Legal

Cookie Policy

Effective
<date>
Last updated
<date>

What this website and the app store on your device. The short version: this website sets no cookies at all, makes no third-party requests, and writes one item of browser storage, which you can clear yourself.

1. Cookies on this website

This website sets no cookies

Not a session cookie, not a preference cookie, not a consent cookie, and not an advertising one. There is nothing on this site to consent to, which is why you have not been asked and will not be.

That is possible because the website has no accounts on it. Signing in happens in the Android app, so the site has no session to remember, no personalisation to store, and no reason to keep anything in your browser across visits. What the site does — explaining the platform, serving the legal pages, showing an invitation, pointing at the download — needs no cookie to work.

The platform also does not run a consent-management tool. Those exist to collect a choice about non-essential cookies; with none to collect, adding one would be a dialog about nothing.

2. Browser storage, and the one item we write

Cookies are one way a site keeps something on your device; browser storage is another, and it is not covered by the word "cookie". This site uses exactly one item, and it is worth naming precisely:

NameWhat it holdsWhyEssential?
`globalrewards.referral.pending`A referral code — the same code that was already in the address of the page you opened.If you arrive through somebody’s invitation link and then go to the download page, the code would be lost when the page changed. This key carries it across so the download page can show it back to you, ready to enter when you create your account.No. The code is in the address bar either way, and everything on the site works without this key.

It is written only when an invitation link is opened and the code in it resolves. It holds the code and nothing else — no identifier, no history — and it is never read back to decide anything about you. The referral itself is recorded by the platform when an account is created, not by anything your browser stored.

There is no other storage on this site: no session storage, no IndexedDB, and no cache of your activity.

3. How to control it

Because nothing here is essential to the site working, you can remove it without breaking anything:

  • **Clear site data** in your browser’s settings and the item is gone. Every browser has this under its privacy or storage settings.
  • **Use a private browsing window** and it is discarded when you close the window.
  • **Do not visit the invitation page** and nothing is written at all — the key exists only to carry a referral code.

If you clear it, the consequence is only this: if you follow an invitation link and then move to the download page, the code may no longer be shown there. It is still in the address of the invitation page, and it can be entered by hand when you create your account.

4. Third-party requests

This website makes **no third-party requests**. That is unusually absolute, and it is checked rather than assumed:

  • No analytics service — not a self-hosted one and not a hosted one.
  • No advertising network, no tracking pixel, and no tag manager.
  • No social media plug-in, no embedded video, no map, and no chat widget.
  • No external fonts. The site uses the fonts already on your device, so not even a typeface is fetched from somebody else’s server.
  • No content delivery network for images or scripts: everything the page loads is served from this site.

One request does leave this site, and it is ours: when a page needs to check a referral code, the **website’s own server** asks the platform’s API. It happens between our servers, not from your browser, and no third party is involved.

5. What the app stores on your device

The Android app is where an account lives, so it stores more than the website does. It uses the device’s own secure storage — the Android Keystore — rather than ordinary preferences:

What is storedWhyEssential?
Your session: the sign-in tokens, the device identifier, and when the session expires.So you stay signed in between launches, and so the app can refresh the session without asking you for your password again.Yes. Without it you would sign in every time you opened the app.
A device identifier — a random value created the first time the app runs.So you can see where your account is signed in, and end a session you do not recognise.Yes. It is required before the first sign-in.
  • **No password is ever stored on the device**, in any form. Signing in exchanges it for tokens, and the password is not kept.
  • **The identifier is not a hardware identifier.** It is generated by the app, it is not derived from your device’s serial number or any advertising identifier, and deleting the app deletes it.
  • **Nothing is cached for advertising**, because there is no advertising in the app.
  • If secure storage is unavailable, the app falls back to keeping the session in memory only — so the device is not written to at all.

The app requests no runtime permissions: not location, not camera, not contacts, not access to your files. It asks only for the ability to reach the network, which is part of being an app that talks to a server.

6. The operator console

For completeness, because this policy is about storage rather than only about visitors: the internal console used by platform operators sets no cookies, and keeps its access token in memory rather than on disk, so closing the tab ends the session. It stores one preference — whether the operator prefers the light or dark interface — which is cosmetic and can be cleared at any time. The console is not reachable by the public and makes no third-party requests either.

7. If this changes

This document is short because the honest answer is short, and it will stay honest only if it changes at the moment the site does. If analytics, a consent tool, an embedded video or any other third-party script is ever added, this page changes in the same release — an appended clause in a later version would mean the site had been running something it had not disclosed.

The date at the top of this page is the version you are reading. Questions about it go to [CONTACT EMAIL].

Contact

Questions about this policy go to [CONTACT EMAIL]. The help centre answers questions about how the platform works, and the app itself is where an account is managed.

Related policies

Back to top