viewed, which features get tried, and whether you come back. First-party product analytics only; it honors your browser's “Do Not Track” setting and is not used to track you across other sites. | Cookie: up to one year. Local storage: until you clear your browser's site data. |
aura_ref | Cookie | Auraverse | Remembers which link or campaign (for example a ?ref= tag on our landing page) brought you here, so we can credit that channel if you sign up. | 30 days. |
aura_first_seen and aura_fnl_… markers | Browser local storage | Auraverse | Small first-party markers recording the date of your first visit and which first-time actions (for example your first swipe or first chat message) have already been counted, so our analytics count each of them only once. | Until you clear your browser's site data. |
We use two analytics tools. PostHog provides the first-party product analytics described in the table above; we configure it to honor your browser’s “Do Not Track” setting and to create a person profile only once you sign in. Vercel Analytics, run by our hosting provider, counts page views and referrers cookielessly — it stores nothing on your device, which is why it has no row in the table.
Our contact form is protected by Cloudflare Turnstile, which checks that a submission comes from a person rather than a bot. Turnstile sets no tracking cookies; it receives your IP address and basic browser signals solely to score that check.
3. What activates when advertising is enabled
The Service is ad-supported on its free tier; paid Patron plans are ad-free. When advertising is enabled, our own promotions (“house ads”) are chosen on our servers and set no additional storage beyond the aura-ad-session identifier listed above. Ads served through a third-party advertising network, and the consent prompt that gates them, involve the following categories:
| Name | Type | Set by | Purpose | Lifetime |
|---|---|---|---|---|
Consent storage (FCCDCF, FCNEC, and an IAB consent string) | Cookie and browser local storage | Google Privacy & Messaging (our consent management platform) | Records the advertising choices you make in the consent prompt, so you are not asked again on every visit and so your choice can be enforced when an ad is selected. The consent string is the standard IAB Transparency & Consent Framework record of exactly which purposes and vendors you allowed. | Typically up to 13 months, as set by the consent platform. |
Ad-serving cookies | Cookie | Our advertising network | Selects which ad to serve, caps how often you see it, and detects invalid or automated traffic. | Varies by cookie, as set by the advertising network. |
Ad-measurement cookies | Cookie | Our advertising network | Counts views and clicks so ad performance can be reported and billed. | Varies by cookie, as set by the advertising network. |
Where consent is legally required for personalized advertising, we collect it through Google Privacy & Messaging, a Google-certified consent platform using the IAB Transparency & Consent Framework, before any third-party ad request is made. Google targets the prompt to the places that require one, so most visitors never see it. Nothing in the table above loads or is stored until third-party advertising is switched on — the consent script does not run before then, and none runs today. Without consent you are served our own ads instead — the decision is made on our servers, which hold the advertising network’s tag and release it only when a lawful basis is recorded, so no ad request is made on your behalf either way. Advertisers never receive your chat messages, voice transcripts, the memories artists hold about you, or your email address. See Section 6 of the Privacy Policy.
4. Your choices
- Browser controls. Every major browser lets you block or delete cookies and clear site data. Blocking the sign-in cookies will stop you from being able to sign in, and the Service will not work.
- Consent control. Where a consent prompt applies to you, you can change your advertising choices at any time from the consent control on the site.
- Opting out of personalized ads. We provide a “Do Not Sell or Share My Personal Information” control, linked in the footer of every page and available at Settings → Privacy. No account is needed. We also honor Global Privacy Control (GPC) browser signals as an opt-out request on their own, so a browser that sends one is opted out without using the control. Either way the choice is enforced on our servers when the ad is selected. Opting out does not remove ads — it leaves you with our own ads or non-personalized ads.
- No ads at all. A paid Patron subscription removes advertising from the Service.
5. Children
The Service is intended for users age 18 and older and is not directed to minors. We do not knowingly collect personal information from anyone under 18. We do not serve personalized or third-party network advertising to users we know to be under 18, and we never use age or date of birth to target advertising. See Section 12 of the Privacy Policy.
6. Changes and contact
We may update this Policy from time to time and will update the “Last updated” date above. Questions? Email support@auraverse.fm or use our contact page.