← Back
Legal · Version 2.0

Cookie Policy

Effective 31 July 2026

Change your cookie preferences

Re-open the preferences manager to update your choices any time.

This Cookie Policy explains how the Cuddly Platform uses cookies, localStorage, and other similar storage technologies (collectively “cookies” throughout, in line with EU ePrivacy Directive Article 5(3) terminology) when you use our service.

Two things are true cookies: your sign-in session and your chosen interface language. Everything else the platform stores lives in localStorage, which stays in your browser and is never transmitted with HTTP requests — but ePrivacy treats localStorage as a “similar technology” that requires the same consent rules as traditional cookies. We apply the same rigour to both.

1. The four categories

Essential

Strictly necessary for the platform to function. You cannot opt out of these — without them you cannot stay signed in, maintain a project context, or see the interface in the language you picked. We rely on the “strictly necessary” exemption in Article 5(3).

Functional

Remember your preferences (CMS choices, your cookie consent itself). The platform works without these, just less conveniently. You can decline these in the preferences manager.

Analytics

Currently not in use. We do not run Google Analytics, Hotjar, Segment, Mixpanel or any equivalent. The toggle exists so that if we ever add product analytics, your declared preference applies before any request lands.

Marketing

Currently not in use. We do not run advertising, retargeting, or third-party marketing trackers. Same forward-compatible reasoning as Analytics.

2. What we actually store — full inventory

The complete list of items the platform stores in your browser, plus third-party services that may set their own cookies on their own domains when you interact with them.

ItemCategoryStorageDurationPurpose
cuddly_sessionEssentialCookie8 hours, or until you sign outYour signed session token, held in an HttpOnly cookie that JavaScript running on the page cannot read. It is sent with every request to our API to authenticate you. Without it you cannot stay signed in.
cuddly_localeEssentialCookie12 monthsThe interface language you chose (e.g. en-GB, fi-FI). Held in a cookie rather than localStorage so pages rendered on the server come back in the right language on the very first request.
cuddly_userEssentiallocalStorageSession (cleared on sign-out)Cached profile — name, email, role, language and persona preference, and any profile fields you have filled in (job title, phone) — so each page render does not need a round-trip to the server.
cuddly_projectsEssentiallocalStorageSession (cleared on sign-out)Cached list of projects you belong to, populates the My Projects sidebar.
cuddly_current_projectEssentiallocalStorageSessionRemembers which project you have open so the project sidebar persists across navigations.
cuddly_cookie_consentFunctionallocalStorage12 months, or until we publish a new version of this policyRecords this very consent choice, plus the policy version and timestamp, so we don't re-prompt you on every visit.
Stripe (Checkout)FunctionalCookieSet by stripe.comWhen you pay an invoice via Pay-by-card, Stripe's hosted Checkout page sets its own session and fraud-prevention cookies on stripe.com. We never see those cookies.

3. Third-party services

We try to keep third-party requests to a minimum. Anything that loads from a domain other than thecuddly.app is listed below.

Outside of the above, the platform is self-contained: fonts are bundled at build time, JavaScript is served from our own origin, and we do not embed third-party widgets, analytics, or marketing tags. No cookies leave the browser to ad networks or trackers.

4. How to manage your preferences

Use the Manage preferences button at the top of this page (or any “Cookie settings” link) to open the preferences manager. You can change your choice as often as you like; the new choice takes effect immediately.

You can also clear all Cuddly storage from your browser’s privacy controls. The next time you visit the platform, the consent banner re-appears and you can make a fresh choice.

5. Where your consent is recorded

Your choice is stored in your browser’s localStorage as cuddly_cookie_consent with a timestamp, the policy version, and the categories you accepted. If you are signed in to Cuddly, we also record the same information server-side against your user account so our Data Protection Officer can answer the audit question “when did this user consent to functional cookies?” without ambiguity.

If we update this policy in a way that affects you, we bump the version number and re-prompt everyone on next visit. Your previous record is kept for the audit trail.

6. Contact

Questions or complaints about how we handle cookies and storage? Contact our Data Protection Officer at privacy@thecuddly.app. You also have the right to file a complaint with the data-protection authority in your country — for Finnish customers, Tietosuojavaltuutetun toimisto.

See also: Privacy Policy · Terms of Service · Data Processing Agreement