Cookie Policy
Last updated: 2026-07-25
1. What we use, by category
Our consent banner (CookieConsent v3, self-hosted) groups everything into three categories. Here is the complete inventory — cookies and browser storage, because storage deserves the same transparency:
Strictly necessary
Always on. Required for the site and the web player to function.
| Name | Type | Purpose |
|---|---|---|
| cc_cookie | Cookie (first-party, 6 months) | Stores your consent choice so we do not re-prompt on every page |
| iv_auth | localStorage | Keeps you signed in to the web player |
| iv_player_snapshot | localStorage | Remembers your playback position so the player resumes where you stopped |
| iv_progress_queue | localStorage | Queues listening progress while you are offline, syncs when you reconnect |
| iconicVoicesLeads | localStorage | Fallback copy of a notify-me email you submitted, kept in your browser if the network submission fails |
| ivBannerDismissed | sessionStorage | Remembers that you closed an in-page banner during this visit |
| iv_utm | sessionStorage | The utm_* values from the link you arrived on, so we can tell which campaign a signup came from. Tab-scoped — it disappears when you close the tab |
| Cloudflare Turnstile | Cookie / script (challenges.cloudflare.com) | Bot protection on the sign-up and password-reset forms only |
Analytics
| Name | Status | Purpose |
|---|---|---|
| Plausible Analytics | Active (cookieless) | Anonymous aggregate page-view counts. Sets no cookies, stores no personal data, does no cross-site tracking — which is why it runs regardless of the Analytics toggle; the toggle still controls the Consent Mode signal |
Google Analytics 4 (_ga) | Configured, currently disabled | Would load only after Analytics consent, with IP anonymization |
| Microsoft Clarity | Configured, currently disabled | Would load only after Analytics consent |
Marketing
| Name | Status | Purpose |
|---|---|---|
Meta Pixel (_fbp) | Consent-gated; loads only after you grant Marketing | Ad measurement; communicates with connect.facebook.net |
TikTok Pixel (_ttp) | Consent-gated; loads only after you grant Marketing | Ad measurement; communicates with analytics.tiktok.com |
| iv_em | localStorage; written only with Marketing consent | A hashed (never plaintext) copy of an email you submitted, used for ad-platform matching |
| iv_attrib_first, iv_attrib_last | localStorage; written only with Marketing consent | The campaign parameters of the link you arrived on — utm_* plus the Meta (fbclid) and TikTok (ttclid) click identifiers — kept so a later signup can be credited to the right ad. Removed if you withdraw Marketing consent |
Marketing storage is written only after you grant the Marketing category, and it is deleted again the moment you withdraw it. In regions where the banner runs in opt-out mode (see section 2) the Marketing category starts enabled, so this storage may be written on your first page view; rejecting removes it.
2. How consent works, by region
- EEA, UK, and Switzerland: opt-in. Analytics and Marketing are
off until you explicitly enable them. Google Consent Mode v2 signals default
to
deniedbefore any tracker script loads (assets/js/consent-default.jsfires first). - Other regions (including the US): opt-out. The optional categories are on by default, the banner still appears, and you can reject or customize at any time — rejecting takes effect immediately.
Region detection uses your browser timezone — including the EU territories outside the
Europe/ zones (Cyprus, the Azores, Madeira, the Canaries, Martinique,
Guadeloupe, French Guiana, Réunion, Mayotte) and the EEA ones (Iceland, Svalbard). If we
cannot tell, we treat you as EEA (the stricter default). It is a timezone guess, not a
legal determination: wherever you are, "Reject all" is one click away and is honoured
immediately.
California (CCPA/CPRA): we do not sell personal information. If the consent-gated marketing pixels are active in your region, you can opt out of that sharing at any time — click "Reject all" or toggle Marketing off in the banner's Customize dialog. That is our "Do Not Sell or Share" mechanism; no account or email is needed.
3. How to change your preferences
- Re-open the cookie banner — click the floating preference icon in the lower-left of the landing page. This reopens the Customize dialog and lets you toggle categories per-service.
- Reset entirely — clear cookies and site data for iconicvoices.io in your browser's privacy settings. The banner reappears on your next visit.
- Email us — privacy@iconicvoices.io and we will help.
4. Third parties
Where the tools above involve a third party, their privacy policies are:
| Tool | Category | Privacy Policy |
|---|---|---|
| Cloudflare (hosting, Turnstile) | Strictly necessary | cloudflare.com/privacypolicy |
| Plausible Analytics | Analytics (cookieless; aggregated only) | plausible.io/privacy |
| Google Analytics 4 | Analytics (consent-gated; currently disabled) | policies.google.com/privacy |
| Microsoft Clarity | Analytics (consent-gated; currently disabled) | privacy.microsoft.com |
| Meta Pixel | Marketing (consent-gated) | facebook.com/privacy/policy |
| TikTok Pixel | Marketing (consent-gated) | tiktok.com/legal/privacy-policy |
5. The apps
The iOS and Android apps use no cookies, no advertising identifiers, and no third-party analytics. Buying the subscription in the iOS app goes through Apple's In-App Purchase system, which uses no cookies and no ad identifiers either — what is exchanged with Apple is described in the Privacy Policy, sections 2, 3 and 6.
6. Contact
Questions or requests: privacy@iconicvoices.io. For how we handle data generally, see our Privacy Policy.