Cookie Policy (Web Build) - CriApp
NOTICE: Reviewed by the internal legal audit (2026-05-02) and completed with the owner's details on 2026-08-20. Sign-off by counsel licensed in Peru (governing law) is recommended before a large-scale launch campaign.
Version: 2.0.0
Last updated: 2026-08-20
1. What are cookies and similar technologies?
Cookies are small files a website stores in your browser. Similar technologies include localStorage, sessionStorage, IndexedDB, web beacons, and fingerprinting.
CriApp Web uses:
- Strictly necessary cookies (no consent required under ePrivacy/GDPR).
- Functional cookies (remember language, theme).
CriApp v1.0 is 100% free and ad-free: we do NOT use advertising cookies, third-party analytics cookies, or any tracking technology beyond what is strictly necessary or functional. If this changes in a future version, we will notify you and request consent.
2. Cookie inventory
2.1 Strictly necessary
| Name | Origin | Purpose | Duration |
|---|---|---|---|
criapp_session | criapp.smarthuaraz.cloud | Maintain session | Session |
criapp_csrf | criapp.smarthuaraz.cloud | CSRF protection | Session |
better_auth.session_token | criapp.smarthuaraz.cloud | Auth (Better-Auth) | 7 days |
better_auth.refresh_token | criapp.smarthuaraz.cloud | Token refresh | 30 days |
2.2 Functional
| Name | Origin | Purpose | Duration |
|---|---|---|---|
criapp_lang | criapp.smarthuaraz.cloud | Language | 1 year |
criapp_theme | criapp.smarthuaraz.cloud | Theme (light/dark) | 1 year |
criapp_active_child | criapp.smarthuaraz.cloud | Selected child | 30 days |
2.3 Analytics
CriApp web does NOT use external analytics cookies (no Google Analytics, no Mixpanel). We use Sentry server-side for errors. Sentry Session Replay is NOT enabled (defense-in-depth: we do not record user interactions).
2.4 Advertising
CriApp v1.0 does NOT set advertising cookies of any kind. There is no third-party ad SDK on the web build.
3. Your consent
3.1 Strictly necessary + functional only
Because CriApp v1.0 only uses strictly necessary and functional cookies, no cookie consent banner is required under ePrivacy / GDPR for the cookies actually set. Functional cookies (language, theme) are set only after the user explicitly opts in via the relevant Settings.
3.2 Pre-consent default categories
- Necessary: ON (cannot disable; no consent required).
- Functional: OFF until the user makes a choice in Settings.
3.3 Geographic application
Same defaults worldwide. No advertising or analytics tracking is applied to any user, regardless of jurisdiction.
3.4 Do Not Track / Global Privacy Control
We respect GPC (Sec-GPC: 1). Because we do not sell or share data with third parties for advertising, GPC is honored by default for all users.
4. Third-party cookies
CriApp v1.0 does NOT set third-party cookies on the web build. Sentry runs server-side only and does not set browser cookies (Session Replay is disabled).
5. How to block cookies
- Browser settings: block/delete cookies.
- Incognito mode.
- CriApp banner: reject optional categories.
If you block strictly necessary cookies, parts of the Service may not work.
6. Your rights
Same rights as in the main Privacy Policy: access, rectification, erasure, objection. Contact: dpo@criapp.smarthuaraz.cloud.
7. Contact
privacy@criapp.smarthuaraz.cloud / dpo@criapp.smarthuaraz.cloud