Cookie Policy
Version 1.1 — Effective June 19, 2026
This policy explains what cookies and browser storage TruChat uses, and how you can control them.
Cookie Declaration
Every cookie TruChat sets, what sets it, and how long it lasts. You can change your choices at any time with below.
| Name | Provider | Category | Duration | Purpose |
|---|---|---|---|---|
truchat_guest_id | TruChat | Strictly necessary | 24 hours | Identifies your guest session so your chats and username survive a page reload. Signed, so it cannot be forged. |
truchat_human | TruChat | Strictly necessary | 24 hours | Records that you passed the bot check, so you are not asked to repeat it. httpOnly and signed — scripts on the page cannot read or set it. |
truchat_guest_form_saved | TruChat | Strictly necessary | 1 year | A single flag noting that you saved your guest details, so the entry form can offer them back. Contains no personal data itself. |
truchat_admin_session | TruChat | Strictly necessary | 8 hours | Administrator sign-in session. Only ever set for TruChat staff accounts. |
cf_* / __cf_bm | Cloudflare (third party) | Strictly necessary | Up to 30 minutes | Set by Cloudflare Turnstile while verifying that a visitor is not a bot. Required for abuse prevention. |
_ga | Google Analytics (third party) | Analytics | 2 years | Distinguishes one visitor from another so we can count how many people use TruChat. Only set if you accept analytics. |
_ga_* | Google Analytics (third party) | Analytics | 2 years | Keeps session state for Google Analytics 4. Only set if you accept analytics. |
_gid | Google Analytics (third party) | Analytics | 24 hours | Distinguishes visitors within a single day. Only set if you accept analytics. |
Essential Cookies (Always Active)
These are required for TruChat to function and cannot be declined.
- Guest session cookie (
truchat_guest_id) — a signed, secure, HttpOnly cookie that identifies your guest session. Set by our server when you start a guest chat. - Auth session — Supabase authentication tokens (managed by the Supabase SDK, stored in browser local storage for web clients).
- Cookie consent preference (
truchat_consent_prefs) — remembers whether you accepted or declined analytics cookies.
Analytics Cookies (Optional — Requires Consent)
With your explicit consent, we use Google Analytics 4 to understand how TruChat is used. Google Analytics sets cookies (_ga, _gid, _ga_*) and processes data on servers in the United States. No demographic data (age, gender, country) is shared with Google Analytics.
You can withdraw analytics consent at any time with . You do not need to clear your cookies or wait for the banner to reappear.
Local Storage
TruChat stores the following items in your browser's local storage:
truchat_consent_prefs— Your cookie choices, so you are not asked again on every visit.truchat_device_id— A random identifier used to manage your active session and prevent duplicate connections. Not shared with third parties.truchat_fp— A hash of browser properties (screen size, timezone, language) that lets you reclaim your guest username if your cookie is lost. Sent only to TruChat’s own servers, and erased from our records when your guest session expires.truchat_guest_form— The username, age and location you entered as a guest, so you can reuse them.truchat_guest_last_login— When you last started a guest session, so the entry form can offer your details back.truchat-theme— Whether you chose light or dark mode.truchat-language— Your chosen interface language.truchat_notif_sound_enabled / truchat_notif_sound_volume— Your notification sound preference and volume.truchat_ad_popup / ad_history— Counts how many ads you have already been shown, so the frequency limits actually hold.truchat_keep_logged_in / truchat_last_activity— Keeps you signed in and powers the inactivity timeout.pwa-install-dismissed / app_version_sha— Remembers that you dismissed the install prompt, and which build you last loaded so stale caches can be cleared.truchat_room_* / truchat_last_read_*— The last 50 messages of each conversation you have open, plus how far you had read, so switching chats is instant instead of blank. Cleared when you log out or end a guest session.truchat_guest_session / truchat_guest_id— Your guest identity for this session, so a page reload does not lose your chats.truchat_blocked_user_ids— Who you have blocked, kept locally as well as on the server so blocks apply immediately.truchat_favourites / truchat_custom_rooms— Your favourited people and the rooms you created, cached for faster loading.truchat_guest_wallpaper— The chat wallpaper you picked as a guest.truchat_notif_push_enabled— Whether you turned on desktop notifications.tc_gif_ts— Timestamps of your recent GIF sends, used to enforce the per-hour GIF limit on your own device.arcade:* / arcade_tutorials_dismissed— Arcade state: sound and music settings, your energy pool, per-game best scores, and which how-to-play overlays you have dismissed.truchat_cookie_consent— A legacy copy of your analytics choice, kept in step with the categorised preference above so an older build reads the same answer.
Internal Analytics
We collect usage events (such as pages visited and features used) in our own database for product improvement. This does not involve third-party cookies and is not affected by your analytics cookie preference.
Your Choices
Change your consent at any time with , which is also linked in the footer of every page. You can additionally manage cookies through your browser settings — clearing them resets your consent preference, and clearing essential cookies will end your current session.
If your browser sends a Global Privacy Control signal, TruChat treats it as an objection to advertising consent and keeps that category switched off, whatever is stored locally.