Skip to main content
← Crumble

Cookie policy

Last updated: 2026-07-23

This policy explains the cookies and similar local-storage entries Crumble sets in your browser. It complements our privacy policy.

What we set today

Every cookie in the table below is essential — it is there to sign you in, protect the sign-in against CSRF, or carry something you clicked (an invite, a share link, a QR code) across the sign-in round-trip. We set no advertising cookies, and there are no ad networks or advertising trackers on our pages.

We do measure how the app is used, but not with cookies. Our analytics is software we deploy and run ourselves — the data is not sold, shared, or handed to an advertising network. It stores nothing on your device, so it does not appear in the table below. It labels pageviews with your account so we can tell which features are actually used, and it is on by default: because it is cookieless first-party measurement we run it under our legitimate interest, and you can opt out at any time in the banner. See the privacy policy for the legal basis and how to object.

Name
Purpose
Duration
crumble_session
Keeps you signed in. HMAC-signed, HttpOnly, SameSite=Lax, Secure.
30 days, refreshed on use
oauth_state
One-shot CSRF guard for the Google OAuth sign-in handshake. Cleared the moment sign-in completes.
Until sign-in completes (max 10 min)
pending_ref
Holds an invite/referral code from a ?ref=… link so it survives the OAuth round-trip and is applied at onboarding. Cleared after it is claimed.
24 hours
crumble_consent
Stores your cookie preferences from the consent banner. Mirrored in localStorage.
1 year
crumble_ref
Set when you open a Crumble campaign link or scan one of our QR boards (a /r/… URL), so a sign-up later that week is still counted against the right board or link. It measures our own posters and links — it is not an advertising cookie and is never shared.
90 days, cleared once claimed
pending_signup
Holds an in-progress sign-up so you can finish onboarding after the Google round-trip.
30 minutes
pending_friend_invite
Set when you open someone's share link, so we can offer to connect you with them once you have an account. Cleared after it is applied.
7 days

We also use localStorage for in-app preferences (theme, last-seen tutorial) and for the consent record. localStorage is not transmitted to our servers.

Categories

  • Essential — required for the service to function (sign-in, CSRF, invite and campaign capture, your saved consent choice). Cannot be disabled. No consent is required under the ePrivacy Directive for strictly necessary cookies.
  • Analytics — usage measurement on analytics we deploy ourselves. Sets no cookies and stores nothing on your device, but it does label pageviews with your account. Because it is cookieless and first-party, it runs on by default under our legitimate interest; turn it off to opt out. Opting out also switches off the client error reports we use to find crashes.
  • Marketing — not used. We run no advertising and no ad networks. The toggle stays in the banner so that if this ever changes we have to ask you before it does.

Manage or revoke consent

You can change your cookie preferences at any time:

The button reopens the consent banner. To fully erase your consent record, clear cookies and localStorage for this site in your browser settings — the banner will appear again on your next visit.

Third-party services

When you use specific features, your browser contacts third parties directly:

  • Google during sign-in (OAuth consent screen), and only then.
  • Map tiles. The map is drawn from a Protomaps tile server we run ourselves. If it is unavailable your browser falls back to Protomaps' hosted tiles, and in the last resort to OpenStreetMap raster tiles; map fonts and icons load from Protomaps' public asset host.
  • Cloudflare Turnstile on the login page — a privacy-respecting CAPTCHA that replaces the usual tracking-based bot checks.

These third parties may set their own cookies on their own domains under their own policies. We do not control or read those cookies.

Contact

Questions about this policy: privacy [at] crumble [dot] me.

Privacy · Terms · Cookies · Security
Privacy · Terms · Cookies · Security · Businesses ·