Cookie Policy
How Purupuru Maker uses essential storage, analytics, optional services and advertising consent signals.
Last updated: 2026-07-19
Scope
This policy explains the browser storage and similar technologies used on Purupuru Maker. It supplements our Privacy Policy.
Regional Defaults
Purupuru Maker is hosted on Cloudflare Workers. For each request, the edge provides a country code and an EU-country signal. The application converts that information into a policy class and does not expose the country code to the browser.
- In the European Economic Area, the United Kingdom and Switzerland, Google-related storage starts denied and the privacy panel asks for a choice.
- If the edge cannot reliably identify the region, the same conservative denied default applies.
- In other recognized countries, Google Analytics storage starts granted under our current regional policy. A visitor can disable it at any time.
These operational defaults implement our present service policy. They are not a claim that a static country list is a complete statement of every law that may apply. We review the policy when the service, target markets or official provider requirements change.
Essential Storage
Essential storage is not controlled by the optional-service switches because it keeps the site secure and remembers choices.
| Name or category | Purpose | Typical duration |
| ----------------------------------- | -------------------------------------------------------------------------------------------------------- | --------------------------------------- |
| purupuru_consent_v2 | Saves separate choices for Google Analytics, Google One Tap and support chat | 180 days |
| PARAGLIDE_LOCALE | Remembers the selected site language | Browser/provider-configured duration |
| Authentication and security cookies | Maintains a signed-in session, protects authentication and prevents abuse when account features are used | Session or provider-configured duration |
| Theme/browser preferences | Remembers display choices on the device | Until changed or cleared |
Google Analytics and Consent Mode v2
When a valid GA4 Measurement ID is configured, the Google tag loads on every
page using Advanced Consent Mode. Before the tag loader, any config, or
any measurement event, the site sends a default state for all four signals:
analytics_storagead_storagead_user_dataad_personalization
In prior-consent and unknown regions, all four default to denied. The tag can
still send cookieless measurement signals for aggregate measurement and
modeling. Enabling Google Analytics sends a Consent Mode update for
analytics_storage; disabling it sends an update back to denied. In other
recognized regions, the four signals default to granted, except that a
browser Global Privacy Control signal forces advertising user data and
personalization to denied.
When analytics storage is granted, Google Analytics may set identifiers such
as _ga and _ga_*. Their exact lifetime follows the configured Google
Analytics property and Google's current implementation. We do not send names
or email addresses to GA4.
Plausible Analytics
When Plausible is configured, its standard cookieless script loads independently
of Google Analytics consent. It does not set cookies or use local storage for
visitor identification. Site-specific pa-*.js scripts are initialized with
plausible.init() and the loader is guarded so it is injected only once.
If Plausible is later configured with features that add storage or materially change its data use, this policy and the corresponding control will be updated before that configuration is published.
Google One Tap and Support Chat
Google One Tap has its own switch. It is loaded only when that switch is on, the visitor is signed out, and the operator has enabled and configured One Tap.
Support chat has a separate switch. Crisp or Tawk.to loads only when that switch is on and the corresponding provider is configured. Those providers may set their own cookies or storage after loading. Turning either service off causes a clean reload so previously injected widget code is not retained in the page.
Google AdSense
AdSense is not controlled by the site's Google Analytics, One Tap or support switches. Its script can load only when AdSense is enabled, the exact site has passed review and is marked Ready, a Google-certified CMP is published, and the current page is approved for ads. The site's Privacy choices panel is not a Google-certified CMP.
Where Google's EEA/UK/Switzerland publisher requirements apply, advertising choices and IAB TCF signals are collected by the published Google-certified CMP. Google and advertising vendors may then use cookies, web beacons, IP addresses or other identifiers according to that choice and their policies.
Change or Withdraw a Choice
Use Privacy choices at the bottom of the page to change Google Analytics, Google One Tap or support chat independently. You can also clear browser data. AdSense advertising choices are changed through the certified CMP when it is active, and Google ad personalization can also be managed in My Ad Center.
Questions can be sent to support@purupuru-maker.org.