Website data
Cookies & Storage Notice
Effective and last updated 12 August 2026 · Version 2026-08-12
Erynva does not use advertising cookies. This notice identifies the website, security and sign-in technologies that may run in your browser.
1. Operator and scope
This notice applies to the Erynva website operated by Peter Stoney, a sole trader operating under the registered business name Erynva (ABN 42 423 397 171), based in Victoria, Australia. It should be read with the Privacy Policy. Contact support@erynva.com with questions.
2. Public website and Cloudflare
Erynva does not currently use behavioural advertising, cross-site marketing analytics or sale-of-data technologies. Cloudflare and the hosting platform process request information and may use strictly necessary cookies or similar storage to deliver pages and downloads, route traffic, mitigate bots and attacks, balance load and diagnose failures. Blocking these controls can prevent the site from loading correctly.
3. Google script on the sign-in page
When you open an Erynva sign-in page for the website account or desktop app, Erynva automatically loads the Google Identity Services script so the Google button can be displayed. This happens before you choose between Google and email sign-in. Loading the script sends Google ordinary connection and browser information such as your IP address, user agent, referring page and timestamp. Google may read or set cookies or use browser storage under its own policies.
If you choose the Google button, Google processes the interaction and supplies an identity credential to Erynva’s Supabase authentication service. If you choose email instead, Erynva does not intentionally use the Google credential, but the script-load request has already occurred. You can avoid Google Identity Services by not opening the browser sign-in flow and using Erynva without an account under the local free allowance.
4. Supabase authentication
Supabase processes the email-link or Google authentication request and uses necessary security state to complete sign-in. The browser-to-desktop hand-off uses a single-use code that expires after five minutes. Access and refresh tokens are not placed in a return URL. For website billing, Erynva stores the signed-in session only in that browser tab using sessionStorage; closing the tab clears it. Email-link sign-in temporarily stores a one-time PKCE verifier in same-origin localStorage so an emailed link can open safely in a new tab. Erynva deletes that verifier when the callback uses it, and rejects it after ten minutes. The installed app separately stores its long-lived refresh token using operating-system credential protection.
5. Stripe checkout and billing portal
If you open checkout or the customer portal, you leave Erynva’s account flow and enter a Stripe-hosted page. Stripe uses cookies and similar technologies for payment security, fraud prevention, checkout preferences and service operation under its own cookie and privacy information. Stripe’s storage is not used by Erynva for advertising.
6. Your controls
You can inspect, block or delete cookies and site data using browser settings. Blocking provider storage may prevent sign-in, checkout, billing or security features from working. Erynva currently has no non-essential analytics or advertising cookie category to opt into or out of.
If Erynva later adds non-essential analytics, advertising or other consent-based technology, it must not be enabled for affected users until this notice, the Privacy Policy and any legally required preference control have been updated.
