Cookies and local storage
## v0.4 necessary chat controls When you open the assistant, the necessary HttpOnly **filaraki_chat** cookie associates this browser with a random server identifier for up to 180 days. It supports a 24-hour verification session and daily anti-abuse counters; it is not used for analytics or advertising. **filaraki_chat_reopen** in sessionStorage contains only a flag to reopen chat after login, then is removed. **filaraki_location_prompt** in sessionStorage remembers that the location prompt was answered during this tab session; it contains no coordinates. These controls do not enable optional maps or analytics. Change those separately in **Settings → Website preferences** or the footer. --- ## Map display provider Optional external maps now use MapLibre with Geoapify map data. Enabling maps permits direct browser requests to Geoapify. Disabling maps removes active map views and stops new map requests; requests already sent cannot be recalled. Filaraki's service worker does not cache external map tiles for offline use. --- ## Necessary Google sign-in cookies Only when starting Google sign-in, **filaraki_google_flow** binds the authorization response to your browser, and **filaraki_google_result** briefly holds a one-use reference for completion. These first-party HttpOnly, SameSite=Lax cookies last up to ten minutes and use Secure on HTTPS. They are not analytics or advertising cookies. Google controls cookies on its own sign-in pages. Password login remains available. Report drafts in this tab may also retain uploaded-photo references and selected location information for up to 24 hours, so a sign-in redirect does not lose that progress. Dedicated contact, microchip, private identifying features and acceptance fields are excluded. Clear the draft using the report form if you share a device. --- ## v0.3 choices and optional analytics This update supersedes earlier references to maps as the only optional feature or to analytics being absent. Choose **Necessary only**, **Accept all**, or **Settings**. Maps and usage analytics have separate switches, both off by default. Consent is requested again for this release. Choices are saved for up to 180 days. Optional **filaraki_analytics_session** in sessionStorage contains a random tab-session ID and creation time, rotated after 24 hours. It is created only when analytics are allowed. Withdrawal removes it and requests server-side deletion of associated events. **filaraki_analytics_withdrawal** temporarily retains the ID solely to retry a deletion request. A one-day server tombstone rejects late requests. Events expire after 14 days; active-session records after one day, with removal by the worker. No replay, keystrokes, private page contents or advertising identifiers are collected. Browser DNT/GPC signals prevent collection even if the switch is enabled. See the [Privacy policy](/privacy). --- ## What we use Filaraki uses browser storage and technical features for sign-in, choices you request, security and installation as an app. This release has no advertising or traffic analytics cookies. ## Necessary features - **pawhaven_token / pawhaven_user (localStorage):** sign-in and local account details. The token expires after 8 hours. Signing out removes these entries; token expiry alone does not remove every local copy. - **pawhaven_language:** remembers your Greek/English choice. - **pawhaven_favorites:** stores animals you save as a guest. They can be merged into your account when you sign in. - **pawhaven_report_draft (sessionStorage):** a draft in the current tab, with a 24-hour expiry check. Dedicated contact fields, microchip details, private features and acceptances are excluded. - **pawhaven_ai_hint (sessionStorage):** remembers that you dismissed the assistant hint for this session. - **filaraki_cookie_choice:** remembers your external-map choice for 6 months. It is not an advertising identifier. - **Service worker / Cache Storage:** static files and an offline page for the PWA. It does not cache API responses, report photos or map tiles. Browser storage remains until cleared, replaced or expired as described. Clearing it in browser settings may remove sign-in state, drafts and preferences. ## Anti-abuse checks Cloudflare Turnstile loads when you request a protected action such as submitting a form. It processes browser/connection signals for security, not advertising. Security cookies can depend on the hosting account's Cloudflare configuration. Read [Cloudflare's privacy notice](https://www.cloudflare.com/privacypolicy/). ## Optional external maps Maps stay off until you allow them. Enabling them sends your IP, technical details and requested map tiles/area to the configured map provider. Report lists work without maps. This choice covers maps, not all site images: animal/organization photos and form security are separate functions. ## Your choices Use the banner to keep necessary features only, allow external maps or open settings. Maps are not selected in advance. Continuing to browse is not acceptance. Change or withdraw your choice using **Cookie settings** in the footer. Withdrawal stops new map requests; it cannot recall data already transmitted. Any new optional tools require an updated policy and choice mechanism before activation. See our [Privacy policy](/privacy).
