Cookie Policy

Last updated April 21, 2026

This Cookie Policy explains how 15064121 Canada Inc., doing business as CoCo Parenting AI ("CoCo", "we", "us"), uses cookies, local storage, IndexedDB, and similar technologies (together, "cookies") on our website and apps (the "Service"). Read this alongside our Privacy Policy.

1. What are cookies?

Cookies are small data files placed on your device when you visit a website. They let the site remember things (like whether you’re signed in), measure performance, and (on some sites) track behavior across sites. We also use local storage and IndexedDB, which work similarly but can store more data on your device.

Cookies set by CoCo are "first-party" cookies. Cookies set by partners we use to deliver parts of the Service are "third-party" cookies — these are limited to the vendors listed in Section 4.

2. Our approach — minimal, consent-aware, no ad tracking

  • We use cookies to keep you signed in, remember your preferences, prevent abuse, and understand product usage in aggregate.
  • We do not use advertising or cross-site tracking cookies.
  • We do not sell or "share" your information for cross-context behavioural advertising (as defined by CCPA/CPRA).
  • In the EEA, UK, and Quebec (under Law 25), we show a consent banner on first visit. Non-essential cookies are off until you consent.
  • We respect browser-level Global Privacy Control (GPC) signals and treat them as an opt-out for non-essential cookies.

3. Categories we use

NameTypePurposeDuration
firebase:authUser:*EssentialKeeps you signed in via Firebase AuthenticationUntil sign-out or 30 days
coco_sessionEssentialShort-lived session ID used by our API layerSession
coco_cookie_consentEssentialRemembers your cookie preferences (where a banner applies)12 months
coco_preferencesFunctionalRemembers UI preferences (language, theme, last stage viewed)12 months
__stripe_mid / __stripe_sidEssentialStripe fraud prevention on checkout pagesUp to 1 year / Session
sentry-sidFunctionalCorrelates error events so we can fix bugs affecting your sessionSession
IndexedDB: firestore-*FunctionalOffline cache of your own Firestore data (read/write resilience)Until you clear site data

4. Third-party cookies and storage

Some third-party providers may set cookies when you use their features in our Service:

  • Google / Firebase — authentication tokens, session management. See Firebase privacy.
  • Stripe — fraud-prevention cookies on checkout pages. See Stripe’s cookie policy.
  • Vercel — hosting and delivery; may set a small anti-bot cookie.
  • Sentry — minimal error-tracking session id (no cross-site tracking).

A full and current list of vendors is on our Subprocessors page.

5. How long cookies last

  • Session cookies are deleted when you close the browser.
  • Persistent cookies remain until their expiry (shown in Section 3) or until you clear them.
  • Local storage / IndexedDB remains until you clear site data or uninstall the app.

6. How to control cookies

In CoCo

  • On first visit from the EEA, UK, or Quebec, use the Cookie settings banner to accept or reject non-essential cookies.
  • Anywhere else, open Profile Settings → Privacy → Cookie preferences at any time to change your choices.
  • Sending a GPC signal automatically opts you out of non-essential cookies.

In your browser

  • Chrome: Settings → Privacy and security → Cookies and other site data
  • Firefox: Settings → Privacy & Security → Cookies and Site Data
  • Safari: Preferences → Privacy → Cookies and website data
  • Edge: Settings → Cookies and site permissions → Cookies and site data

Blocking essential cookies will sign you out and break core features. Blocking non-essential cookies only disables analytics.

7. Mobile apps

Our mobile apps do not use browser cookies, but they use equivalent on-device storage for your sign-in token, preferences, and offline cache. You can clear this by signing out, deleting the app, or using iOS/Android’s "Clear app data" option.

8. Do Not Track and Global Privacy Control

Industry has not adopted a consistent response to legacy Do Not Track signals, so we do not use DNT. We do respect the Global Privacy Control (GPC) signal as a valid opt-out for users in jurisdictions that recognize it (California, Colorado, Connecticut, and others).

9. Changes

We may update this Cookie Policy. The date at the top shows when it was last updated. Material changes are announced in the app or by email.

10. Contact

Questions about cookies? Email support@cocoparentingai.com with the subject line "Cookies".

Related policies: Privacy Policy · Terms · Subprocessors