Cookie policy
Last updated: 27 July 2026
This Cookie Policy explains what cookies are, which ones Aulify uses, for what purpose and how you can manage them. It applies under article 22.2 of Spanish Law 34/2002 (LSSI-CE), the GDPR and the guidelines of the Spanish Data Protection Agency (AEPD).
0. Website vs. iOS app
This policy mainly concerns the website (aulify.app) opened in a browser.
- iOS app: the app does not use advertising or analytics cookies. It only stores your session and preferences locally on the device (secure storage /
localStorage), which is strictly necessary to keep you signed in. For that reason, no cookie banner is shown inside the app. Deleting the app removes that local data. - Website: in addition to the strictly necessary session storage, the Google advertising tag may be loaded, and it only activates after you accept in the consent banner.
1. Consent banner (website only)
The first time you visit the website we show a consent banner where you can accept or reject non-essential cookies. Your choice is stored locally in your browser (localStorage, key aulify_cookie_consent_v1) so we do not ask again on every visit. You can change your mind at any time by clearing the site data in your browser: the banner will reappear on your next visit.
Until you accept, Google's Consent Mode v2 keeps advertising and analytics storage denied. Strictly necessary cookies (session, authentication) are always loaded, as the service would not work without them.
2. What are cookies?
A cookie is a small text file that a website stores in your browser or device when you visit it. It allows the site to remember information about your visit (language, session, preferences). We also use similar technologies such as localStorage and sessionStorage, subject to the same rules as cookies.
3. Cookies we use
3.1. Technical cookies (strictly necessary)
These do not require consent and are essential for the service to work:
| Cookie / storage | Purpose | Duration |
|---|---|---|
sb-access-token | Keep your session signed in | 1 hour (renewable) |
sb-refresh-token | Renew the session without signing in again | 30 days |
supabase.auth.token (localStorage) | Persist authentication across tabs | Until you sign out |
aulify_cookie_consent_v1 (localStorage) | Remember your cookie choice | Until site data is cleared |
3.2. Preference storage
Stores choices that improve your experience, such as interface language, chosen theme and study progress cached locally. Only set when you change a preference.
3.3. Analytics and advertising cookies (website only, consent required)
On the website we use the Google tag (gtag.js) for Google Ads to measure the effectiveness of our campaigns (for example, how many people sign up after clicking an ad). These cookies are only activated after you accept in the banner; if you reject or ignore it, Consent Mode keeps them disabled and no advertising identifier is stored. IP anonymisation is enabled.
We do not run this tag inside the iOS app, and we do not track you across other companies' apps or websites.
4. Third-party cookies
- Supabase / Lovable Cloud: authentication and session. See supabase.com/privacy.
- Google Ads (website only, after consent): advertising measurement. See policies.google.com/privacy.
5. How to manage cookies
You can configure, accept or reject cookies (except strictly necessary ones) at any time from your browser:
Important: if you disable technical cookies you will not be able to sign in or use the core features of the service.
6. Updates
This policy may be updated when we add features or change providers. The last update date appears at the top of the document.
More information in our Privacy policy.