1. What these technologies are
"Cookies" are small files stored by your browser. "Local storage" is a related browser mechanism for storing small amounts of data on your device. We use both for the limited purposes below, including cookies set by Microsoft Clarity, a third-party analytics provider (see Section 2). We do not use third-party advertising cookies or cross-site advertising trackers.
2. What we use, why, and for how long
| Name | Type | Purpose | Category | Duration |
|---|---|---|---|---|
NEXT_LOCALE | Cookie | Remembers your chosen language so the site displays in your locale | Functional | ~12 months |
cl_age_18 | Cookie (signed token) | Records that you affirmed you are 18+ so we don't show the age gate on every visit; lets you skip re-confirmation. Contains a signed, tamper-evident token (not your identity) | Strictly necessary (for lawful operation of an 18+ service) | 90 days by default; 12 months if you choose "remember for a year" |
| Authentication tokens | localStorage (not a cookie) | Keeps you signed in and authorizes requests to our API | Strictly necessary | Until you sign out, the session expires, or you clear browser storage |
_clck | Cookie (Microsoft Clarity) | Persists a unique visitor identifier across visits so Clarity can group session recordings and heatmaps per visitor. Set only on our public marketing and legal pages, and only for anonymous (logged-out) visitors — see Section 3 (Sharing and sub-processors) of our Privacy Policy | Analytics (third-party) | ~1 year |
_clsk | Cookie (Microsoft Clarity) | Links the page views within a single visit into one session recording. Same scope as _clck above | Analytics (third-party) | ~1 day |
| Umami analytics | None — cookieless, no local storage | Our self-hosted Umami analytics never sets a cookie or writes to local/session storage. Its script is present on every page of the Service, but we record a page view only for our public marketing, SEO, catalog, image-generator, and legal pages; a named product event may be recorded from any page, with the page address replaced by a fixed placeholder when it fires outside those pages. See our Privacy Policy for full detail, including the separate, account-linked activity log we keep for signed-in users on those same pages | Analytics (first-party, self-hosted) | Not applicable |
| Web push subscription state (Firebase Cloud Messaging) | localStorage / browser push registration | If you opt in to web push notifications | Functional (opt-in) | Until you disable notifications |
We may also use transient, strictly-necessary technologies required for security (e.g., abuse prevention) and for the basic functioning of pages.
About Microsoft Clarity. Clarity provides session-replay recordings and heatmaps that help us understand how visitors use our public pages. It records anonymous, logged-out visitors only, on a limited allowlist of public marketing, SEO, and legal pages — the authenticated app, sign-in/sign-up flows, and any page that could show your account content are never recorded, and recording stops immediately if you sign in during a session. Data collected by Clarity is processed by Microsoft as our sub-processor.
About Umami analytics. Umami is our self-hosted, cookieless analytics tool — it never reads or writes a cookie or a local/session-storage item. Its tracking script is present on every page of the Service, including the signed-in app, because a small set of named product events (for example, that a checkout started, or that an image finished generating) needs to be recorded wherever it happens; unlike Clarity, Umami keeps running whether or not you are signed in. We record an actual page view, however, only for our public marketing, SEO, catalog (including individual listing pages), image-generator, and legal pages — never for chat, account, billing, or sign-in pages — and a named event fired outside those pages has its page address swapped for a fixed placeholder before Umami ever sees it, so no account-specific or token-carrying address reaches it. Umami's own database is never linked to your identity. If you are signed in, some of this same public-page activity is additionally kept — this time linked to your account — in a first-party activity log we operate for support, security, and product-quality purposes, viewable only by authorized Charmloop staff; that log is not a cookie or local-storage mechanism (nothing about it is stored on your device) and is described further in our Privacy Policy.
3. Why some of these cannot be switched off
The age-affirmation token and authentication storage are strictly necessary: without them we cannot lawfully gate adult content or keep you securely signed in. They are not used for advertising or profiling. The Clarity cookies and Umami analytics above are not strictly necessary — they support analytics only, and you can decline or limit them as described below.
4. How to control cookies and local storage
- You can clear or block cookies and local storage in your browser settings. Note that clearing the age-affirmation token will cause the age gate to appear again, and clearing authentication storage will sign you out.
- You can block or delete the Microsoft Clarity cookies (
_clck,_clsk) in your browser's cookie settings without affecting your ability to use the Service, since Clarity never runs on pages that require you to be signed in. - Umami sets no cookie or local-storage item to block. Since its script must be present site-wide for named product events to be recorded, the practical way to stop it entirely is to block script requests to our analytics subdomain with a browser extension or network-level tool. If you are signed in, you can also ask us to delete the account-linked activity log described above at any time by contacting privacy@charmloop.ai, or it is deleted automatically when you delete your account.
- We do not currently display a cookie-consent banner. Microsoft Clarity separately enforces its own consent requirement for visitors in the EEA, UK, and Switzerland, which may limit or prevent recording of those sessions.
- You can decline or revoke web-push notifications in your browser at any time.
- If we introduce a consent-management platform or additional non-essential cookies in the future, we will update this Policy accordingly.
5. Changes and contact
We will update this Policy if our use of these technologies changes. Questions: privacy@charmloop.ai.