Nutmeg

Nutmeg

Cookie Policy

Effective 2026-09-13 · Version 2026-09-13

1. Scope

This policy explains cookies and similar browser storage used by Nutmeg. Cookies are small values sent with web requests. Local storage stays in the browser until the application or the user removes it. Supabase and PostHog generate some names from the configured project, so the table uses patterns rather than exposing project identifiers.

2. Choice

Nutmeg applies the same strict choice globally. Necessary storage is used to deliver authentication, security, language and requested features. For public visitors and teachers, optional PostHog analytics is off unless “Accept analytics” is selected. Student and parent accounts never use PostHog analytics, regardless of any choice already stored in that browser. Declining is remembered. A teacher can change the choice in Settings; withdrawal stops future capture, resets the PostHog browser identity and analytics properties, and records an opt-out. The opt-out marker and a newly generated anonymous value may remain until the user clears site data.

3. Nutmeg and service storage

Name or patternProvider/typePurposeCategoryDuration
sb-<project-reference>-auth-token (including numbered chunks when required)Supabase / cookieKeep the signed-in session and refresh authenticationNecessaryUntil sign-out, invalidation or the authentication session expires
localeNutmeg / cookieRemember Polish or EnglishPreference necessary to provide the selected languageOne year
nutmeg_invitation_authNutmeg / secure HttpOnly cookieBind a one-time Google signup/invitation intent without exposing the secret to client codeNecessaryUp to one hour; cleared on completion/failure
gcal_oauth_stateNutmeg / secure HttpOnly cookiePrevent Google Calendar OAuth request forgeryNecessary for requested Calendar connection10 minutes; removed at callback
nutmeg.analytics-consentNutmeg / local storageRemember grant or refusal so analytics stays off until granted and a refusal does not repromptNecessary to remember the privacy choiceUntil changed by the user or browser data is cleared
teacher-sidebar-collapsed, student-sidebar-collapsed; sidebar-collapsed may be read from older browser dataNutmeg / local storageRemember sidebar displayPreferenceRole-specific keys: until changed or browser data is cleared. Older key: until browser data is cleared
nutmeg:practice-tools-posNutmeg / local storageRemember the position of practice toolsPreferenceUntil changed or browser data is cleared

4. Optional PostHog analytics

For public visitors and teachers, and only when analytics consent is granted and PostHog analytics is available, the PostHog JavaScript SDK may store pseudonymous identifiers, consent state and settings under project-generated names such as ph_<project-key>_posthog or related PostHog entries. Nutmeg disables this SDK for student and parent accounts. The purpose is product-usage measurement. Nutmeg disables session replay, masks configured page text, removes invitation tokens and personal URL segments, and identifies a teacher account only with an opaque internal identifier, role and studio context. Exact entry names and browser expiry values can vary with the PostHog project and SDK configuration.

5. Security and third-party interactions

Cloudflare Turnstile receives browser, device and network signals when a protected form is used and may use strictly necessary browser mechanisms for challenge integrity. Google, Stripe sandbox, YouTube, Vimeo, Supabase Storage or bunny.net may use their own storage when the user starts their hosted or embedded function. A YouTube preview image may be requested before the user opens a player; the player itself loads when the related view or preview is opened. Those providers control their own storage under their notices.

Nutmeg serves its application fonts from its own site. Optional DiceBear avatar images are requested from the DiceBear API and may disclose ordinary request information such as the IP address and browser headers even if no cookie is set.

6. No advertising storage

Nutmeg does not use behavioural advertising, remarketing tags or cookies that sell or share personal information in the beta.

7. Browser controls and consequences

A user can remove or block storage through browser settings. Blocking necessary authentication/security storage may prevent sign-in, invitations, Calendar connection or other requested functions. Refusing optional analytics does not prevent use of Nutmeg.

8. Changes and contact

Version and effective date: 2026-09-13. Material changes will be communicated by email and/or in-app notice, as appropriate. Questions can be sent to hello@usenutmeg.com.