Legal
Cookie Policy
Effective date: September 1, 2026
This Cookie Policy explains what cookies are, which ones Digital Family Home uses, why we use them, and how you can control them.
1. What Are Cookies?
Cookies are small text files placed on your device when you visit a website. They are widely used to make websites work correctly, improve user experience, and provide security. Cookies set with the HttpOnly flag cannot be read by JavaScript and are used specifically for secure server-side session management.
2. Our Approach
Digital Family Home uses two categories of cookies:
- Essential (strictly necessary) cookies for authentication, session management, and security.
- Analytics cookies set by Google Analytics, loaded through Google Tag Manager, to understand how visitors find and use the Service so we can improve it.
We do not use advertising or retargeting cookies, social media tracking pixels, or personalisation cookies beyond what is described here. We do not sell the data collected through these cookies.
You retain full control over cookie storage through your browser settings, and you can opt out of Google Analytics using the Google Analytics Opt-out Browser Add-on.
3. Cookies We Use
The following cookies may be set when you use the Service:
| Name | Type | Duration | Provider |
|---|---|---|---|
| refresh_token | Essential | 30 days | Digital Family Home |
| OAuth state cookies | Essential | Session (minutes) | Digital Family Home |
| _ga | Analytics | 2 years | |
| _ga_<container> | Analytics | 2 years | |
| _gid | Analytics | 24 hours | |
| __stripe_mid | Essential | 1 year | Stripe |
| __stripe_sid | Essential | 30 minutes | Stripe |
refresh_token
Stores your encrypted session refresh token so you stay logged in across browser restarts. HttpOnly and Secure, inaccessible to JavaScript.
OAuth state cookies
Transient CSRF-protection state tokens generated during Google, Apple, or Microsoft sign-in flows. Deleted immediately after the OAuth callback completes.
_ga
Google Analytics cookie used to distinguish unique visitors and measure how the Service is used. Set via Google Tag Manager.
_ga_<container>
Google Analytics 4 cookie used to persist session state for usage measurement. Set via Google Tag Manager.
_gid
Google Analytics cookie used to distinguish visitors over a short period for usage measurement.
__stripe_mid
Stripe machine identifier used for fraud detection and secure payment processing.
__stripe_sid
Stripe session identifier used for fraud detection and secure payment processing.
4. Authentication Cookie Detail
When you log in, we issue a refresh_token cookie with the following security attributes:
- HttpOnly: cannot be read or modified by JavaScript, protecting against XSS attacks
- Secure: transmitted only over HTTPS connections
- SameSite=Strict: not sent on cross-site requests, mitigating CSRF
- Max-Age: 30 days, expires automatically; refreshed on each active session
Your short-lived access token is stored in memory (not in a cookie or localStorage) and is never written to disk.
5. Stripe Payment Cookies
When you access the billing or payment section of the app, Stripe.js sets the __stripe_mid and __stripe_sid cookies on Stripe's behalf. These are used solely for fraud prevention and are governed by Stripe's Privacy Policy.
6. Google Analytics
We use Google Analytics, loaded through Google Tag Manager, to measure traffic and understand how the Service is used (for example, which pages are visited and how visitors navigate). Google Analytics sets the _ga, _ga_<container>, and _gid cookies. This data is used only to improve the Service and is governed by Google's Privacy Policy. You can opt out using the Google Analytics Opt-out Browser Add-on.
7. OAuth Sign-In Cookies
If you sign in using Google, Apple, or Microsoft, we temporarily set a short-lived state cookie during the OAuth handshake to prevent CSRF attacks. This cookie is deleted automatically once the sign-in flow completes (typically within seconds). No data from the OAuth provider is stored in cookies.
8. Managing & Deleting Cookies
You can control or delete cookies through your browser settings. Note that deleting or blocking the authentication cookie will log you out of the Service.
9. Changes to This Policy
We may update this Cookie Policy as our technology evolves. Any change will be reflected by an updated effective date at the top of this page. Material changes will be communicated via in-app notice.
10. Contact Us
If you have questions about our use of cookies, please contact us:
Digital Family Home
Submit an inquiry through our contact form.