Cookie Policy
Effective: August 11, 2026
Version: 1.2
This Policy explains how Eveli, Inc. uses cookies, local storage, pixels, SDKs and similar device technologies on eveli.ai and related services.
1. Categories
Strictly necessary
Limited to technologies objectively necessary for a user-requested service or secure operation. Authentication, security, load balancing and consent storage may qualify; payment, anti-abuse and other technologies must be assessed individually rather than labeled necessary by provider or purpose alone. Necessary technologies cannot be switched off through the cookie tool.
Preferences
Remember optional interface, language or personalization choices. These remain off until consent where law requires.
Analytics
Measure use, errors and product performance. These remain off for EU/EEA and UK users until consent.
Marketing
Measure campaigns, create advertising audiences or track activity across services. These remain off until consent. EVELI does not condition Service access on marketing-cookie consent.
2. Your choices
The customer application reviewed on August 11, 2026 uses only product storage needed for sign-in, device identity, casting work and security. It does not contain optional analytics, advertising or marketing technology, so EVELI does not display a consent banner merely to ask permission for technologies it does not use.
If EVELI enables an optional technology, it will update the table below and, before activation where consent is required, provide equally accessible Reject non-essential, Manage choices and Accept all controls. Optional categories will remain off until the user chooses them. Browser blocking or clearing local storage may sign a user out or remove device-local casting work.
3. Live technology table
| Technology | Provider | Purpose | Category/legal basis | First/third party | Data | Duration |
|---|---|---|---|---|---|---|
\eveli_beta_session\ local storage | EVELI/Supabase authentication | Maintain the signed-in session and refresh it securely | Strictly necessary; requested service and security | First party | Access token, refresh token, account email and expiry | Until sign-out, token expiry or browser storage is cleared |
\eveli_casting_v2\ and legacy casting local storage | EVELI | Save device-local casting work and migrate earlier drafts | Strictly necessary for the requested save function | First party | Casting brief, choices, local project state and asset references | Until the user deletes/overwrites the work or clears browser storage |
\eveli_principal\ and \eveli_device_id\ local storage | EVELI | Maintain a stable device-scoped owner when verified production persistence is unavailable | Strictly necessary for record separation and continuity | First party | Random device identifier and cached principal state | Until browser storage is cleared or replaced by verified production identity |
| Cloudflare security technologies, only when a security challenge is triggered | Cloudflare, Inc. | Deliver the site, prevent abuse and protect requests | Strictly necessary security | Third party | IP address, request/device and security signals | Provider-configured, risk-based duration |
| Stripe Checkout and Billing Portal technologies, after the user chooses to purchase or manage a plan | Stripe | Secure payment, fraud prevention and subscription management on Stripe-hosted pages | Strictly necessary for the requested transaction | Third party | Transaction, browser/device and fraud-prevention data | Under Stripe's published policy and legal retention duties |
The table must include cookies, local storage, pixels, scripts, SDK identifiers and server-side events that rely on device data. Re-scan after every analytics, payment, authentication, anti-abuse, marketing or hosting change.
4. Consent records
No optional-cookie consent record is created while no optional technology is offered. If optional technology is introduced, EVELI will record the policy/version, selected categories, timestamp, region and interface language, and will make withdrawal as easy as acceptance. A policy update will not revive withdrawn consent.
5. Contact
Questions: legal@eveli.ai