Cookie, Browser and Device Storage Notice
Published 16 September 2026 · effective 16 September 2026.
Last updated: 16 September 2026 This notice explains cookies and other technologies that store information on, or access information from, a browser, computer, phone or tablet used with FaceCards. It covers more than cookies because FaceCards also uses browser-extension storage, localStorage, secure app storage and desktop application storage. 1. Why this notice exists UK privacy rules can apply to cookies and similar storage/access technologies in websites and apps. We aim to use only the storage needed for requested functionality unless a user has made any additional choice required by law. 2. Authentication and security cookies The FaceCards website may use authentication/session cookies or equivalent mechanisms to keep you signed in, authenticate requests, protect sessions and perform security-sensitive functions. These are intended to be used where necessary to provide the account service you requested. 3. Website local/session storage Website features may use local or session storage for device-side controller state, calibration, installation identity, interface preferences or other requested functions. The precise keys can change as the product is updated, but their purpose must remain consistent with this notice and the Privacy Policy. 4. Local calibration storage Calibration settings can be stored locally on a device so FaceCards can recognise gestures without recalibrating every session. Local calibration may include the derived measurements described in the Camera, Gesture Tracking and Calibration Notice. A saved calibration may also be synchronised to the account separately. Server-side account storage is covered by the Privacy Policy rather than being a browser cookie. 5. Desktop application storage The desktop app uses a FaceCards application store for local settings and a generated installation identifier. Controller bearer credentials are intended to use a secure native storage mechanism rather than ordinary readable web storage. In limited fallback circumstances, a non-secret installation identifier may be kept in the app webview’s local storage. 6. Mobile application storage Native mobile builds may use device secure storage such as Keychain/Keystore for controller credentials and local app storage for settings, installation identity, calibration and mappings. Web-based development/fallback surfaces may use browser local storage instead. 7. Browser extension storage The FaceCards extension uses extension storage for information needed to operate the extension, which may include a random installation identifier, controller token and expiry, connection state, selected mode, limited bootstrap configuration and up to the configured number of page mappings. Page mappings may include the target origin/path prefix and technical locator/control-label information needed to reproduce a user-created mapping. FaceCards does not need to store the text of the flashcard itself merely to execute the mapping. 8. Site permissions are separate from storage A browser extension’s permission to access a website is not itself a cookie. FaceCards may request optional access to a site when you choose to start or map control on that site. See the Platform Permissions, Automation and Compatibility Notice. 9. Server-side aggregate analytics FaceCards’ limited aggregate usage analytics are stored on the server and are not a browser cookie. They are described in the Privacy Policy. 10. Advertising and behavioural tracking FaceCards does not currently intentionally use Meta Pixel, Google Analytics or another behavioural advertising tracker. We do not currently rely on advertising cookies for the core service. Google MediaPipe Tasks performance/utilisation metrics described in the Privacy Policy are operational SDK metrics, not FaceCards behavioural advertising tracking. Any storage/access technology or consent obligation that applies to a released SDK build must be handled consistently with the Privacy Policy and applicable law. If we introduce advertising, cross-site tracking or another non-essential storage/access technology, we will update this notice and obtain consent where required before activating it. 11. Third-party payment/store storage Stripe, Apple, Google, authentication providers or other third parties may use their own cookies, app storage or device identifiers when you interact with their services. Their own notices govern storage they control independently, subject to applicable law. 12. How long local data remains Persistence depends on the technology. Session storage can end with a session; local/extension/app storage can remain until the app, browser profile or extension clears it; secure credentials remain until revoked, expired, signed out or removed through the relevant workflow. Uninstalling an app/extension or clearing a browser profile may remove local data. Account deletion does not automatically wipe data from every device already in your possession. 13. Your controls You can use browser, operating-system and app controls to clear local data or revoke permissions. Blocking strictly necessary authentication storage may prevent sign-in or controller connection from working. 14. Changes and contact We will update this notice if the production storage/tracking design materially changes. Questions: facecardssupport@gmail.com
