Cookie and Browser Storage Policy

Last Updated: August 2, 2026

1. Scope

This Policy explains how DOTVIDEO LLC, operating as Promote It, uses cookies and similar browser storage on promote.sh, app.promote.sh, and other browser-based parts of the Service. A cookie is a small value a website asks a browser to store and return. Local storage and session storage remain in the browser but are not automatically attached to every request.

Our native iOS and Android apps do not use browser cookies for ordinary app operation. They use app and operating-system storage, push tokens, and SDK-generated identifiers, described in Section 4 and our Privacy Policy.

2. Current Browser Storage Inventory

Names can include a project-specific suffix, prefix, or numbered chunk, and an SDK may change a technical name without changing the purpose described here. The following table reflects the Service as of the Last Updated date.

Technology/nameCategory and purposeProviderTypical duration
sb-<project-ref>-auth-token and numbered chunksEssential. Stores the Supabase authentication session so signed-in requests can be authorized.SupabaseSession lifetime; refreshed while authentication remains valid and removed on sign-out or expiry.
Supabase PKCE code-verifier storage, with a project-specific nameEssential. Completes a secure sign-in or OAuth redirect on the same browser.SupabaseTemporary; until the authentication exchange completes, expires, or storage is cleared.
locale and @app_languageFunctional. Remembers the selected site language.Promote ItThe site cookie is intended for one year; the app-web entry remains until changed or cleared.
promote_ref and app-web @promote_refFunctional. Attributes a registration to the referring brand or creator using a referral type and opaque identifier.Promote It30 days.
@device_fingerprintEssential security. Stores the generated browser fallback identifier used for account-security, abuse, and duplicate-account signals.Promote ItUntil browser storage is cleared or the identifier is replaced.
promote_analytics_consent_v1 in local storageEssential preference. Remembers whether you allowed or rejected optional web analytics and masked session replay.Promote ItUntil you change the choice or clear browser storage.
PostHog project-specific storage, generally identifiable by ph_ or PostHog-related namesOptional analytics. Maintains a pseudonymous analytics identity, session, feature-flag state, and replay linkage after consent.PostHogVaries with SDK configuration; until expiry, consent withdrawal, or browser storage is cleared.
Feature and interface entries in local storageFunctional. Remembers theme, layout, favorites, dismissed interface state, feature/configuration state, and selected settings.Promote ItUntil cleared, replaced, or removed by the feature.
REACT_QUERY_CACHE, account-scoped dataCache:*, and other cached contentFunctional. Caches profiles, Programs, wallet/dashboard summaries, conversation lists, translations, messages, support state, or other non-authoritative content to improve continuity and performance.Promote ItUntil refreshed, evicted, identity changes/sign-out cleanup runs, or browser storage is cleared.
Temporary session-storage entriesFunctional. Carries one-session navigation or interface highlights without creating a persistent profile.Promote ItCurrent browser tab/session.

3. Optional Web Analytics

PostHog web analytics, feature-flag persistence, and session replay are disabled by default. They start only after you choose Allow analytics. We collect product events, pages or screens viewed, pseudonymous or signed-in account identifiers, device/browser data, and feature interactions. The configuration removes URL query strings, disables IP capture, and masks text, inputs, images, attributes, and network details in replay.

Choosing Reject, withdrawing consent, or using a supported Global Privacy Control or Do Not Track signal keeps capture disabled and clears or disables PostHog persistence under our control. A provider may retain previously collected events for its configured retention period, as explained in the Privacy Policy.

We do not currently deploy Google Analytics, Google Ads, Meta/Facebook Pixel, LinkedIn Insight Tag, or other advertising pixels on the Service. We also do not intentionally load social-sharing widgets that set social-network cookies on Promote It pages. If this changes, we will update this inventory and obtain any required choice before activating them.

4. Native App Storage and Permissions

The mobile apps use AsyncStorage, operating-system storage, and SDK storage rather than ordinary browser cookies. Depending on the feature, these stores may contain:

  • Authentication sessions and social-connection flow state.
  • Language, theme, onboarding, layout, and other app preferences.
  • Cached messages, translations, drafts, media references, and feature/configuration state.
  • Push-notification tokens and app/device identifiers.
  • An antifraud device fingerprint based where available on Apple's IDFV, Android ID, or a generated identifier.
  • PostHog product analytics, feature-flag, diagnostics, and privacy-masked replay identifiers.

Camera, microphone, photo-library, and file access occur only when you use a feature that needs them and grant the relevant operating-system permission. You can revoke permissions in device settings, but the corresponding feature may stop working. Clipboard access occurs only when you invoke a copy, paste, or share-fallback control. Deleting the app generally clears app-local storage but does not delete server-side account data; use the account-deletion process in the Privacy Policy for that.

5. Your Controls

5.1 Promote It Web Privacy Settings

The browser Service displays a consent prompt before optional PostHog analytics and replay. Use the persistent Privacy settings control to allow or reject them later. Essential authentication and preference storage does not depend on analytics consent because it is needed to provide a requested login, language, referral, or privacy choice.

5.2 Browser Controls

Browsers let you inspect, block, and delete cookies, local storage, and site data. Blocking all storage can sign you out, prevent an OAuth return from completing, lose preferences, or make parts of the Service unavailable. Clearing storage also clears the recorded analytics choice, so the consent prompt may appear again.

5.3 Global Privacy Control and Do Not Track

When the browser exposes a supported GPC or Do Not Track signal, our current web configuration keeps optional PostHog analytics and replay disabled even if an earlier browser preference allowed them. Learn more about GPC at globalprivacycontrol.org.

6. Third-Party Sites and Redirects

Payment, payout, social-connection, sign-in, app-store, and external-link flows may redirect you to a third-party domain. Whop, Talentir, Supabase, Google, Apple, TikTok, Instagram, YouTube, X, or another destination may use its own cookies once you visit or interact with that service. Those cookies are controlled by the third party, not by this inventory. Review the notice shown by that service.

7. Changes to This Policy

We update this Policy when browser storage, analytics, advertising, or providers materially change. We will revise the date above and provide additional notice or consent where required. Technical names may vary by environment or SDK version, but a new purpose or category will be disclosed before activation where law requires it.

8. Contact

Contact us if you have a question about this inventory or want to exercise a privacy right.

DOTVIDEO LLC

5830 E 2ND ST, STE 7000 #26043

CASPER, WYOMING 82609

Phone: +1 321 237 7487

Support: [email protected]

Privacy: [email protected]

Your choice

Essential storage keeps sign-in and requested features working. Optional PostHog web analytics and masked replay remain off unless you allow them, and you can change that choice at any time through Privacy settings.

© 2026 DOTVIDEO LLC. All rights reserved.

Cookie Policy | Promote It