This policy explains what Yallah AI stores on your device, what it reads back, and what you can turn off. It covers both the website and the iOS and Android apps — those apps are wrappers around the same web app, so they use the same browser storage described here.
We do not use advertising cookies, and we do not share anything with ad networks or data brokers. Nothing described here is used to track you across other websites.
These are the only true HTTP cookies we set, and they are set only after you sign in. If you are browsing while signed out, we set no cookies at all.
| Cookie | Purpose | Retention |
|---|---|---|
sb-<project>-auth-token | Keeps you signed in and authenticates your requests. Set by our authentication provider, Supabase. | Until you sign out or the session expires |
These cannot be switched off, because the Service cannot keep you logged in without them. Under UK/EU ePrivacy rules they are "strictly necessary" and do not require consent.
Most of what we store locally uses localStorage or sessionStorage rather than cookies. This data stays on your device, is readable only by Yallah, and is never sent to an advertising network. It is functional — it exists to make the app work the way you left it.
| Key | Purpose |
|---|---|
yallah-cookie-consent | Remembers the choice you made on the cookie banner. Stored whichever way you choose, including when you decline — otherwise we would have to ask again on every page. |
yallah-lang | Your language preference (English or Arabic). |
yallah_geo | Cached approximate country, used to display the correct tax treatment at checkout. Expires after 24 hours. |
yallah_pending_checkout | Marks that you left for the payment page, so the app can refresh your plan when you return. Cleared on return. |
| Unsent form drafts | Keeps what you typed into a task, goal or budget form if you navigate away before saving. |
| AI coaching cache | Caches an AI goal-coaching response for 24 hours so re-opening a goal doesn't spend another AI message. |
| Push notification token | Stores this device's notification token so signing out can deregister this device only, rather than all your devices. |
| Admin/support keys | Only present for staff accounts — remembers the last admin tab and flags an active support session. |
You can clear all of this at any time by clearing site data in your browser, or by signing out and deleting the app.
With your consent, we load Vercel Web Analytics and Vercel Speed Insights. These tell us which pages/screens are visited and how fast they load for real users, so we can fix slow screens.
We want to be precise about what these do, rather than ask for permission we don't need:
Because nothing is stored on or read from your device, these scripts fall outside the part of ePrivacy law that governs cookies. We still ask, and still let you decline, because the IP-derived visitor count is personal data under GDPR and you should have a say in it. If you decline, the scripts are never loaded at all — we do not load them and merely suppress reporting.
We use no other analytics, no session recording, no heatmaps, and no advertising or marketing trackers of any kind.
Two parts of the Service hand you over to another company, and at that point that company's own policy applies:
We do not control these and cannot switch them off on your behalf. Neither is loaded unless you actively start a checkout or a Google sign-in.
You can change your analytics choice at any time using the button below, or the "Cookie preferences" link in the site footer. Declining takes effect immediately — the analytics scripts are removed from the page.
Questions about this policy? Contact us at support@yallahai.app. See also our Privacy Policy.