Cookie & Analytics Policy
Cloud Creator LLC · ozu.studio
This Cookie & Analytics Policy explains how Ozu ("Ozu," "we," "us") uses cookies and similar technologies when you visit ozu.studio and app.ozu.studio.
1. What Are Cookies
Cookies are small text files placed on your device by a website. They are widely used to make websites work more efficiently and to provide information to site operators. Some cookies are essential for the Service to function; others help us understand how you use the site.
2. Cookies We Use
2.1 Essential Cookies
These cookies are required for the Service to operate. They cannot be disabled without breaking core functionality.
- __pp_session — A first-party session identifier. It is not a Firebase ID token. It identifies your logged-in session with Ozu, expires when you sign out or after 14 days of inactivity, and is first-party, httpOnly, and secure.
- __cf_bm — Cloudflare bot management cookie. Used to distinguish humans from bots and protect against abuse. Expires after 30 minutes. Set by Cloudflare.
Firebase ID tokens are separate. Firebase Authentication issues a short-lived ID token (about 1 hour, auto-refreshed while you’re active). On the web, that token lives in your browser’s local storage, not as the __pp_session cookie. Both can be true at once: a short-lived Firebase token for API auth, and a longer-lived first-party session cookie as a session identifier. See Privacy Policy §2.2 and §7.
2.2 Functional Cookies
These cookies remember your preferences and settings to provide a better experience.
- pp_theme — Stores your dark/light mode preference. First-party. Persistent (1 year).
- pp_canvas_state — Stores canvas zoom level and position for the Director Review Board. First-party, session-scoped.
2.3 Analytics Cookies
Ozu does not use third-party advertising analytics or tracking pixels. No Google Analytics. No Meta Pixel. No ad trackers.
We collect anonymous, aggregated usage metrics through Cloudflare Web Analytics, which does not use cookies and does not track individuals across sites.
We may introduce privacy-respecting analytics in the future (e.g., Plausible, Fathom) and will update this policy accordingly.
3. Third-Party Cookies and related tech
The following third-party services may set cookies when you use Ozu on the web:
- Firebase Authentication (Google) — Sets cookies or similar storage for authentication state management. These are essential for sign-in functionality. See Section 2.1 on how this relates to
__pp_session. - Stripe — May set cookies during checkout and payment flows for fraud prevention. These are scoped to the payment process.
- Cloudflare — Sets security cookies for DDoS protection and bot management.
The native iPad app does not use browser cookies; it uses platform secure storage and Firebase Auth SDKs for session management.
Sentry is used for crash diagnostics on the iPad app. That is not a browser cookie, is not advertising, and is not used to track you across sites. See Privacy Policy §2.2.
4. Managing Cookies
You can control and manage cookies through your browser settings. Most browsers allow you to block or delete cookies. However, blocking essential cookies will prevent you from signing in and using core features of the Service.
Browser-specific instructions:
- Chrome: Settings > Privacy and security > Cookies and other site data
- Firefox: Settings > Privacy & Security > Cookies and Site Data
- Safari: Preferences > Privacy > Manage Website Data
- Edge: Settings > Cookies and site permissions
5. Do Not Track, and GPC
Ozu does not currently respond to Do Not Track (DNT) browser signals because there is no industry-standard implementation. However, our minimal cookie approach and absence of third-party advertising trackers already aligns with the intent of DNT.
Separately from DNT: we honor Global Privacy Control (GPC) as a Do Not Sell or Share request under the CCPA. That is a privacy-rights signal, not the same thing as DNT. See our Privacy Policy.
6. Changes to This Policy
We will update this policy if we introduce new cookies or analytics tools. Material changes will be communicated to registered users via email. Continued use of the Service after changes constitutes acceptance.
7. Contact
Cloud Creator LLC
c/o Northwest Registered Agent, 30 N Gould St, Ste N, Sheridan, WY 82801
[email protected]
Revised August 13, 2026: clarified that Firebase ID tokens (~1 hour) and __pp_session (up to 14 days) are different; noted Sentry is iPad crash diagnostics, not a cookie or ad tracker; kept Cloudflare Web Analytics cookieless and no ad pixels; explained that GPC is honored as a CCPA Do Not Sell/Share request and is not DNT; standardized the registered-agent address to Ste N.