Version 1.0 · Last updated: 10 August 2026
This page is the full list promised by clause 14.3 of our Privacy Policy. It covers the website at cherie.social. Section 5 covers the Chérie app, which does not use cookies but does use a device identifier, and which we describe here so that everything is in one place.
A cookie is a small file a website asks your browser to keep and to send back on every later request. It is the only one of these technologies that travels back to a server automatically, which is why it is the one the law is written about.
Local storage and session storage are also stored by your browser, but they never travel anywhere on their own. Something has to read them and choose to send them. We use local storage to hold your answers to the questionnaire so that a refresh, a back button or a lost connection does not make you start again.
A device identifier is the app equivalent: a number your phone gives an app so that repeat use can be counted without knowing who you are. It is not a cookie and it is not an advertising identifier.
Strictly necessary means the thing you asked for does not work without it — staying signed in, taking a payment, keeping the site secure. Those do not need your consent. Everything else does.
This is the complete list as at 10 August 2026. If it is not on this list, we do not set it.
| Name | Set by | What it does | How long it lasts | Needs consent? |
|---|---|---|---|---|
__casting_admin_session | Chérie (first party) | Keeps a Chérie administrator signed in to our internal casting console. It is only ever set after a member of staff signs in with an approved email address. Browsing the site as a member or a visitor never sets it. It is HttpOnly — no script on the page can read it — and Secure, and SameSite=Lax. | 5 days, then it expires. Signing out deletes it immediately. | No — strictly necessary |
| Stripe’s own cookies | Stripe, Inc. (third party), from js.stripe.com | Fraud prevention and payment security. Stripe’s payment script loads on the subscription and payment steps only — not on the rest of the site — and Stripe sets its own cookies when it does. We do not set them, we cannot read them, and we do not receive them. Stripe publishes what it sets at stripe.com/legal/cookies-policy. We list them here by reference to Stripe’s own published policy rather than by name, so that this page cannot go stale the next time Stripe changes them. | Set by Stripe. See Stripe’s policy. | No — strictly necessary for taking a payment |
There is no third cookie. In particular there is no analytics cookie, no advertising cookie, no social media cookie, and no cookie set by a content delivery network, an embedded video, an embedded map, or a font provider. Our two typefaces are served from cherie.social itself rather than from Google Fonts, so loading a page does not tell Google that you did.
The questionnaire is long and people fill it in over more than one sitting. So it is saved as you go, on your device.
| Key | Where | What is in it | How long it lasts |
|---|---|---|---|
seasons-quiz | Local storage | Your answers to the first questionnaire, which step you reached, when you started, and the campaign parameters from the link you arrived on (utm_source, utm_medium, utm_campaign, utm_content) so that we can tell which of our own posts and adverts brought people to us. | Until you clear your browser storage for this site. It has no expiry of its own. |
seasons-phase2 | Local storage | Your answers to the second questionnaire, the one after you create an account, and how far through it you are. | Same — until you clear browser storage for this site. |
| Firebase authentication state | Browser storage, written by Google’s Firebase SDK — not a cookie | Your signed-in state, so that you are not asked to sign in again on every page. Only present once you have an account and have signed in. | Until you sign out, or until the sign-in expires. |
The two keys still say seasons because that is what we were called when they were written, and renaming a storage key silently throws away the answers of everyone who is mid-questionnaire at the moment we deploy it. We would rather have an untidy name than lose your work. It holds nothing beyond what is described above.
None of this is readable by anyone else. It is on your device, in storage scoped to cherie.social, and no other website can reach it.
We want to be exact about this rather than reassuring, because “we may use” is how most cookie policies avoid saying anything at all.
What we checked. On 10 August 2026 we read the source of this website and we also fetched the live homepage and read the HTML that was actually served.
What we found. The site contains code for Google Analytics 4 and for the Meta pixel. Both are switched off. Each one only loads if a configuration value holding its ID has been set, and neither ID is set — so on the live site neither script is present, neither runs, and neither sets a cookie. We confirmed that by reading the served page, not by reading the code.
What is still there. Every page does carry three network hints —preconnect to www.googletagmanager.com and to connect.facebook.net, and dns-prefetch to www.google-analytics.com. They are a leftover from when those tools were expected to be switched on. They open a connection in advance; they load no script, run no code and set no cookie. But opening a connection does disclose your IP address to Google and to Meta, and you are entitled to know that even though nothing else follows from it. They should be removed while the tools are off, and this line stays here until they are.
What happens if we turn analytics on. We will ask you first. We will not set an analytics or advertising cookie without your consent, we will update this page before we do it rather than after, and consent will be as easy to withdraw as it was to give. Until that happens there is no cookie banner on this site, for the plain reason that there is nothing to consent to.
The decision on whether to run analytics at all, and on what basis, is not yet made: [To be completed — decision on whether Google Analytics 4 and the Meta pixel are switched on, and the consent mechanism if they are]
The app is not a browser and does not use cookies. Clause 14.4 of the Privacy Policy describes what it does use, and this is the detail behind it.
If we add a cookie, or switch on anything described in section 4, we will update this page before the change goes live, not after. Previous versions are kept at cherie.social/legal/archive, and the date at the top of this page tells you when it last changed.
If something on this page does not match what you see in your own browser, tell us — that is a bug and we want to know. Email hello@cherie.social, or write to Chérie Social, Inc. at the address in our Privacy Policy.