Cookies & Storage
Last updated: 27 July 2026
The short version
Plot does not use advertising cookies, ad pixels or third-party analytics identifiers. After sign-in, one essential HttpOnly session cookie keeps the account authenticated. Local device storage supports preferences, continuity and offline use. The 'Got it' button acknowledges this notice; it is not consent to advertising or optional tracking.
Essential session cookie
plot_session — keeps you signed in. It contains a signed session token, is unavailable to page JavaScript because it is HttpOnly, uses SameSite=Lax, is Secure in production and lasts for up to 7 days after the latest active session. It is cleared on logout or account deletion.
Other storage on your device
localStorage — requested theme and interface preferences, dismissed notices, a non-secret signed-in marker, a marker that the landing intro has already played, and cached account/trip state for stable reloads and offline continuity.
IndexedDB — queued trip changes made while offline, removed after successful synchronisation or logout.
Cache Storage — the installable app shell and static assets needed to load the PWA reliably.
sessionStorage — temporary guest, navigation and game state.
Web Push — if you grant notification permission, the browser creates a push subscription that Plot stores on the server until you unsubscribe, the subscription expires, or the account is deleted.
Product measurement — no analytics identifier is persisted on the device. A random page-memory identifier disappears when the page reloads or closes.
Why there is no Accept/Reject wall
Plot's own cookie and local storage are used to authenticate you, remember choices you make, prevent repeated functional notices, synchronise offline work and provide the service you request. They are not used for advertising or tracking across websites. The notice is informational rather than a consent request. If Plot later introduces optional analytics, advertising or other non-essential storage, it must remain off until a separate valid choice is obtained.
Third parties
Proxied place-search and weather requests go from Plot's server to Google. The interactive Google map loads directly in your browser, so Google receives end-user data directly and may use functional browser storage under its own terms. If Google sign-in is configured, Google's sign-in script loads when the sign-in form displays so its official button can be rendered. Apple's sign-in script loads only after you choose Apple. Plot does not embed third-party advertising trackers.
Clearing storage
Logging out clears the plot_session cookie, cached account/trip state and queued offline writes. Some device preferences and dismissal choices remain so the interface behaves as requested. Clear Plot's site data in your browser to remove all cookies, localStorage, sessionStorage, IndexedDB and Cache Storage for the site.
Contact
privacy@acronym.sk