Cookie and browser-storage policy
Last updated: September 2026
Who operates this site
WOW-TERRE, S.L. (NIF B55305254, EU VAT ESB55305254) operates OmniClass at C/ Falguera 19/A, Aiguaviva Park, 17411 Vidreres, Girona, España. Privacy questions: hola@spainaura.es.
Cookies and similar storage
This policy describes HTTP cookies, localStorage, and Cache API storage used by omniclass.io and the OmniClass web app. We use technically correct terms: not every item below is a cookie.
Necessary and functional storage
Some storage is required for sign-in, security, language, appearance, offline availability, and product preferences. It works whether or not you allow analytics. Rejecting analytics does not disable these features.
Optional analytics storage
Google Analytics 4 (GA4) loads only after you choose Allow analytics and only when NEXT_PUBLIC_GA_MEASUREMENT_ID is configured in the deployment. We use Google Basic Consent Mode: no Google Analytics request runs before explicit permission, and advertising storage, advertising user data, and ad personalization remain denied. Google signals and ad personalization signals are disabled in our GA4 config. Page views send the path only (no query strings). Authenticated learning routes are excluded by an application allowlist. We do not intentionally send user ID, email, role, school, name, AI content, or other account attributes to GA4. GA4 processes usage and device information under your consent; it is not fully anonymous.
Storage inventory
The table lists storage we use today. Cookie and key names are shown exactly as in the product.
| Name / key | Mechanism | Purpose | Provider | Duration | Category | Consent |
|---|---|---|---|---|---|---|
| omniclass_locale | HTTP cookie | Stores your selected interface language (en, es, hu). | WOW-TERRE, S.L. (OmniClass) | 1 year (max-age in application code) | Necessary / functional preference | No analytics consent required |
| sb-<project-ref>-auth-token (and sb-<project-ref>-auth-token.0, .1, … when chunked) | HTTP cookie | Maintains Supabase authentication session and refresh. | Supabase | Up to 400 days cookie max-age per @supabase/ssr 0.12.3 defaults; session tokens inside may refresh while you use the site. Browsers may apply shorter limits. | Strictly necessary (authentication) | No analytics consent required |
| omniclass.cookieConsent | localStorage | Stores your analytics choice: version, analytics boolean, decidedAt timestamp. | OmniClass | Until you change your choice, the policy version changes, or you clear site data | Functional (privacy preference record) | Records your choice only; does not enable analytics when rejected |
| theme | localStorage | Stores light, dark, or system appearance preference. | OmniClass | Until changed or site data is cleared | Requested functional preference | No analytics consent required |
| omniclass_pwa_install_dismissed | localStorage | Remembers that the install prompt was dismissed. | OmniClass | Until site data is cleared or implementation changes | Functional preference | No analytics consent required |
| omniclass-v2-shell | Cache API (service worker) | Offline shell and static assets for PWA availability. Older omniclass-* cache versions are removed on service worker activation when applicable. | OmniClass | Until cache version update, service worker cleanup, or browser deletion | Technical storage | No analytics consent required |
| omniclass.rememberMe; omniclass.dashboard.layout.v1; omniclass.student.calendar.v1; omniclass.studyTimer.v1; omniclass.pets.equippedId | localStorage | Authenticated product preferences: login remember-me toggle, dashboard layout, student calendar entries, study timer state, equipped pet selection. | OmniClass | Until changed or site data is cleared | Functional product preference | No analytics consent required |
| omniclass.brainLab.audioMuted | localStorage | Brain Turbo sound effects mute preference (defaults to muted). | OmniClass | Until changed or site data is cleared | Functional product preference | No analytics consent required |
| Patterns such as omniclass.wordMatching.*, omniclass.faceDecoder.*, omniclass.dualNBack.*, omniclass.echoGrid.tutorialSeen.v1, omniclass.snapSort.*, omniclass.choiceUnderFire.*, omniclass.memoryHeist.*, omniclass.inventIt.*, omniclass.rippleLab.*, omniclass.patternPulse.*, omniclass.mindSwitch.* | localStorage | Brain Turbo rotation, tutorial flags, and local game-state helpers to vary content for guest and signed-in play. | OmniClass | Until changed or site data is cleared | Functional product storage | No analytics consent required; not Google Analytics |
| omniclass_manga_active_target_lang_v5; omniclass_manga_progress_{target}_{source}_v5 | localStorage | Language Story guest progress and active target language selection. | OmniClass | Until changed or site data is cleared | Functional product storage | No analytics consent required |
| _ga | HTTP cookie (after consent) | Google Analytics 4 distinguishes visitors on approved public and auth-funnel pages. | Google Analytics / Google Ireland Limited | 2 years by Google default; browsers may apply shorter limits | Optional analytics | Required; loaded only after Allow analytics |
| _ga_<measurement-id> | HTTP cookie (after consent) | GA4 session state for the configured measurement ID. | Google Analytics / Google Ireland Limited | 2 years by Google default; browsers may apply shorter limits | Optional analytics | Required; loaded only after Allow analytics |
Consent and withdrawal
Analytics is optional. Necessary and requested functional storage remains available when analytics is rejected. Reopen this dialog anytime with Cookie settings (also linked in the site footer). You can allow or reject analytics later. Withdrawing analytics consent removes first-party _ga* cookies through the application cleanup and stops further GA4 loading until you allow analytics again. Changing consent is as accessible as granting it. You can also clear site data in your browser settings.
Browser-level deletion
Your browser lets you delete cookies, localStorage, and cached data for omniclass.io. Clearing site data removes preferences such as theme, consent record, and local learning progress stored on this device.
Children under 14
OmniClass is youth-focused. If you are under 14, ask a parent or guardian to choose whether analytics is allowed. They can use Cookie settings to review or change the choice later.
Third-party providers
Supabase processes authentication cookies as our auth provider. Google Analytics / Google Ireland Limited provides optional GA4 measurement after consent. Google Search Console ownership verification and indexing are not part of this storage inventory. Search Console is not configured in this application codebase.
Policy updates
We may update this policy when storage or analytics behavior changes. The last-updated date at the top reflects the current version. A new cookie-policy version may reset the consent prompt when implemented.
Contact
Questions about cookies or browser storage: hola@spainaura.es