Cookie Policy
Effective September 27, 2026
This page lists every cookie creavu sets, what it is for, and how to change your choice. The controller is Michal Schneedorfer, company ID (IČO) 19667302; the full picture is in the privacy policy.
The Czech wording is binding. This English text is a courtesy translation.
This is a working draft written to describe precisely what the product does. It has not yet been reviewed by a lawyer qualified in Czech and EU law.
Strictly necessary
The site does not work without these. They are not optional and we do not ask before setting them; the Electronic Communications Act (Section 89(3)) does not require it for cookies without which the service you asked for cannot be provided.
| Cookie | What it is for | How long |
|---|---|---|
better-auth.session_token | Keeps you signed in, after a Google sign-in and after a code sign-in alike. | Until expiry or sign-out |
better-auth.session_data | A short-lived copy of the session so every page load does not hit the database. | 5 minutes |
creavu.locale | Remembers the language you chose. | 400 days |
creavu.theme | Remembers the appearance you chose (light, dark, system). | 400 days |
creavu.pending_intent | Remembers what you were about to do before being sent to sign in, so you land back there. Signed and readable only by our server. | 15 minutes |
creavu.consent | Remembers the choice you made on this page. Paradoxically necessary: without it we would have to ask on every visit. | 180 days |
sidebar_state | Remembers whether you collapsed the sidebar in the app. Only after signing in. | 7 days |
Payment
On checkout pages a Stripe script runs to process the card payment. Stripe sets its own cookies there (__stripe_mid, __stripe_sid) to detect fraudulent payments. Payment cannot go through without them, so they count as strictly necessary; the controller for that data is Stripe under its policy. Outside the checkout the Stripe script is not loaded.
Analytics, only with your consent
| Cookie | What it is for | How long |
|---|---|---|
ph_*_posthog | Your browser's identifier in PostHog, so repeat visits can be recognised as the same usage. | 1 year |
Until you consent, nothing analytical is set. If you decline, the PostHog script stays off and no analytics event and no error report leaves your browser. The site works exactly the same either way; nothing is hidden behind consent.
We serve PostHog through our own domain (/ingest) so a tracker blocker does not silently break the site. The requests therefore look like our own, but the data goes to PostHog. What it receives is described in the privacy policy.
Two things are not analytics and happen regardless of your choice, and without cookies:
- Errors on the server. When something breaks on our server, the error is reported so we can fix it. It contains neither your email address nor form contents.
- Messages you send us. Feedback and store reports are stored on our server and reach PostHog regardless of your choice, because they are messages you knowingly sent, not tracking. Your email address is never attached to them.
What we don't do
No advertising cookies. No third-party trackers embedded in our pages. No tracking pixels in emails. We hand your browsing to no one for marketing. We do not sell data.
Changing your choice
Use the Cookie settings link in the footer of any page. Declining is one click and exactly as easy as accepting. When you withdraw consent, analytics switches off and the browser identifier is deleted.
Your choice lasts six months, then we ask again, following the recommendation of the Office for Personal Data Protection. You can also delete cookies in your browser, which brings the question back.