The short version, because there isn't much to say: yamma doesn't use tracking or advertising cookies.
In short
One essential cookie, a handful of localStorage entries for UI preferences, and a cookieless analytics tool.
| Name | Type | Purpose |
|---|---|---|
| Supabase auth session | Cookie | Keeps you signed in. |
| yamma-theme / yamma-theme-mode | localStorage | Remembers your light/dark mode and colour theme before your account preferences load. |
| yamma-action-centre-intro-seen | localStorage | Remembers you've seen the first-run tooltip so it doesn't show again. |
| Dismissed nav alerts | localStorage | Remembers which alerts you've dismissed so they don't reappear. |
| Draft form inputs (e.g. the budgets grid) | localStorage | Protects unsaved input if you accidentally navigate away or lose connection. |
| Vercel Analytics | Cookieless | Aggregate, anonymised page-view counts. Doesn't set a cookie or identify you individually. |
Under UK PECR, a consent banner is only required for non-essential cookies. We don't set any, so there's nothing to ask permission for.
The Supabase session cookie is "strictly necessary" — required for you to be logged in at all — which UK cookie law (PECR) exempts from consent requirements. Every localStorage item above lives only on your device and is never read by our servers; it's not a cookie and isn't subject to PECR at all. If that ever changes — for example, if we add a genuinely optional analytics or marketing cookie in future — we'll add a proper consent banner before we do, not after.
Clearing cookies or site data in your browser will log you out and reset your local preferences — nothing more.
Because we set so little, there's not much to manage. Clearing your browser's cookies for yamma will simply sign you out; clearing site data will also reset your local theme preference and dismissed-alerts list until you sign back in.
Upgrading or managing a Pro subscription takes you to Stripe's own checkout and billing pages, which are subject to Stripe's cookie policy, not ours.
yamma doesn't embed any payment form or Stripe script directly on its own pages — upgrading to Pro or managing an existing subscription takes you to a page hosted directly by Stripe (Checkout, and the Customer Portal). While you're on those pages you're on Stripe's domain, not yamma's, and any cookies set there — Stripe uses some for fraud prevention and to process your payment — are governed by Stripe's own cookie policy, not this one. Once you're redirected back to yamma, this policy applies again as normal.
Questions about any of this, or want to exercise one of your data rights? Contact help@yamma.money.