Nutmeg
Cookie Policy
Effective 2026-09-13 · Version 2026-09-13
1. Scope
This policy explains cookies and similar browser storage used by Nutmeg. Cookies are small values sent with web requests. Local storage stays in the browser until the application or the user removes it. Supabase and PostHog generate some names from the configured project, so the table uses patterns rather than exposing project identifiers.
2. Choice
Nutmeg applies the same strict choice globally. Necessary storage is used to deliver authentication, security, language and requested features. For public visitors and teachers, optional PostHog analytics is off unless “Accept analytics” is selected. Student and parent accounts never use PostHog analytics, regardless of any choice already stored in that browser. Declining is remembered. A teacher can change the choice in Settings; withdrawal stops future capture, resets the PostHog browser identity and analytics properties, and records an opt-out. The opt-out marker and a newly generated anonymous value may remain until the user clears site data.
3. Nutmeg and service storage
| Name or pattern | Provider/type | Purpose | Category | Duration |
|---|---|---|---|---|
| sb-<project-reference>-auth-token (including numbered chunks when required) | Supabase / cookie | Keep the signed-in session and refresh authentication | Necessary | Until sign-out, invalidation or the authentication session expires |
| locale | Nutmeg / cookie | Remember Polish or English | Preference necessary to provide the selected language | One year |
| nutmeg_invitation_auth | Nutmeg / secure HttpOnly cookie | Bind a one-time Google signup/invitation intent without exposing the secret to client code | Necessary | Up to one hour; cleared on completion/failure |
| gcal_oauth_state | Nutmeg / secure HttpOnly cookie | Prevent Google Calendar OAuth request forgery | Necessary for requested Calendar connection | 10 minutes; removed at callback |
| nutmeg.analytics-consent | Nutmeg / local storage | Remember grant or refusal so analytics stays off until granted and a refusal does not reprompt | Necessary to remember the privacy choice | Until changed by the user or browser data is cleared |
teacher-sidebar-collapsed, student-sidebar-collapsed; sidebar-collapsed may be read from older browser data | Nutmeg / local storage | Remember sidebar display | Preference | Role-specific keys: until changed or browser data is cleared. Older key: until browser data is cleared |
| nutmeg:practice-tools-pos | Nutmeg / local storage | Remember the position of practice tools | Preference | Until changed or browser data is cleared |
4. Optional PostHog analytics
For public visitors and teachers, and only when analytics consent is granted and PostHog analytics is available, the PostHog JavaScript SDK may store pseudonymous identifiers, consent state and settings under project-generated names such as ph_<project-key>_posthog or related PostHog entries. Nutmeg disables this SDK for student and parent accounts. The purpose is product-usage measurement. Nutmeg disables session replay, masks configured page text, removes invitation tokens and personal URL segments, and identifies a teacher account only with an opaque internal identifier, role and studio context. Exact entry names and browser expiry values can vary with the PostHog project and SDK configuration.
5. Security and third-party interactions
Cloudflare Turnstile receives browser, device and network signals when a protected form is used and may use strictly necessary browser mechanisms for challenge integrity. Google, Stripe sandbox, YouTube, Vimeo, Supabase Storage or bunny.net may use their own storage when the user starts their hosted or embedded function. A YouTube preview image may be requested before the user opens a player; the player itself loads when the related view or preview is opened. Those providers control their own storage under their notices.
Nutmeg serves its application fonts from its own site. Optional DiceBear avatar images are requested from the DiceBear API and may disclose ordinary request information such as the IP address and browser headers even if no cookie is set.
6. No advertising storage
Nutmeg does not use behavioural advertising, remarketing tags or cookies that sell or share personal information in the beta.
7. Browser controls and consequences
A user can remove or block storage through browser settings. Blocking necessary authentication/security storage may prevent sign-in, invitations, Calendar connection or other requested functions. Refusing optional analytics does not prevent use of Nutmeg.
8. Changes and contact
Version and effective date: 2026-09-13. Material changes will be communicated by email and/or in-app notice, as appropriate. Questions can be sent to hello@usenutmeg.com.