1. Scope
This policy covers first-party web cookies, browser storage and mobile WebView storage used by Anthony Stilo. Provider websites opened in a new browser context set their own technologies under their policies.
Last updated: 12 August 2026
This inventory distinguishes necessary account and security storage from analytics or advertising, which the current version of the site and app does not include.
Last updated: 12 August 2026
Cookies are small browser values. The website and app can also use browser or device storage with similar practical effects. A final scan of the live website and published apps is still pending before this inventory is confirmed as complete.
This policy covers first-party web cookies, browser storage and mobile WebView storage used by Anthony Stilo. Provider websites opened in a new browser context set their own technologies under their policies.
A review dated 1 August 2026 found Supabase authentication storage, a route-specific Cloudflare Turnstile widget, and mobile local storage for language and a random per-install notification identifier. It found no advertising pixel or general-purpose analytics SDK. The live website configuration, provider dashboards and final published apps remain to be audited.
When account access is configured, Supabase SSR uses first-party browser-readable cookies for PKCE/session material and token refresh. They are marked Secure in production and SameSite=Lax in the current configuration. They are necessary to sign in, keep the requested session and protect authenticated routes; exact cookie names, lifetimes and logout behaviour will be confirmed against the live service.
The private-request page can load Cloudflare Turnstile when configured. The browser runs Cloudflare code and the server sends the resulting token and, where available, the request IP to Siteverify to distinguish legitimate submissions from abuse. Cloudflare may process browser, network and challenge signals. Whether a clearance cookie is enabled, and the contractual retention, are still being verified in the widget settings.
The mobile app stores the selected language and a random installation nonce locally. Supabase can also persist the app session on the device. The nonce supports registration or revocation of an optional push token; it is not presented as an advertising identifier. Clearing app data or uninstalling can remove local values but does not by itself delete server records.
No generic analytics, advertising SDK, ad display, cross-company tracking or profiling cookie is present in the current version. This is a scoped technical finding, not a permanent promise. If any non-essential analytics, personalisation or advertising technology is added, this policy, the consent interface and the store disclosures will be updated before it loads.
Necessary authentication and security storage does not use the same consent rule as optional tracking. If optional technology is introduced, it must remain blocked until a valid choice, offer reject and accept with comparable prominence, allow granular control, record the choice, and make withdrawal as easy as consent. Browser settings can delete or block storage, but doing so may break sign-in or the protected form.
Relevant observed services are Supabase and Cloudflare; Google or Apple may set storage when the user actively chooses their OAuth flow, and Booksy applies its own policy after an external click. OpenAI processes Concierge requests server-side and is not loaded as a browser cookie script in the current implementation. Supplier roles and retention remain subject to the approved register.
Inventory changes will be versioned. Questions, or a mismatch between this policy and what your browser shows, can be raised through the site assistant (/en/assistant) or the official Instagram account @anthonystilo. The full storage audit for this version is still pending.
Related information
See the full data-flow, supplier and retention explanation.