Cookie Policy

Last updated June 2026

This Cookie & Local Storage Policy explains how Hangout (“Hangout”, “we”, “us”) uses cookies, browser local storage, and similar technologies on our websites, including the marketing site at myhangout.xyz and the signed-in web app at app.myhangout.xyz. It also explains, in general terms, how our mobile apps differ. This policy supplements and should be read together with our Privacy Policy. This is a starting template and should be reviewed with legal counsel before launch.

1. What cookies and local storage are

Cookies are small text files that a website asks your browser to store on your device. They can be read back on later visits or requests, which lets a site recognize your browser, keep you signed in, and remember your choices. Cookies set by the site you are visiting are called first-party cookies; cookies set by another domain whose content is embedded in the page are called third-party cookies.

Local storage (and the related session storage) is a separate browser feature that lets a site save small pieces of data, such as preferences, directly on your device. Unlike cookies, local storage is not automatically sent to a server with every request: it stays in your browser until the site or you clear it. We use the umbrella term “storage technologies” in this policy to cover cookies, local storage, session storage, and similar mechanisms.

2. How Hangout uses these technologies

Hangout is a social meetup app, not an advertising business. On the web we use storage technologies mainly to sign you in and keep you signed in, to remember your preferences, and to understand how the product is used so we can improve it. We do not use third-party advertising cookies, and we do not build cross-site advertising profiles or sell your browsing activity. The categories below describe everything we set ourselves, plus the third-party content that can set its own cookies when it loads.

3. Strictly necessary cookies

These are required for the web app to work and to keep your account secure. They cannot be switched off through a consent control, because the service cannot function without them, and under applicable law they do not require consent.

  • Authentication and session. When you sign in to the web app we use Supabase Auth, which stores your session in cookies whose names begin with sb- (for example, an access token and a refresh token). These keep you signed in as you move between pages so you do not have to verify your phone number on every request.
  • Scope. These auth cookies are host-only cookies scoped to the app subdomain (app.myhangout.xyz). They are not shared with the marketing site and are not designed to follow you across other websites.
  • Security and load. We and our infrastructure providers may set standard tokens used for security (for example, to protect against cross-site request forgery) and for load balancing or routing, so requests reach a healthy server.

If you block these cookies, you will not be able to stay signed in to the web app.

4. Functional and preference storage

These remember choices you make so the app feels consistent. They are mostly stored in your browser’s local storage and stay on your device until you clear them. Examples include:

  • Recent searches. A local storage key such as hangout.recentSearches holds the search terms you have entered recently, so we can show them again to save you typing.
  • Interface preferences. Settings such as a reduce-motion preference and other UI choices are stored so the interface respects them on your next visit.

This functional data stays on your device and is not used for advertising. If you clear it, the relevant features simply start fresh.

5. Analytics and performance

We use privacy-respecting product analytics (for example, PostHog) to understand how the web app and site are used in aggregate, and a crash and error diagnostics service (for example, Sentry) to detect and fix bugs, so we can improve the experience. These tools may use cookies and/or local storage to recognize a returning browser and to measure things like:

  • which pages and features are visited, and in what order;
  • roughly how many people use the app and how often;
  • errors and performance issues that we should fix.

We do not use these technologies for third-party advertising, ad targeting, or cross-site tracking. Where required by applicable law, we set non-essential analytics storage only in line with the consent rules described in Section 8.

6. Storage we use, with purpose and duration

The following list describes the main storage technologies on the web, what each is for, whether it is a cookie or local storage, and how long it lasts. Specific names and lifetimes may change as the product evolves.

Strictly necessary

  • sb- auth cookies (Supabase Auth): keep you signed in to the web app. Cookies, host-only on app.myhangout.xyz. The access token is short-lived (session), while the refresh token is persistent and lasts until it expires or you sign out.
  • Security tokens (for example, anti-CSRF): protect requests against forgery. Cookies, typically session duration.
  • Load-balancing or routing tokens (infrastructure): send your requests to a healthy server. Cookies, typically session duration.

Functional and preference

  • hangout.recentSearches: remembers your recent search terms. Local storage, persistent until cleared.
  • UI preference keys (for example, reduce-motion): remember interface choices. Local storage, persistent until cleared.

Analytics and performance

  • Product analytics identifier and state (for example, PostHog): recognizes a returning browser to measure aggregate usage. Cookies and/or local storage, persistent (commonly up to about a year) unless cleared.

7. Third-party content and its cookies

Some features load content from third parties, and that content can set its own cookies or use its own storage when it appears. We do not control these cookies, and their providers’ own privacy and cookie policies govern them. Examples include:

  • GIFs. GIF search and playback provided through Tenor.
  • Maps and places. Map tiles and place or location data used to show where a hangout is.
  • App store badges. “Get the app” badges and links to the Apple App Store and Google Play.

We use these only to provide the relevant feature, not for advertising. To understand and control their cookies, please review the relevant provider’s policy and your browser controls.

8. Consent (Canada and the EU/EEA)

We serve people in Canada and the United States. Strictly necessary cookies are used because they are essential to deliver a service you have asked for, and they do not require consent under Canadian privacy law (including PIPEDA and Quebec’s Law 25) or under EU/EEA-style rules.

For non-essential storage, such as analytics, we rely on the consent standard that applies to you. In Canada we provide clear notice and meaningful choice consistent with PIPEDA and Quebec Law 25. Where ePrivacy or GDPR-style rules apply (for example, in the EU/EEA or the UK), we ask for your consent before setting non-essential storage and let you withdraw it at any time. You can always change your mind using the controls in Section 9.

9. How to control cookies and storage

  • Browser settings. Most browsers let you block or delete cookies and clear site data. Look in your browser’s privacy or site-settings menu. You can usually clear local storage by clearing site data for our domains.
  • Per-site clearing. Clearing site data for myhangout.xyz and app.myhangout.xyz removes our cookies and local storage, including your recent searches and preferences, and signs you out of the web app.
  • Global Privacy Control and Do Not Track. Where required by applicable law, we honor recognized opt-out preference signals such as Global Privacy Control. Because there is no common standard for Do Not Track, we treat it on the same basis as our other consent controls.
  • Effect of disabling essential cookies. If you block the strictly necessary cookies described in Section 3, you will not be able to stay signed in to the web app, and parts of the service may not work.

10. Mobile apps

Our iOS and Android apps do not use browser cookies. Instead they use device-level technologies, including:

  • Device identifiers used to operate and secure the app;
  • Push tokens issued by the Apple Push Notification service (and the equivalent on Android) so we can send the notifications you have enabled;
  • On-device local storage used to keep you signed in and to remember preferences.

You can manage these through your device settings: for example, turn notifications off for Hangout, reset your advertising identifier, or limit tracking in your operating system’s privacy controls. Note that sign-in uses your phone number plus a one-time code (delivered via Twilio through Supabase), so there are no passwords stored in cookies. How the apps handle personal information is described in our Privacy Policy.

11. Changes to this policy

We may update this policy as our product, providers, or legal obligations change. When we make material changes we will update the date above and, where appropriate, provide additional notice. Please check back from time to time.

12. Contact

Questions about this policy or our use of cookies and storage? Email legal@myhangout.xyz.