Cookie Policy
Short version: sttchr.com sets no cookies of its own, and we use no advertising or cross-site tracking anywhere on the site. We do not sell or share your personal information. What we do use is a small amount of browser storage, most of it required to sign you in and keep the site secure, plus one optional analytics identifier that is only ever written if you say yes.
Opens the same notice you saw on your first visit. You can switch it either way, as often as you like.
1. Strictly necessary storage
These are set without asking, because the site cannot do what you asked of it otherwise. Under the ePrivacy rules they fall inside the strictly necessary exemption.
| Item | Type | Set by | What it does | How long |
|---|---|---|---|---|
sttchr_consent | Local storage | sttchr.com | Records your analytics choice and the date you made it, so we do not ask again. This is the one thing we must store even if you decline, because it is how the decline is remembered. | 12 months, then we ask again |
firebaseLocalStorageDb, firebase:authUser:* | IndexedDB, local storage | sttchr.com (Firebase Authentication) | Keeps you signed in between pages and visits. | Until you sign out or clear your browser |
sttchr.web.token | Local storage | sttchr.com | Holds your session token for our API. | Until you sign out or clear your browser |
_GRECAPTCHA, plus reCAPTCHA's own storage | Cookie, local storage | google.com | Firebase App Check with reCAPTCHA. Confirms a request came from the real Sttchr site rather than an automated script. This protects purchases, creator accounts, and payouts from abuse, so it is not optional. | Up to 6 months, set by Google |
firebase-app-check-database | IndexedDB | sttchr.com | Caches the App Check token from above so it is not requested on every action. | Until you clear your browser |
sttchr.apiBase | Local storage | sttchr.com | A development setting, written only if you deliberately open a URL with an ?api= parameter. |
Until you clear your browser |
2. Things you switch on yourself
Set only as a direct result of an action you took, and only remembering what you chose.
| Item | Type | Set by | What it does | How long |
|---|---|---|---|---|
sttchr_listing_view | Local storage | sttchr.com | Remembers whether you picked the grid or the list view on your seller dashboard. | Until you clear your browser |
sttchr_search_recents | Local storage | sttchr.com | Your last few search terms, so the search box can offer them again. Never leaves your browser. | Until you clear your browser |
firebase-messaging-database, service worker | IndexedDB, service worker | sttchr.com (Firebase Cloud Messaging) | Registered only if you turn on browser notifications, so we can deliver them. | Until you turn notifications off or clear your browser |
3. Analytics, only with your consent
This is the only category that asks. Until you accept, we send no analytics request and write no analytics identifier. Declining, or withdrawing later, deletes the identifier from your browser.
| Item | Type | Set by | What it does | How long |
|---|---|---|---|---|
sttchr_anon_id | Local storage | sttchr.com | A random identifier containing no personal information, so that several page views from you count as one visitor rather than several. Written only after you accept. | 12 months, or until you withdraw |
| PostHog event requests | No cookie. A request to us.i.posthog.com | sttchr.com | Carries the event name, the page path with no query string, and the identifier above, so we can see which pages and features get used. We deliberately do not use PostHog's autocapture, so every event is one we chose to send. Never includes your email or anything you have typed. | See retention in the Privacy Policy |
4. Global Privacy Control
If your browser sends a Global Privacy Control signal, we treat it as a standing refusal: analytics stays off and we do not show you the notice at all. You do not need to do anything else.
5. Other third parties
Two more services are involved in loading the site, and neither is used to track you.
Our code and fonts are served from our own domain, and the Firebase SDK is loaded from
Google's gstatic.com CDN, which is required for the site to run at all.
Payments happen on Stripe's own checkout pages, so any cookie Stripe sets is set there
and is governed by Stripe's policy, not this one.
6. Changing your mind, or removing everything
Use Change your analytics choice above at any time. To clear everything at once, clear this site's storage in your browser settings. That will sign you out, reset the preferences above, and make us ask about analytics again.
7. Questions
Email sttchr.app@gmail.com. See also our Privacy Policy and Terms of Service.