Cookie Policy
Cookies, analytics, regional consent, and privacy controls used by Kavello
Last updated: 2026-09-15
Effective date: September 1, 2026
Last updated: September 15, 2026
This Cookie Policy explains how Kavello uses cookies and similar technologies on kavello.app. It should be read with our Privacy Policy.
1. What these technologies are
Cookies are small text files stored by your browser. Similar technologies include local storage, tags, scripts, pixels, and software that reads browser privacy signals. They can keep a session secure, remember a choice, or measure site use.
2. Your regional choices
We use approximate IP geolocation to determine which consent experience to show.
- In the EU/EEA, United Kingdom, Brazil, Quebec, China, Switzerland, and other regions that require or may require prior opt-in, optional analytics is disabled until you choose Accept All or enable Analytics in Preferences.
- In other regions, optional analytics may be available with an opt-out where lawful.
- If a region cannot be determined, we use the stricter prior-opt-in experience.
The controls are:
- Accept All: enables optional Analytics;
- Reject Optional: keeps only necessary technologies and cookie-free Plausible analytics; and
- Preferences: lets you switch optional Analytics on or off.
Your choice is stored locally in that browser for 6 months and is not automatically synchronized to your account or other devices. We may ask again sooner after a material change in vendors or purposes. You can reopen Cookie Preferences from the site footer.
3. Global Privacy Control
When Kavello detects a supported Global Privacy Control (GPC) signal, Google Analytics, Microsoft Clarity, advertising, marketing, and affiliate tracking remain disabled for that browser. Necessary technologies and cookie-free Plausible analytics remain enabled. GPC does not disable a technology needed to authenticate you, keep the Service secure, complete a payment, or remember your privacy choice.
4. Categories
Necessary
Necessary technologies operate the Service and cannot be disabled through Cookie Preferences. They may:
- maintain authentication and security sessions;
- support Google OAuth or Google One Tap, including security/state cookies such as
g_stateorg_csrf_tokenwhere used; - remember language through
NEXT_LOCALE; - remember your cookie choice;
- prevent fraud, abuse, duplicate submissions, or unauthorized access; and
- complete checkout and payment-provider security flows.
Their names and duration can vary by browser, authentication state, and provider. Session cookies normally end when the browser session or authentication session ends; preference and security cookies last only as long as needed for their stated purpose.
Analytics (optional)
With your consent where required, the Analytics switch enables:
- Google Analytics 4 (GA4): measures site and feature use using identifiers such as
_gaand_ga_*. Google may retain these browser identifiers for up to 2 years, while Kavello configures GA4 user/event retention to 14 months without resetting it on new activity. Google advertising features are not enabled by this choice. - Microsoft Clarity: provides public-page heatmaps and session diagnostics. Representative cookies may include
_clck,_clsk,CLID,ANONCHK,MR, andSM, with provider-set durations ranging from a session or minutes up to approximately one year. Kavello excludes generator, dashboard, history, settings, and checkout pages and masks inputs; prompts, uploads, outputs, emails, and payment details must not be recorded. - Kavello first-party event analytics: uses the HttpOnly cookie
kavello_analytics_visitor, lasting up to 30 days or the remaining permission period if shorter, for a random visitor identifier linked to your internal account after sign-in to measure the click, signup, generation and payment journey. Tab session storagekavello_analytics_pending_v1may hold up to 50 pending records from the last 24 hours for retry. Visitor and account identifiers are not sent to Plausible. Disabling Analytics or enabling GPC stops browser recording and identity linking and clears this cookie and pending queue. When the server receives the change, it also revokes the associated permission, preventing later optional outcome copies and pending delivery, including for asynchronous tasks. Event details are retained for 90 days, then deleted by scheduled cleanup; expired visitor associations are removed once no retained events need them. Necessary business records remain separate and are not deleted or disabled by this choice. Earlier optional details remain subject to retention and eligible access/deletion requests.
Rejecting or disabling Analytics prevents GA4 and Clarity from loading or sending cookieless pings. If you withdraw consent after they have run, Kavello should stop future analytics activity and remove accessible first-party analytics cookies where technically possible; provider-held data remains subject to lawful retention and deletion processes.
Cookie-free aggregate analytics
Plausible Analytics Cloud is configured to measure aggregate site traffic without cookies, persistent device identifiers, cross-site tracking, or behavioural advertising. It remains enabled after Reject Optional and under GPC. If the configuration changes so it is no longer cookie-free and aggregate, it must be reclassified and, where required, blocked until consent.
5. UTM and campaign attribution
Kavello may read a utm_source value from a landing-page URL to understand where a visit originated. A campaign-attribution cookie must follow the regional consent and GPC choice described above unless it is strictly necessary for a user-requested transaction. Kavello does not currently use this information for behavioural advertising.
6. Approved analytics events
Kavello limits analytics to events such as page view, completed sign-up/login, checkout started, purchase completed, subscription cancelled, and generation started/completed/failed. Permitted parameters are limited to non-sensitive operational fields such as route, plan, amount/currency, internal order reference, model, media type, duration bucket, credits spent, and standardized error category.
Third-party analytics must not receive prompts, names, email addresses, account identifiers, uploaded content, private or generated URLs, IP addresses or keyed IP values, provider transaction IDs, or full error messages. The first-party analytics described above links random visitor identifiers to internal account IDs only in the local database, without forwarding those identifiers.
Image-generation routes, including /ai-image/gpt-image-2.5 and /create, are excluded from Clarity. Prompt-template pages may use permitted public-page analytics, but generated or uploaded user content must not be recorded. Analytics page addresses omit query strings and fragments so prompt parameters are not included in page-location data.
7. Browser controls and consequences
You can also delete or block cookies through your browser. Blocking necessary cookies may prevent sign-in, language preferences, fraud protection, checkout, or other Service functions from working. Blocking optional Analytics does not prevent core generation features from operating.
Provider information is available from Google Analytics, Microsoft Clarity, and Plausible.
8. Changes and contact
We will update this Policy when technologies, purposes, or providers materially change and will request renewed consent where required.
Questions may be sent to support@kavello.app.
If the English Policy conflicts with a translation, the English version controls to the extent permitted by law. Mandatory rights under applicable law remain unaffected.