⚠ Solicitor review pending. This page is published in good faith; treat it as best-effort, not legal advice. Email admin@echoversecollective.com if anything here is unclear or wrong.
Cookie Policy
This page lists every cookie and similar storage technology (including browser localStorage) used on echoversecollective.com. We use as few as possible. We do not sell your data, and we do not run advertising cookies.
Cookies we use
| Cookie / Provider | Type | Consent | Duration | Purpose |
|---|---|---|---|---|
evc_pass | Strictly necessary | Not required | Up to 1 year | Authenticates a logged-in reader. Without it, account-gated content cannot be served. Exempt under PECR reg 6(4). |
sb-* (Supabase) | Strictly necessary | Not required | While you stay signed in | Set when you sign in to a reader account: keeps your authenticated session with our auth provider (Supabase). Exempt under PECR reg 6(4). |
evc_reader_callback_nonce | Strictly necessary (security) | Not required | 10 minutes | Protects the sign-in flow against forged callbacks. Set only while you are signing in. |
evc_free_read | Strictly necessary (access control) | Not required | Up to 48 hours | Records which single dispatch you opened as a guest today, so the one-free-read-a-day meter works. Signed, and holds no browsing history beyond that one article. |
| Vercel (security) | Strictly necessary | Not required | Session | Hosting-platform protection: bot mitigation, DDoS, request integrity. Set by our infrastructure provider. |
| YouTube / Vimeo / Spotify (embeds) | Third-party media | Required (loaded on play) | Per provider | Set by embedded video and audio players when you press play. We use privacy-enhanced modes where supported. |
Our optional readership analytics (below) are cookieless: accepting them sets no cookie. If we add new cookies in the future (for example payment processing or additional embedded media), we will update this page and request consent before setting any non-essential cookie.
Local storage we use
Alongside cookies, we keep a small number of first-party keys in your browser’s localStorage. Each is set only by your own actions, is never transmitted automatically with requests, is never used for tracking, and can be removed at any time by clearing site data in your browser. The keys marked “Intelligence” are set only if you use the signed-in Intelligence reader surfaces.
| Key | Type | Consent | Duration | Purpose |
|---|---|---|---|---|
evc-analytics-consent | Consent record | Not required (records your choice) | Until you clear it | Records whether you accepted or declined first-party analytics, so we can honour your choice on every visit. Set only when you press Accept or Decline in the consent banner. |
ph_phc_* | Analytics session (optional) | Required (only set after you accept analytics) | Until cleared or the session ends | Remembers your analytics session between page views after you accept analytics. Never set before consent; removed when you decline. |
evc.personal.tour.v2 | Functional preference (Intelligence) | Not required (set only by your explicit action) | Until you clear it | Records that you closed the Intelligence feature tour, so it does not reopen on your next visit. |
evc.personal.articlechat.hint.v1 | Functional preference (Intelligence) | Not required (set only by your explicit action) | Until you clear it | Records that you dismissed the one-time article-chat hint, so it is not shown again. |
evc.personal.welcome-seen.v1:<code> | Functional preference (Intelligence) | Not required (interface state only) | Until you clear it | Records that the welcome animation on your dispatches page has already played, so it does not replay every time you return. A short scrambled code stands in for your account so a second reader on the same browser still gets their own welcome; it cannot be turned back into your name or email. |
onboard-draft-<session id> | Functional draft autosave (Intelligence) | Not required (holds only what you typed) | Until you submit (then removed) | Autosaves the answers you type during Intelligence text onboarding, so a page refresh does not lose them. The draft stays in your browser; your answers reach us only when you press submit. |
Session storage we use
Some surfaces also keep short-lived interface state in sessionStorage, a per-tab store your browser empties as soon as the tab closes. None of it is used for tracking or shared with third parties.
| Key | Where | Purpose |
|---|---|---|
evc.personal.tour.v3, evc.personal.tour.v3.routes, evc.personal.tour.v3.nav | Intelligence feature tour | Your progress through the tour and the routes it has visited, so an accidental reload resumes rather than restarts. |
evc-personal-agent-session:… (and the legacy evc-article-chat-session:…) | Intelligence chat | A random conversation id so a reload reconnects you to the same chat session. |
evc-nova-chat-transcript:<session id> | Intelligence chat onboarding | Keeps a copy of your interview conversation in the tab so a reload does not lose it. |
evc-welcome-typed, evc-onboard-transition-typed, evc-personal-profile-typed, evc-zero-feed-typed | Intelligence welcome & profile | Remembers that an intro animation already played in this tab, so it is not replayed. |
evc-subscribe-banner-dismissed | Dispatches feed | Remembers that you dismissed the subscribe banner for this tab. |
Analytics (optional, consent-based)
If, and only if, you accept analytics via the consent banner, your browser sends us anonymous usage events: the page you viewed, the link you clicked (address and short label), the referring page (address only, never query strings), a coarse browser type, a two-letter country code, and a pseudonymous visitor code. The visitor code is a one-way hash of your IP address and browser user-agent with a secret salt that changes every day, so signed-out visits cannot be linked to you across days (signed-in visits are linked to your account, as described below); your raw IP address and user-agent are never stored for analytics.
These events use no cookies. They are collected on our own domain (echoversecollective.com) and processed on our behalf by PostHog Inc. on servers in the EU, under a data-processing agreement: PostHog may not use your data for its own purposes, and we never sell it or share it with anyone for advertising. If you are signed in when you accept analytics, events are associated with your account so we can understand and improve your own product experience; signed-out visits stay pseudonymous. Analytics data is deleted after 30 days. Before you make a choice, no analytics events are sent at all. You can withdraw or change your choice at any time using the 'Privacy settings' link in the site footer; collection stops immediately.
Your choices
- Strictly necessary cookies are exempt from consent under regulation 6(4) of the Privacy and Electronic Communications (EC Directive) Regulations 2003. They cannot be disabled without breaking core functionality.
- Optional analytics run only after you accept them via our consent banner, and any future non-essential cookie will likewise be set only after you accept it. You can change or withdraw your choice at any time using the “Privacy settings” link in the site footer.
- You can also clear or block cookies in your browser settings. If you block strictly necessary cookies, login and paid features will not work.
- Embedded video and audio players (e.g. YouTube, Vimeo, Spotify) only set cookies when you press play. If you do not interact with an embedded player, no third-party cookie is set.
Changes to this policy
We will update this page when we add, remove, or change a cookie or storage key. Material changes will be flagged on the site footer for 30 days.
Contact
Questions about this policy: admin@echoversecollective.com.