Cookie Policy
Updated 2026-05-30
What we use
Viralefy uses one essential cookie to keep you signed in (`viralefy_token`) and one preference cookie for currency selection. No third-party advertising or tracking cookies are set on the main site.
Why
The token cookie is required to keep your session active across pages. The currency cookie remembers your last currency choice so you don't have to re-pick it on every visit.
Lifetime
The session cookie lasts 30 days. The currency cookie lasts 1 year. Both can be cleared from your browser settings at any time.
Third parties
The payment gateways (Woovi, Heleket) may set their own cookies on their own pages when you complete a payment. Those are governed by the gateway's privacy policy, not ours.
Consent
We show a cookie banner on first visit that lets you accept, customize or limit your choice to essential cookies only. Essential cookies (session, anti-CSRF, language preference) load with no consent required because they're necessary for the site to function. Analytics and marketing cookies — when used — only load after explicit opt-in. You can revisit and change your decision at any time at /legal/cookie-preferences.
Complete cookie and storage list
This table covers 100% of what the Viralefy stack may persist in your browser. Analytics and marketing cookies are only loaded after explicit consent. Manage your cookie preferences.
| Name | Provider | Party | Category | Purpose | Duration | Type |
|---|---|---|---|---|---|---|
| viralefy_token | Viralefy | First | Necessary | Authenticated session — keeps you signed in across pages and API requests. Required for any logged-in feature. | 30 days | cookie |
| vf_currency | Viralefy | First | Preferences | Remembers the currency you selected (USD, BRL, EUR…) so prices render the same on every visit, across www/auth/admin subdomains. | 1 year | cookie |
| vf_theme | Viralefy | First | Preferences | Remembers your dark/light/system theme choice across pages and subdomains. Read server-side to avoid a flash of the wrong theme on first paint. | 1 year | cookie |
| viralefy_gdpr_consent | Viralefy | First | Necessary | Stores your cookie consent choices (preferences, analytics, marketing). Without it the banner cannot remember your decision. | 12 months (re-prompt) | localStorage |
| __cf_bm | Cloudflare | Third | Necessary | Cloudflare Bot Management — distinguishes humans from automated traffic to keep the site online during DDoS or scraping. | 30 minutes | cookie |
| cf_clearance | Cloudflare | Third | Necessary | Cloudflare challenge clearance — set after you pass a Turnstile/managed challenge, prevents repeated challenges in the same session. | 30 days | cookie |
| _ga / _ga_* | Google Tag Manager | Third | Analytics | Google Analytics 4 — aggregated traffic and product usage metrics. ONLY loaded if you opt in to analytics in the cookie banner. | Up to 2 years | cookie |
| _gid | Google Tag Manager | Third | Analytics | Google Analytics session identifier. ONLY set if analytics consent is given. | 24 hours | cookie |
| sentry-trace / baggage | Sentry | Third | Analytics | Distributed-tracing request headers used for error monitoring. Currently disabled in production (DSN not configured). Will be gated by analytics consent if enabled. | Session | sessionStorage |
This list is manually audited every release. If you notice a discrepancy between this list and what your browser shows, please contact support.
