MatchLayer · Updated 2026-09-28
Cookies & device storage
This includes cookies, local storage and session storage. The app stores access and event state on your device. Hosting/security providers may process technical requests. No advertising pixels or remotely loaded fonts are present in the current source.
| Purpose | Storage and duration | Choice |
|---|---|---|
| Organizer authentication | Supabase sb-…-auth-token, until sign-out or browser clearing; server session validity is controlled separately. | Necessary for signed-in access. |
| Event identity and offline views | matchlayer:event:active-participant, profile, server-profile and gateway-snapshot. Saved until cleared; offline snapshots expire after 24 hours. | Remembers the event you opened. Use “Clear this event from this device” in event privacy controls on shared devices. |
| Event selection | matchlayer:user:selected-event-id, until cleared. | Remembers your selected organizer event. |
| Optional Pass | matchlayer:pass-token and pass-profile, until Pass deletion or browser clearing. | Explicit Pass action. Browser clearing does not delete the server identity. |
| Privacy choice | matchlayer:privacy-choice, version/date/choice valid for 180 days. | Remembers acceptance or refusal; choose again in the footer. |
| Optional analytics | Consented view-event queue, at most 200 entries; optional diagnostic-session ID lasts for the tab session. | Off by default. Withdrawal clears queued optional events and stops future sends. |
Reject and allow have equal prominence. Scrolling or using the site is not consent. Requested networking actions and minimal security logs still operate when analytics are rejected. Consented view events go to the event database; external PostHog diagnostics are sent only if configured. Advertising is not implemented.
Use “Privacy preferences” below to withdraw or change consent. Clearing site storage in your browser removes device access, so keep your invitation securely. Server-side erasure requires a separate request.