Skip to content

Belovity Cookie Policy

Last Updated: September 6, 2026

Table of Contents

1. What This Covers

This policy covers cookies and similar technologies we use on the Belovity web application and progressive web app (the "Service") and on our website at belovity.com (the "Site"), including browser cookies, localStorage, sessionStorage, service-worker Cache Storage, and web push subscriptions. We treat all of these the same way for transparency. This statement is part of our Privacy Policy (https://belovity.com/privacy).

2. Our Approach

**Belovity does not show a cookie consent banner because we use no advertising cookies, no ad-tech, and no cross-site advertising profiling, and we do not sell data. We use cookies and storage in three categories — strictly necessary, functional, and analytics — plus a security technology from Google and payment technology from Stripe. Analytics begins when a page loads. We do not claim to have obtained your prior consent to analytics, and this statement describes the position accurately so you can make your own choices using the controls below.

3. The Cookies and Storage We Use

Strictly necessary

Name Set by Purpose Duration
belovity-session Belovity (first-party) Holds an encrypted session identifier; session contents live server-side. Maintains sign-in and request continuity. Secure, HttpOnly, SameSite=Lax. 2 weeks
XSRF-TOKEN Belovity (first-party) Cross-site request forgery protection; readable by our front-end code to echo back. Matches session lifetime
remember_web_... Belovity (first-party) Keeps you signed in across sessions. Always set at login; there is no "remember me" checkbox. 400 days

Functional

Name Set by Purpose Duration
isOpen Belovity (UI) Remembers sidebar state. Until you clear site data
isOpenDesktop Belovity (UI) Remembers desktop sidebar state. Until you clear site data
collapsedGroups Belovity (UI) Remembers collapsed navigation groups. Until you clear site data
theme Belovity (UI) Light/dark preference. Read on load but not currently written by the app (no theme switcher). If present, until cleared
pwa-installed Belovity Remembers the app was installed as a PWA. Until cleared
pwa-install-date Belovity Date the PWA was installed. Until cleared
pwa-banner-dismissed Belovity Records that you dismissed the install prompt. Until cleared
pwa-ios-instructions-dismissed Belovity Records dismissal of iOS install instructions. Until cleared
belovity-v1.0.0 (Cache Storage) Belovity Service-worker cache of app files for offline use; old versions removed on update. Until replaced or site data cleared
Web push subscription Belovity + your browser's push service A browser-issued push endpoint and encryption keys stored on our servers; a device-level identifier. Until you revoke the browser permission (see Your Choices), or until you delete your account, which deletes the stored subscription

Browser extension storage

These are stored by the Belovity browser extension inside your browser's extension storage, not as website cookies. They exist only if you install the extension and connect it to your account. You may have up to five connected browsers at a time; connecting a sixth ends the oldest connection.

Name Set by Purpose Duration
Extension access token Belovity A short-lived credential the extension sends with each request so our API knows the request is yours. Held in the extension's in-memory session storage. 15 minutes; discarded when the browser closes
Extension refresh token Belovity A single-use credential the extension exchanges for a new access token. It is replaced on every use, and reuse of an old one disconnects the extension (a few seconds' allowance exists so a dropped network response does not disconnect you). Held in the extension's local storage. Until used, or until the connection reaches its 30-day limit
Selected family and gift list Belovity Remembers which family and gift list you last added an item to, so you do not have to pick again. Held in the extension's local storage. Until you disconnect the extension or clear extension data

Analytics (PostHog)

Name Set by Purpose Duration
ph_<project-token>_posthog (cookie) PostHog (first-party cookie, proxied via a Belovity subdomain) Stores the analytics distinct_id, device ID, session ID, and initial referrer/UTM. Written at the registrable-domain level and shared across subdomains. 365 days
ph_<project-token>_posthog (localStorage) PostHog Same identifiers persisted in localStorage. Until you clear site data
ph_<project-token>_window_id PostHog Per-window/tab identifier. sessionStorage; cleared when the tab closes
ph_<project-token>_primary_window_exists PostHog Tracks which tab is primary. sessionStorage; cleared when the tab closes

These apply on the Service. On the Site, analytics runs in cookieless mode: no analytics cookie and no localStorage identifier are written, and no session replay runs there.

Security (Google)

Name Set by Purpose Duration
_GRECAPTCHA and associated Google cookies Google (third-party) Bot and abuse detection on sign-in, sign-up, admin-invite, and invitation pages, and on the contact form at belovity.com/contact. Set on Google's domains; we do not control them. Per Google's disclosures

Payments (Stripe)

Name Set by Purpose Duration
Stripe cookies Stripe (third-party) Set on Stripe's own domains (checkout.stripe.com, billing.stripe.com) when you are redirected there to subscribe or to manage your subscription. Used by Stripe for payment processing and fraud detection. We do not control them; see Stripe's privacy policy at https://stripe.com/privacy. Per Stripe's disclosures
js.stripe.com script on the payment-confirmation page Stripe (third-party) Belovity's own pages do not load any Stripe code. The one exception is a payment-confirmation page used when your bank requires extra authentication (3-D Secure); Stripe redirects you there, and it loads Stripe's script so the confirmation can complete. Duration of that page

4. Third-Party Technologies

  • PostHog Inc. (United States) provides our analytics, including autocapture (automatic recording of clicks and inputs) and session replay, which records and lets us replay your interactions with pages to debug and improve the product. Although analytics requests appear to come from a Belovity subdomain, the recipient of the analytics data is PostHog Inc. in the United States. On the Site, analytics runs in cookieless mode and session replay is not enabled. We route analytics through a Belovity subdomain (a reverse proxy) so that analytics continues to work when ad-blockers would otherwise block it; we disclose this openly here.
  • Google reCAPTCHA loads on authentication and invitation pages, and on the Site’s contact form, to detect bots and abuse. Its request to Google occurs on every load of those pages.
  • Stripe processes subscription payments. When you subscribe or manage a subscription you are taken to a page hosted by Stripe, where Stripe's own cookies and fraud-detection signals apply. Card details are entered on Stripe's pages; Belovity's own pages never load Stripe code, except on the bank-authentication (3-D Secure) confirmation page described above.
  • Public script CDNs (jsDelivr, and cdn.tailwindcss.com on the installable app's offline pages) serve certain scripts on Gift List and offline pages. They receive your IP address and User-Agent but set no cookies.

5. Cross-Site Behavior

Our session cookie is configured SameSite=Lax, so it is not transmitted to Belovity from other websites' pages.

The Belovity browser extension does not use your session cookie at all. When you choose to connect it from the Browser extension connections page in your account, we issue the extension its own short-lived token, and the extension sends that token to our API. You can disconnect the extension at any time from that page, which immediately stops it from working.

6. What We Do Not Use

We do not use advertising cookies, ad-network or social-media pixels, cross-site behavioral advertising profiles, or data selling. We do not use any third-party font service (no Google Fonts or similar); country-flag images are served locally. We do not store card numbers, and we do not run any payment or card-fingerprinting script on our own pages.

7. Your Choices

  • Browser controls: you can block or delete cookies in your browser settings. In Chrome, Safari, Firefox, and Edge, look under Settings > Privacy. Note that blocking strictly-necessary cookies will break sign-in.
  • Clearing storage: you can clear localStorage, sessionStorage, and site data through your browser's site-settings or "clear browsing data" tools. Extension storage is separate: clearing browsing data does not clear it, and removing the extension does.
  • Browser extension: open the Browser extension connections page in Belovity to see which browsers you have connected and to disconnect any of them. Disconnecting takes effect immediately, and an unused connection expires on its own within 30 days.
  • Analytics opt-out: PostHog honors browser-level controls; clearing site data removes its identifiers, and privacy-focused browsers and extensions can block analytics requests.
  • Global Privacy Control (GPC): we do not sell or share personal information or run advertising, so there is no sale/targeted-advertising activity for a GPC signal to stop; we do not currently operate a mechanism that detects GPC.
  • Web push: turn off the push toggles in the app, and to fully stop push, revoke the site's notification permission in your browser settings. Deleting your account deletes the push subscription record stored on our servers.
  • Payments: Stripe's cookies are set on Stripe's own pages when you subscribe or manage a subscription. You control them through your browser, and through any controls Stripe offers on those pages; blocking them may prevent payment from completing.
  • Removing the PWA: uninstalling the installed app and clearing site data removes the service-worker cache from your device.

8. Do Not Track

Some browsers send a "Do Not Track" signal. There is no common industry standard for responding to it, and the Service does not respond to Do Not Track signals.

9. Changes and Contact

We may update this Cookie Policy and will post the updated version with a new "Last Updated" date.
Questions: alex@belovity.com, 8735 Dunwoody Place, Suite R, Atlanta, GA 30350, USA.

Belovity
© 2026 Belovity LLC. All rights reserved.