LEGAL INFORMATION
Cookies and local storage
What Woven Loves stores on a device, what is essential and how optional tracking is controlled.
Effective and last updated: 1 September 2026
Strictly necessary session cookie
The __Host-ustwo cookie holds an opaque identifier for a server-side login session. It is required for authentication, CSRF protection, device-session binding and account security. It is marked Secure, HttpOnly, SameSite=Lax and Path=/, and expires after the configured session period or when revoked.
The readable password, private answers and AI conversation text are not placed in this cookie. Blocking or deleting it signs the user out and prevents account features from working.
Device sessions and security
The session contains a random device-session binding. Woven Loves stores only its SHA-256 digest in the database together with IP address, browser information and timestamps. This supports individual-device revocation, logout-all and security investigation.
App cache and local storage
The installable web app uses a service worker and browser Cache Storage for the stylesheet, script and app icon so the interface can load reliably. A minimal offline response may be shown when disconnected.
Browser settings, the operating system and installation method may maintain additional local data. Clearing site data removes cached assets and normally signs the user out.
Push notifications
Push is optional and begins only after the user enables it and grants browser permission. The browser creates a subscription endpoint that Woven Loves stores encrypted. Delivery may involve the Push service provided by the browser or operating system.
Push can be disabled in Woven Loves Settings or browser or device settings.
Analytics preference cookie
The __Host-woven-analytics-consent cookie remembers whether analytics was accepted or rejected and the version of the privacy choice. It is treated as a necessary preference because it prevents Woven Loves from repeatedly asking or accidentally enabling analytics contrary to the saved choice. It is Secure, HttpOnly, SameSite=Lax and Path=/ and is refreshed only through an explicit privacy choice.
Rejecting analytics does not create an analytics visitor identifier and does not reduce core service access.
Optional Woven Analytics
Basic public-site statistics do not require the __Host-woven-analytics-id cookie. If optional visitor-level analytics is actively accepted, Woven Loves creates the separate __Host-woven-analytics-id cookie containing a signed random identifier. It is used only by our first-party analytics system to count visits and public page views. It is not an advertising identifier and is not shared with ad networks.
Woven Analytics stores the visit time, the public page path viewed and the random analytics identifier. It does not store query strings, raw IP addresses, full user-agent strings, account identifiers, private answers, private Explorer or intimacy content, Private Guide messages or other relationship text.
Analytics visitor and page-view records are retained for up to 180 days. Woven Loves currently does not load Google Analytics, Meta Pixel, TikTok Pixel or another advertising tracker.
Your controls
The first privacy prompt offers Accept analytics and Reject analytics as direct choices. Cookie settings remain available from the site footer so analytics can be enabled or withdrawn later. Withdrawing analytics deletes the analytics identifier and the linked first-party visitor/event record where available, while necessary account and security storage continues. Global Privacy Control and Do Not Track signals are conservatively honoured by keeping optional analytics disabled. Users can also clear cookies and site data in Chrome, Edge, Safari, Firefox or another browser. Questions can be sent to [email protected].
Policy version 1 September 2026