1. Staging policy
Closed staging uses only storage needed for authentication, abuse prevention, safe return, duplicate-request protection, device preferences, and quality review. It does not enable advertising cookies, third-party marketing tags, or behavioral analytics SDKs.
2. Cloudflare Access
Access uses required cookies such as `CF_Authorization` to confirm an allowed identity and manage sessions, CSRF protection, and OTP/MFA abuse prevention. Cloudflare states that its required Access cookies are not used for tracking or analytics.
Lifetime varies by cookie and Access application/policy configuration. Clearing them can require authentication again.
3. Firebase Authentication and Turnstile
Firebase Authentication may use browser storage for anonymous or durable identity and login persistence. Turnstile sends browser, device, and network signals needed for bot and abuse assessment to Cloudflare.
Provider processing is also governed by the provider's privacy and data-processing terms.
4. FLOOR VII localStorage and sessionStorage
Device storage may include:
- a safe post-onboarding return path and one-time request/idempotency identifiers
- audio, motion, display, device-compatibility, and review preferences or results
- temporary development/staging machine-play journals and recovery state
5. Your controls
You can remove cookies and site data through browser settings. Blocking or clearing required storage can trigger reauthentication, remove preferences, recreate a session, or make an in-progress action unrecoverable.
Before adding optional analytics or advertising, we will document purpose, provider, duration, and regional opt-in/opt-out requirements and provide a preference interface where required.