How OwLira uses cookies and local storage on the portal.
Last updated:
This document explains which cookies and storage technologies we use on owlira.com, why, and how you control each category. It complements our Privacy Policy and follows the GDPR (EU 2016/679) and LGPD (Brazil Law 13.709/2018).
1. What cookies are
Cookies are small files stored in your browser when you visit a site. We also use equivalent local storage technologies (localStorage, sessionStorage, and IndexedDB), referred to here together as "cookies".
They remember preferences, keep the portal secure and, when you allow it, measure usage in aggregate.
2. Categories we use
Essential (always on): store your consent choice (in the "owlira-consent" key of your browser), language and security items. The portal cannot work properly without them, so they do not require consent.
Sign-in session (essential, only for people using the account area): Firebase Authentication stores your session tokens in IndexedDB or localStorage, and the portal sets an "owlira-sessao" flag in localStorage to know whether to load the sign-in code. A summary of the account is kept in sessionStorage for up to 5 minutes. They keep you signed in and do not require consent.
Account security (essential): Firebase App Check with Google reCAPTCHA Enterprise stores a verification token in the browser and may set Google's own cookies (for example, _GRECAPTCHA) to protect sign-in against bots and abuse. It only loads when you use the account area or already have a session in this browser, and it is not used for advertising.
Analytics (optional): we use Google Analytics 4, which measures page views, referrers and portal usage events and sets Google cookies (for example _ga) to recognise the browser across visits. It only loads after you consent to the analytics category.
Marketing and measurement (optional): enables YouTube videos played inside the page (through the youtube-nocookie.com domain) and any remarketing pixels. When you play the video that way, YouTube may store its own data in your browser. Without this consent the video opens in a new tab on the YouTube site. It only loads after your explicit consent.
3. Third-party cookies
Embedded content (for example third-party audio or video players) may set its own cookies when played. That processing is governed by those providers’ privacy policies.
Google sign-in opens a window served by Google itself (accounts.google.com), and reCAPTCHA Enterprise is served by Google; both use Google cookies under Google's policy (https://policies.google.com/privacy).
Sign in with Apple opens a window served by Apple itself (appleid.apple.com), which uses Apple cookies under Apple's policy (https://www.apple.com/legal/privacy/).
We do not sell data nor use behavioural advertising network cookies.
4. Legal basis and consent
Non-essential cookies are only enabled after your consent, in line with the GDPR and LGPD.
When you first visit the portal you see a consent banner where you decide which categories to allow.
Session and account security storage is strictly necessary for the service you request when signing in, so it is used without prior consent (GDPR art. 6(1)(b) and 6(1)(f); ePrivacy Directive art. 5(3); LGPD art. 7, V and IX). Declining analytics and marketing in the banner does not affect sign-in.
5. Managing your choices
You can review or change your consent at any time through the banner preferences panel.
You can also block or delete cookies in your browser settings. Blocking essential cookies may break portal features.
Tapping "Sign out" in the account area removes the session and the "owlira-sessao" flag from this browser. Blocking local storage prevents signing in on the portal.
6. Retention
Your consent preference stays on your device until you clear or change it.
Analytics and marketing cookies follow the retention periods set by the provider (Google).
Sign-in session: until you sign out or clear your browser data; the account summary in sessionStorage is only reused for 5 minutes and is deleted when you sign out or close the tab. App Check token: short-lived, refreshed automatically while the account area is in use.
Account data kept on the server (the subscription status read and the download history) is not stored in the browser and is deleted together with the account (https://owlira.com/owlyhero/delete-account).
7. Updates and contact
We may update this Cookie Policy. Material changes will appear here with a new "Last updated" date.