1. Scope
This document is a draft for founder and legal review. It is not legal advice and does not create a commitment until approved and published.
This draft describes browser storage observed in the repository. Browser behavior may change as authentication and analytics integrations evolve.
2. Essential cookies
The frontend references bavio_auth and bavio_onboarding_completed cookies for authentication and onboarding routing. Blocking them may interrupt routing or session behavior.
3. Local and session storage
localStorage is used for Bavio token/client/display state, authentication messages, and theme preference. sessionStorage is used for selected country context. Clearing storage can end a local browser session or remove preferences.
4. Analytics and marketing
This audit did not establish Google Analytics, Meta Pixel, advertising cookies, or a consent-management vendor. Do not assume analytics or marketing cookies are active unless the implementation and notice are updated.
5. Authentication providers
Supabase authentication client behavior may create additional session storage depending on the runtime configuration. Confirm production cookie names and attributes before publication.
6. Browser choices
Browser settings can block or clear cookies and storage. This does not delete server-side account, Conversation, Lead, billing, or provider data.
7. Changes
Cookie classification, consent requirements, retention, and names should be reviewed when authentication or analytics changes.
8. Contact
Privacy requests: [PRIVACY_EMAIL]. Support: hello@bavio.in.
